# How can I requiere a route to be HTTPS?

**URL:** <https://discourse.slimframework.com/t/how-can-i-requiere-a-route-to-be-https/1384>\
**Category:** Questions\
**Created:** [April 12, 2017, 6:15pm UTC](https://discourse.slimframework.com/t/how-can-i-requiere-a-route-to-be-https/1384 "2017-04-12T18:15:00Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![ywy9876](https://avatars.discourse-cdn.com/v4/letter/y/48db29/32.png) [@ywy9876](https://discourse.slimframework.com/u/ywy9876)\
**Post date:** [April 12, 2017, 6:15pm UTC](https://discourse.slimframework.com/t/how-can-i-requiere-a-route-to-be-https/1384/1 "2017-04-12T18:15:00Z")

</div>

Hello, I’m working with my RESTapi now over HTTP, but I would like some routes (e.g. authentication) be HTTPS for security issues. How should I do it?  
Here you can see the structure of the route:

```auto
$app->get('/glossaries', function (Request $request, Response $response) {
    if (!$success) {
        $data = array("Error Message" => 'authentication failed');
        $newResponse = $response->withJson($data, 401, JSON_PRETTY_PRINT);
       .......
    }
    else {
        $data = array("Token" => $token);
        $newResponse = $response->withJson($data, 202, JSON_PRETTY_PRINT);
    }
    return $newResponse;
});

```

Thank you in advance 🙂 .!

---

<div class="post-metadata">

**Author:** ![robrothedev](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.slimframework.com/robrothedev/32/137_2.png) [@robrothedev](https://discourse.slimframework.com/u/robrothedev)\
**Post date:** [April 12, 2017, 6:27pm UTC](https://discourse.slimframework.com/t/how-can-i-requiere-a-route-to-be-https/1384/2 "2017-04-12T18:27:58Z")

</div>

@ywy9876 I’ve used this in my .htaccess files with success:`

```
RewriteEngine on
RewriteCond %{HTTP:X-Forwarded-Proto} !https
RewriteCond %{HTTPS} off
RewriteRule .* https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
RewriteCond %{REQUEST_FILENAME} !-d
RewriteCond %{REQUEST_FILENAME} !-f
RewriteRule . index.php [L]`
```

---

<div class="post-metadata">

**Author:** ![ywy9876](https://avatars.discourse-cdn.com/v4/letter/y/48db29/32.png) [@ywy9876](https://discourse.slimframework.com/u/ywy9876)\
**Post date:** [April 12, 2017, 7:31pm UTC](https://discourse.slimframework.com/t/how-can-i-requiere-a-route-to-be-https/1384/3 "2017-04-12T19:31:43Z")

</div>

@robrothedev Thanks for your reply, and if you don’t mind, I would like to make some more questions.

1. so there is nothing to do with Slim at all?
2. And for example, using the configuration that your provided, if I use AJAX for authentication making request to [http://myapp.com/api/auth](http://myapp.com/api/auth) (as usual), it will work over HTTPS and thus protecting the credentials I sent as post data? Or I have to use [https://myapp.com/api/auth](https://myapp.com/api/auth)?

Thank you in advance.

---

<div class="post-metadata">

**Author:** ![robrothedev](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.slimframework.com/robrothedev/32/137_2.png) [@robrothedev](https://discourse.slimframework.com/u/robrothedev)\
**Post date:** [April 12, 2017, 7:59pm UTC](https://discourse.slimframework.com/t/how-can-i-requiere-a-route-to-be-https/1384/4 "2017-04-12T19:59:28Z")

</div>

.htaccess is an Apache configuration so Slim has nothing to do with it. I used the .htaccess example provided [here](https://www.slimframework.com/docs/start/web-servers.html) and added the HTTPS redirects.

Personally for AJAX requests, I would just make sure you use https://. I’m not 100% sure how the .htaccess behaves with AJAX requests.

---

<div class="post-metadata">

**Author:** ![ywy9876](https://avatars.discourse-cdn.com/v4/letter/y/48db29/32.png) [@ywy9876](https://discourse.slimframework.com/u/ywy9876)\
**Post date:** [April 12, 2017, 8:26pm UTC](https://discourse.slimframework.com/t/how-can-i-requiere-a-route-to-be-https/1384/5 "2017-04-12T20:26:15Z")

</div>

@robrothedev Thank you for all the information.  
Just want to make things clearer. I’m debugging with WAMP (without HTTPS enables), and used the configuration you mentioned, and when I send a GET request with Postman: [http://myapp.com/api/xxx](http://myapp.com/api/xxx), I got Internal Server Error, so I think it’s mandatory to use [https://myapp.com/api/xxx](https://myapp.com/api/xxx)?

---

<div class="post-metadata">

**Author:** ![Antnee](https://avatars.discourse-cdn.com/v4/letter/a/919ad9/32.png) [@Antnee](https://discourse.slimframework.com/u/Antnee)\
**Post date:** [April 13, 2017, 3:51pm UTC](https://discourse.slimframework.com/t/how-can-i-requiere-a-route-to-be-https/1384/6 "2017-04-13T15:51:23Z")

</div>

I don’t have code to hand (apologies; am on my phone) but I do this in middleware as I can guarantee that it will work regardless of the server.

Basically, add a function that gets the request URI and checks the protocol. If it’s not HTTPS then redirect (via 303) to the HTTPS version.

I also use an environment variable to determine whether to enable this or not so that I can test on a non-HTTPS enabled dev environment.

If you can’t work it out from that, give me a couple of days and I’ll be able to give you a working example (y)

---

<div class="post-metadata">

**Author:** ![ywy9876](https://avatars.discourse-cdn.com/v4/letter/y/48db29/32.png) [@ywy9876](https://discourse.slimframework.com/u/ywy9876)\
**Post date:** [April 13, 2017, 4:35pm UTC](https://discourse.slimframework.com/t/how-can-i-requiere-a-route-to-be-https/1384/7 "2017-04-13T16:35:53Z")

</div>

@Antnee Hi, thanks for your reply.  
But I have some (maybe silly) questions:

1. If I use redirection method, and I post data with HTTP at first, wouldn’t it be unsafe?
2. As you said, if it’s not HTTPS request then redirect (via 303) to the HTTPS version. What should I do for implementing the HTTPS version if I have the HTTP version as follow?

```auto
$app->get('/auth', function (Request $request, Response $response) {
    .......
    if (!$success) {
        $data = array("Error Message" => 'authentication failed');
        $newResponse = $response->withJson($data, 401, JSON_PRETTY_PRINT);
       .......
    }
    else {
        $data = array("Token" => $token);
        $newResponse = $response->withJson($data, 202, JSON_PRETTY_PRINT);
    }
    return $newResponse;
});

```

---

<div class="post-metadata">

**Author:** ![robrothedev](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.slimframework.com/robrothedev/32/137_2.png) [@robrothedev](https://discourse.slimframework.com/u/robrothedev)\
**Post date:** [April 13, 2017, 4:39pm UTC](https://discourse.slimframework.com/t/how-can-i-requiere-a-route-to-be-https/1384/8 "2017-04-13T16:39:16Z")

</div>

@ywy9876 Are you still getting a server error?

---

<div class="post-metadata">

**Author:** ![ywy9876](https://avatars.discourse-cdn.com/v4/letter/y/48db29/32.png) [@ywy9876](https://discourse.slimframework.com/u/ywy9876)\
**Post date:** [April 13, 2017, 4:48pm UTC](https://discourse.slimframework.com/t/how-can-i-requiere-a-route-to-be-https/1384/9 "2017-04-13T16:48:00Z")

</div>

@robrothedev Hi,  
yeah, I got result as the following images show, not sure it is related to that I haven’t enabled the HTTPS yet for WAMP:  
 ![](https://canada1.discourse-cdn.com/flex030/uploads/slimframework/original/1X/f15fbcfa563fd32beca545ae1b4821e106e6d648.png)

 ![](https://canada1.discourse-cdn.com/flex030/uploads/slimframework/original/1X/bde887a6a2159c753fb3139bd80708a54b8f8d33.png)

---

<div class="post-metadata">

**Author:** ![robrothedev](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.slimframework.com/robrothedev/32/137_2.png) [@robrothedev](https://discourse.slimframework.com/u/robrothedev)\
**Post date:** [April 13, 2017, 4:50pm UTC](https://discourse.slimframework.com/t/how-can-i-requiere-a-route-to-be-https/1384/10 "2017-04-13T16:50:02Z")

</div>

@ywy9876 Yeah, my guess is that is the issue.

---

<div class="post-metadata">

**Author:** ![LeeH](https://avatars.discourse-cdn.com/v4/letter/l/e47c2d/32.png) [@LeeH](https://discourse.slimframework.com/u/LeeH)\
**Post date:** [March 19, 2018, 11:30pm UTC](https://discourse.slimframework.com/t/how-can-i-requiere-a-route-to-be-https/1384/11 "2018-03-19T23:30:36Z")

</div>

Hi

I have a similar problem to ywy9876, and I have recently setup my remote LAMP server with SSL which works fine with slim. However I get 504 gateway time out error on my routes that connect to mysql. My routes work fine when the same index.php file is on my local XAMPP server (which is not SSL enabled). So it appears to me that the https protocol is not yet working. what you said here seems to be a great solution, but I don’t know where to begin with middleware. Any help appreciated. Thanks
