Skip to content

Controller

isSecure()

isSecure() — returns boolean

Available in: controller Category: Miscellaneous Functions

Returns whether Wheels is communicating over a secure port. X-Forwarded-Proto is client-controlled and is only honored when the app has opted into proxy trust via set(trustProxyHeaders=true) behind a trusted reverse proxy.

// 1. Redirect non-secure connections to the HTTPS version
if (!isSecure()) {
	redirectTo(protocol="https");
}

// 2. Conditionally set a secure cookie flag based on the connection
cookieOptions = {secure: isSecure(), httpOnly: true};

// 3. Log a warning when a sensitive action is performed over a non-secure connection
if (!isSecure()) {
	logMessage("WARNING: sensitive action performed over non-secure connection");
}