aboutsummaryrefslogtreecommitdiffstats
path: root/actionpack/lib/action_dispatch/middleware
diff options
context:
space:
mode:
authorGuillermo Iguaran <guilleiguaran@gmail.com>2013-06-24 14:20:40 -0700
committerGuillermo Iguaran <guilleiguaran@gmail.com>2013-06-24 14:20:40 -0700
commita6dd2ed4af09b7969612c0aac2218795cd5d8370 (patch)
treecb90f7e3f0734639c16f65abd79eae0402597d09 /actionpack/lib/action_dispatch/middleware
parent035e2976d0d85106fe6f613373fab18497498671 (diff)
parentd8bf1f22ded16e37b3f18b942c8ae49ea79e3d79 (diff)
downloadrails-a6dd2ed4af09b7969612c0aac2218795cd5d8370.tar.gz
rails-a6dd2ed4af09b7969612c0aac2218795cd5d8370.tar.bz2
rails-a6dd2ed4af09b7969612c0aac2218795cd5d8370.zip
Merge pull request #11065 from gbuesing/hstsfix
ActionDispatch:SSL: don't include STS header in non-https responses
Diffstat (limited to 'actionpack/lib/action_dispatch/middleware')
-rw-r--r--actionpack/lib/action_dispatch/middleware/ssl.rb3
1 files changed, 1 insertions, 2 deletions
diff --git a/actionpack/lib/action_dispatch/middleware/ssl.rb b/actionpack/lib/action_dispatch/middleware/ssl.rb
index 9e03cbf2b7..68ced4e40c 100644
--- a/actionpack/lib/action_dispatch/middleware/ssl.rb
+++ b/actionpack/lib/action_dispatch/middleware/ssl.rb
@@ -36,8 +36,7 @@ module ActionDispatch
url.scheme = "https"
url.host = @host if @host
url.port = @port if @port
- headers = hsts_headers.merge('Content-Type' => 'text/html',
- 'Location' => url.to_s)
+ headers = { 'Content-Type' => 'text/html', 'Location' => url.to_s }
[301, headers, []]
end