Security++
This commit is contained in:
parent
6a9651efbd
commit
43580c3545
2 changed files with 4 additions and 1 deletions
|
@ -47,7 +47,7 @@ Rails.application.configure do
|
|||
# config.action_cable.allowed_request_origins = [ 'http://example.com', /http:\/\/example.*/ ]
|
||||
|
||||
# Force all access to the app over SSL, use Strict-Transport-Security, and use secure cookies.
|
||||
# config.force_ssl = true
|
||||
config.force_ssl = true
|
||||
|
||||
# Use the lowest log level to ensure availability of diagnostic information
|
||||
# when problems arise.
|
||||
|
|
3
config/initializers/remove_runtime_header.rb
Normal file
3
config/initializers/remove_runtime_header.rb
Normal file
|
@ -0,0 +1,3 @@
|
|||
if Rails.env.production?
|
||||
Rails.application.config.middleware.delete(Rack::Runtime)
|
||||
end
|
Loading…
Reference in a new issue