diff --git a/framework/yii/web/Request.php b/framework/yii/web/Request.php index 0518529..f38bd0d 100644 --- a/framework/yii/web/Request.php +++ b/framework/yii/web/Request.php @@ -669,7 +669,7 @@ class Request extends \yii\base\Request public function getIsSecureConnection() { return isset($_SERVER['HTTPS']) && (strcasecmp($_SERVER['HTTPS'], 'on') === 0 || $_SERVER['HTTPS'] == 1) - || isset($_SERVER['HTTP_X_FORWARDED_PROTO']) && strcasecmp($_SERVER['HTTP_X_FORWARDED_PROTO'], 'https'); + || isset($_SERVER['HTTP_X_FORWARDED_PROTO']) && strcasecmp($_SERVER['HTTP_X_FORWARDED_PROTO'], 'https') === 0; } /**