Respect HTTP_PROTOCOL config when forcing https

This commit is contained in:
Ryan Ahearn
2023-03-08 09:57:21 -05:00
parent bb77086342
commit 703847e184
4 changed files with 8 additions and 2 deletions

View File

@@ -247,7 +247,8 @@ def create_app(application):
application,
content_security_policy=_csp(application.config),
content_security_policy_nonce_in=['style-src', 'script-src'],
frame_options='deny'
frame_options='deny',
force_https=(application.config['HTTP_PROTOCOL'] == 'https')
)
logging.init_app(application)
webauthn_server.init_app(application)