Skip to main content

The falcon-require-https package provides a middleware component for sanity-checking that the incoming request was received over HTTPS. While the web server is primarily responsibile for enforcing the HTTPS protocol, misconfiguration is still a leading cause of security vulnerabilities, and so it can be helpful to perform certain additional checks, such as this one, within the application layer itself.

Installation

$ pip install falcon-require-https

Usage

The RequireHTTPS middleware class verifies each incoming request. To use it, simply pass an instance to the falcon.API() initializer:

from falcon_require_https import RequireHTTPS

app = falcon.API(middleware=[RequireHTTPS()])

At least one of the following sources must indicate the use of HTTPS:

  • The schema of the requested URL

  • The X-Forwarded-Proto header

  • The Forwarded header (only the first hop is checked)

Otherwise, an instance of falcon.HTTPBadRequest is raised.

Caution

This middleware is not meant to replace proper security controls in your web server or load balancer. It is simply meant as a final backstop to guard against inadvertent misconfiguration at the networking layer.

Credits

This middleware component is based on paul291’s original proof of concept, which was originally submitted as a PR to the falconry/falcon repo.

About Falcon

Falcon is a bare-metal Python web framework for building lean and mean cloud APIs and app backends. It encourages the REST architectural style, and tries to do as little as possible while remaining highly effective.

Metadata

Release files for falcon-require-https 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for falcon-require-https 0.1.0
File Size Uploaded
falcon-require-https-0.1.0.tar.gz 3.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for falcon-require-https 0.1.0
File Interpreter ABI Platform
falcon_require_https-0.1.0-py2.py3-none-any.whl Python 2, Python 3 none any Details

Total release size: 9.7 kB

Release files / falcon-require-https-0.1.0.tar.gz

Download URL falcon-require-https-0.1.0.tar.gz
Size 3.4 kB
Tags Source
SHA-256 checksum
How to use checksums
ef26e22d1a30753d9f6cb44fdab329152d6673a9e3ea8d54b27427877e986597
BLAKE2b-256 checksum
How to use checksums
d4454879b774ec585768966882351d7be5c441eae133a3262bed72aa7a6c00b1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release files / falcon_require_https-0.1.0-py2.py3-none-any.whl

Download URL falcon_require_https-0.1.0-py2.py3-none-any.whl
Size 6.3 kB
Tags Python 2 Python 3
SHA-256 checksum
How to use checksums
0057b8b5fa6606b3f0bc9eb2a3124da58408839cb9d3978255a6f89c6a2775a6
BLAKE2b-256 checksum
How to use checksums
baf6afb943e22ca35209dd776a6ef0e07ebb785b48ca87d1c9498a2a0c44d6e6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page