# {{ request.scheme }} is not honoring https

**URL:** <https://forum.djangoproject.com/t/request-scheme-is-not-honoring-https/25099>\
**Category:** Deployment\
**Created:** [November 7, 2023, 7:05am UTC](https://forum.djangoproject.com/t/request-scheme-is-not-honoring-https/25099 "2023-11-07T07:05:26Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![carltongibson](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/carltongibson/32/267_2.png) [@carltongibson](https://forum.djangoproject.com/u/carltongibson)\
**Post date:** [November 7, 2023, 8:46am UTC](https://forum.djangoproject.com/t/request-scheme-is-not-honoring-https/25099/2 "2023-11-07T08:46:32Z")

</div>

It’s likely you need to set [SECURE\_PROXY\_SSL\_HEADER](https://docs.djangoproject.com/en/4.2/ref/settings/#secure-proxy-ssl-header) to let Django know you’re running under HTTPS.

If that’s not available I documented a WSGI middleware approach at the end of the post here: [CSRF and Trusted Origins in Django 4.x+](https://noumenal.es/notes/til/django/csrf-trusted-origins/#csrf-and-trusted-origins-in-django-4-x).

---

_[View the full topic](https://forum.djangoproject.com/t/request-scheme-is-not-honoring-https/25099)._
