# Do we need an easier toggle for \`request.is\_secure()\` to be True?

**URL:** <https://forum.djangoproject.com/t/do-we-need-an-easier-toggle-for-request-is-secure-to-be-true/20751>\
**Category:** Django Internals\
**Created:** [May 6, 2023, 9:05am UTC](https://forum.djangoproject.com/t/do-we-need-an-easier-toggle-for-request-is-secure-to-be-true/20751 "2023-05-06T09:05:32Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![carltongibson](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/carltongibson/32/267_2.png) [@carltongibson](https://forum.djangoproject.com/u/carltongibson)\
**Post date:** [May 6, 2023, 9:05am UTC](https://forum.djangoproject.com/t/do-we-need-an-easier-toggle-for-request-is-secure-to-be-true/20751/1 "2023-05-06T09:05:32Z")

</div>

Hi all.

[`HttpRequest.is_secure()`](https://docs.djangoproject.com/en/4.2/ref/request-response/#django.http.HttpRequest.is_secure): Returns `True` if the request is secure; that is, if it was made with HTTPS.

Django isn’t magic here: it goes on a couple of clues as to what to answer there:

- [SECURE\_PROXY\_SSL\_HEADER](https://docs.djangoproject.com/en/4.2/ref/settings/#secure-proxy-ssl-header) setting, if set.
- For WSGI, the value of the `"wsgi.url_scheme" ` environ key, otherwise.

Getting this right has always been a bit of a pain.

Since Django 4.0 though, CSRF protection uses this to check the Origin header, and there are **lots** of posts of people tripping up on it.

- Just here in Mystery Errors last week: [Getting Forbidden (CSRF cookie not set.): while trying to login to Django Admin Page](https://forum.djangoproject.com/t/getting-forbidden-csrf-cookie-not-set-while-trying-to-login-to-django-admin-page/20645/1)
- Separately, I posted a TIL about it, having hit the same (again) deploying a fresh project: [CSRF and Trusted Origins in Django 4.x+](https://noumenal.es/notes/til/django/csrf-trusted-origins/) — This suggests `SECURE_PROXY_SSL_HEADER` but mentions a WSGI middleware, and I added [a gist for a Django middleware equivalent](https://gist.github.com/carltongibson/648099cd34b2c0a18e948c917a5c48fd)

But there are legion. A search for [CSRF trusted origins](https://www.google.com/search?client=safari&rls=en&q=CSRF+trusted+origins&ie=UTF-8&oe=UTF-8) has the same issue again and again and again.

I think 🤔 the main issue is that `SECURE_PROXY_SSL_HEADER` is hard to get right, and varies between environments significantly.

**But** , in contrast to the old days, HTTPS is the norm now. Having a really fiddly setting, dependent on equally fiddly settings in my hosting environment, just to get the default to work seems (maybe) an undue burden now.

Should we add some toggle — Grrr, a setting? 😬 — to more easily say, _This project will always be served with HTTPS_, and have `HttpRequest.is_secure()` always defer to that?

This is security sensitive, so we must be careful not just to jump on Yes. 🚨

---

_[View the full topic](https://forum.djangoproject.com/t/do-we-need-an-easier-toggle-for-request-is-secure-to-be-true/20751)._
