From 8d51ce429094d43a91d61c9cb0c0dc7b1e6bd2de Mon Sep 17 00:00:00 2001
From: Naoki Kosaka <n.k@mail.yukimochi.net>
Date: Sat, 6 Jan 2018 04:04:22 +0900
Subject: [PATCH] Fix enforce HTTPS in production. (#6180)

---
 config/initializers/session_store.rb | 2 +-
 spec/rails_helper.rb                 | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/config/initializers/session_store.rb b/config/initializers/session_store.rb
index ef61543a87..3dc0edd6fd 100644
--- a/config/initializers/session_store.rb
+++ b/config/initializers/session_store.rb
@@ -1,3 +1,3 @@
 # Be sure to restart your server when you modify this file.
 
-Rails.application.config.session_store :cookie_store, key: '_mastodon_session', secure: (ENV['LOCAL_HTTPS'] == 'true')
+Rails.application.config.session_store :cookie_store, key: '_mastodon_session', secure: (Rails.env.production? || ENV['LOCAL_HTTPS'] == 'true')
diff --git a/spec/rails_helper.rb b/spec/rails_helper.rb
index 4f7399505c..67c6b92054 100644
--- a/spec/rails_helper.rb
+++ b/spec/rails_helper.rb
@@ -46,7 +46,7 @@ RSpec.configure do |config|
   config.include ActiveSupport::Testing::TimeHelpers
 
   config.before :each, type: :feature do
-    https = ENV['LOCAL_HTTPS'] == 'true'
+    https = Rails.env.production? || ENV['LOCAL_HTTPS'] == 'true'
     Capybara.app_host = "http#{https ? 's' : ''}://#{ENV.fetch('LOCAL_DOMAIN')}"
   end
 
-- 
GitLab