Manual:$wgForceHTTPS/de-formal

Details
If this setting is true, when an insecure HTTP request is received, always redirect to HTTPS. This overrides and disables the preferhttps user preference, and it overrides and the  hook.

may be either https or protocol-relative. If starts with "http://", an exception will be thrown.

If a reverse proxy or CDN is used to forward requests from HTTPS to HTTP, the request header " " should be sent to suppress the redirect.

In addition to setting this to, for optimal security, the webserver should also be configured to send HTTP Strict Transport Security (HSTS) response headers.

When  is set to, HTTP/HTTPS preference is tracked on a per-user basis, by a combination of:


 * the  user preference
 * the cookie  and session metadata (available via )
 * eventual PHP hooks changing session metadata
 * the PHP method

Availability
This variable was added in MediaWiki 1.35.0 (608504). It was backported to 1.34 as part of the MediaWiki 1.34.3 release (612497) as well as to 1.31 as part of the MediaWiki 1.31.9 release (615840).