# How to require a route to be https Slim3

**URL:** <https://discourse.slimframework.com/t/how-to-require-a-route-to-be-https-slim3/404>\
**Category:** Questions\
**Created:** [June 16, 2016, 3:56am UTC](https://discourse.slimframework.com/t/how-to-require-a-route-to-be-https-slim3/404 "2016-06-16T03:56:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![JacobChrist](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.slimframework.com/jacobchrist/32/123_2.png) [@JacobChrist](https://discourse.slimframework.com/u/JacobChrist)\
**Post date:** [June 16, 2016, 3:56am UTC](https://discourse.slimframework.com/t/how-to-require-a-route-to-be-https-slim3/404/1 "2016-06-16T03:56:09Z")

</div>

So I want to force user authentication to use https. I found this but it so old I suspect its pre Slim3

[http://help.slimframework.com/discussions/questions/371-how-do-you-require-a-route-to-be-https](http://help.slimframework.com/discussions/questions/371-how-do-you-require-a-route-to-be-https)

Pre Slim I might have done something like this:

`
  if( substr_compare($_SERVER['HTTP_HOST'], 'localhost', 0, 9) != 0 ) // don't force on dev machine
 {
    if($_SERVER["HTTPS"] != "on"){
        header("Location: https://" . $_SERVER["HTTP_HOST"] . $_SERVER["REQUEST_URI"]);
        exit();
    }
  }
`

Anyone have any suggestions?

Jacob

---

<div class="post-metadata">

**Author:** ![JoeBengalen](https://avatars.discourse-cdn.com/v4/letter/j/b5e925/32.png) [@JoeBengalen](https://discourse.slimframework.com/u/JoeBengalen)\
**Post date:** [June 17, 2016, 3:28pm UTC](https://discourse.slimframework.com/t/how-to-require-a-route-to-be-https-slim3/404/2 "2016-06-17T15:28:44Z")

</div>

I would use some middleware for it.

Here is an example: [https://github.com/oscarotero/psr7-middlewares/blob/master/src/Middleware/Https.php](https://github.com/oscarotero/psr7-middlewares/blob/master/src/Middleware/Https.php)

---

<div class="post-metadata">

**Author:** ![JacobChrist](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.slimframework.com/jacobchrist/32/123_2.png) [@JacobChrist](https://discourse.slimframework.com/u/JacobChrist)\
**Post date:** [June 21, 2016, 5:10am UTC](https://discourse.slimframework.com/t/how-to-require-a-route-to-be-https-slim3/404/3 "2016-06-21T05:10:15Z")

</div>

Thanks looks good as well as some of the other Middleware there. Can’t wait to dig in.

Jacob

---

<div class="post-metadata">

**Author:** ![marcelbonnet](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.slimframework.com/marcelbonnet/32/115_2.png) [@marcelbonnet](https://discourse.slimframework.com/u/marcelbonnet)\
**Post date:** [August 3, 2016, 7:58pm UTC](https://discourse.slimframework.com/t/how-to-require-a-route-to-be-https-slim3/404/4 "2016-08-03T19:58:05Z")

</div>

> [@JacobChrist](#):
>
> header(“Location: https://” . $SERVER[“HTTPHOST”] . $SERVER[“REQUESTURI”]);

Hi, I’m a bit late… but it is a great question, this is what I did today (a middleware) , to solve the same problem for paths related to authentication. The rest of the app may be non secured.

\<?php namespace DarthEv\Core\app\middleware; use Psr\Http\Message\ServerRequestInterface; use Psr\Http\Message\ResponseInterface; ```php /** * This middleware forces declared paths * to be redirect with HTTPS * * @author marcelbonnet * */ final class RequireHttpsMiddleware { const SSL_REQUIRED_PATHS = ['login', 'logout', 'auth/notAuthenticated']; public function __invoke(ServerRequestInterface $request, ResponseInterface $response, callable $next){ if($request-\>getUri()-\>getScheme() !== 'https' && in_array($request-\>getUri()-\>getPath(), self::SSL_REQUIRED_PATHS ) ){ return $response -\>withStatus(302) -\>withHeader('Location' , 'https://' . $request-\>getUri()-\>getHost() . $request-\>getUri()-\>getBasePath() . '/' . $request-\>getUri()-\>getPath() ); } if($request-\>getUri()-\>getScheme() === 'https' && !in_array($request-\>getUri()-\>getPath(), self::SSL_REQUIRED_PATHS ) ){ return $response -\>withStatus(302) -\>withHeader('Location' , 'http://' . $request-\>getUri()-\>getHost() . $request-\>getUri()-\>getBasePath() . '/' . $request-\>getUri()-\>getPath() ); } return $next($request, $response); } } ```

---

<div class="post-metadata">

**Author:** ![nisbeti](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.slimframework.com/nisbeti/32/206_2.png) [@nisbeti](https://discourse.slimframework.com/u/nisbeti)\
**Post date:** [August 31, 2016, 7:13am UTC](https://discourse.slimframework.com/t/how-to-require-a-route-to-be-https-slim3/404/5 "2016-08-31T07:13:25Z")

</div>

We already use Apache rewrite rules in .htaccess, so is there a way to combine that to force https for whole site?  
But in consideration of this advice [https://httpd.apache.org/docs/2.4/rewrite/avoid.html](https://httpd.apache.org/docs/2.4/rewrite/avoid.html)
