From 8d51ce429094d43a91d61c9cb0c0dc7b1e6bd2de Mon Sep 17 00:00:00 2001 From: Naoki Kosaka Date: Sat, 6 Jan 2018 04:04:22 +0900 Subject: Fix enforce HTTPS in production. (#6180) --- config/initializers/session_store.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'config') diff --git a/config/initializers/session_store.rb b/config/initializers/session_store.rb index ef61543a8..3dc0edd6f 100644 --- a/config/initializers/session_store.rb +++ b/config/initializers/session_store.rb @@ -1,3 +1,3 @@ # Be sure to restart your server when you modify this file. -Rails.application.config.session_store :cookie_store, key: '_mastodon_session', secure: (ENV['LOCAL_HTTPS'] == 'true') +Rails.application.config.session_store :cookie_store, key: '_mastodon_session', secure: (Rails.env.production? || ENV['LOCAL_HTTPS'] == 'true') -- cgit