This documentation is for an older version of JHipster. Click here for the current version of the documentation.
Tip submitted by @seanoreillyza, originally posted on his blog
In a JHipster project, this is maintained in a YAML file:
Modify your server directive with the tomcat parameters as follows:
port: 8080
remote_ip_header: x-forwarded-for
protocol_header: x-forwarded-proto
In your file src/main/java/com/my/app/config/
In the class
public class SecurityConfiguration extends WebSecurityConfigurerAdapter {
You should see the member variable:
private Environment env;
To enforce HTTPS, look for the method
protected void configure(HttpSecurity http) throws Exception {
And add the line:
// Enforce HTTPS except on dev
if (env.acceptsProfiles("!dev"))http.requiresChannel().anyRequest().requiresSecure();
Then just package and deploy as normal!