diff options
Diffstat (limited to 'internal/config')
| -rw-r--r-- | internal/config/config.go | 20 |
1 files changed, 18 insertions, 2 deletions
diff --git a/internal/config/config.go b/internal/config/config.go index a239aa2..c231860 100644 --- a/internal/config/config.go +++ b/internal/config/config.go @@ -19,6 +19,12 @@ type Config struct { SuperadminPassword string MaxUploadBytes int64 // default per-file limit; the superadmin can override it per blog Dev bool // reload templates/static from disk + // HTTPS says the proxy in front terminates TLS: generated links are + // https://, the session cookie is Secure and HSTS is sent. + HTTPS bool + // TrustProxy says X-Forwarded-For was written by our own proxy, so its + // last entry is the client address (for throttling and the log). + TrustProxy bool } func Load() (*Config, error) { @@ -31,6 +37,8 @@ func Load() (*Config, error) { SuperadminUsername: env("SUPERADMIN_USERNAME", "admin"), SuperadminPassword: env("SUPERADMIN_PASSWORD", ""), Dev: envBool("DEV", false), + HTTPS: envBool("HTTPS", false), + TrustProxy: envBool("TRUST_PROXY", false), } mb, err := strconv.Atoi(env("MAX_UPLOAD_MB", "10")) if err != nil || mb <= 0 { @@ -62,12 +70,20 @@ func (c *Config) BlogURL(sub string) string { if sub == RootSubdomain { return c.RootURL() } - return "http://" + sub + "." + c.HostWithPort() + return c.Scheme() + "://" + sub + "." + c.HostWithPort() } // RootURL returns the public URL of the management site. func (c *Config) RootURL() string { - return "http://" + c.HostWithPort() + return c.Scheme() + "://" + c.HostWithPort() +} + +// Scheme is the one the public reaches the site by. +func (c *Config) Scheme() string { + if c.HTTPS { + return "https" + } + return "http" } func (c *Config) HostWithPort() string { |
