diff --git a/config/environments/production.rb b/config/environments/production.rb index 41e4964..de4212c 100644 --- a/config/environments/production.rb +++ b/config/environments/production.rb @@ -3,6 +3,9 @@ require "active_support/core_ext/integer/time" Rails.application.configure do + # Force all access to the app over SSL, use Strict-Transport-Security, and use secure cookies. + config.force_ssl = true + # Settings specified here will take precedence over those in config/application.rb. config.hosts << "nindika.com" config.hosts << "www.nindika.com" @@ -49,8 +52,7 @@ # config.action_cable.url = 'wss://example.com/cable' # config.action_cable.allowed_request_origins = [ 'http://example.com', /http:\/\/example.*/ ] - # Force all access to the app over SSL, use Strict-Transport-Security, and use secure cookies. - config.force_ssl = true + # Include generic and useful information about system operation, but avoid logging too much # information to avoid inadvertent exposure of personally identifiable information (PII).