Remove controller-level force_ssl checks.
Obsoleted by force_ssl being globally enabled by default.
This commit is contained in:
@@ -11,7 +11,6 @@ class ApplicationController < ActionController::Base
|
||||
before_action :set_safe_mode
|
||||
# before_action :secure_cookies_check
|
||||
layout "default"
|
||||
force_ssl :if => :ssl_login?
|
||||
helper_method :show_moderation_notice?
|
||||
before_action :enable_cors
|
||||
|
||||
@@ -32,10 +31,6 @@ class ApplicationController < ActionController::Base
|
||||
CurrentUser.can_approve_posts? && (cookies[:moderated].blank? || Time.at(cookies[:moderated].to_i) < 20.hours.ago)
|
||||
end
|
||||
|
||||
def ssl_login?
|
||||
cookies[:ssl_login].present?
|
||||
end
|
||||
|
||||
def enable_cors
|
||||
response.headers["Access-Control-Allow-Origin"] = "*"
|
||||
end
|
||||
|
||||
Reference in New Issue
Block a user