Skip to content

Conversation

@taladar
Copy link

@taladar taladar commented Oct 1, 2014

In this case the internal scheme in Apache was
set unconditionally (the mere presence of the
header is treated as if it's value was always 'on').

This affects e.g. the DirectorySlash Redirect in
mod_dir (the one adding trailing slashes)
and leads to redirects like this:

http://host.name/foo -> https://host.name:80/foo/

when the initial request contained a header

X-Forwarded-HTTPS: off

or

X-HTTPS: off

In this case the internal scheme in Apache was
set unconditionally (the mere presence of the
header is treated as if it's value was always 'on').

This affects e.g. the DirectorySlash Redirect in
mod_dir (the one adding trailing slashes)
and leads to redirects like this:

http://host.name/foo -> https://host.name:80/foo/

when the initial request contained a header

X-Forwarded-HTTPS: off

or

X-HTTPS: off
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant