Only use HSTS if SSL is enabled

This commit is contained in:
Omar Roth 2018-03-11 10:29:40 -05:00
parent 31d1315c60
commit d664d6b371

View file

@ -160,10 +160,6 @@ get "/" do |env|
templated "index"
end
before_all do |env|
env.response.headers.add("Strict-Transport-Security", "max-age=31536000; includeSubDomains; preload")
end
get "/watch" do |env|
if env.params.query["v"]?
id = env.params.query["v"]
@ -356,6 +352,10 @@ if Kemal.config.ssl && redirect
server.listen
end
before_all do |env|
env.response.headers.add("Strict-Transport-Security", "max-age=31536000; includeSubDomains; preload")
end
end
static_headers do |response, filepath, filestat|