Kavach

Fix · Express / Node

Fix “Served over HTTPS” on Express / Node

Install a TLS certificate (free via Let's Encrypt) and redirect all http:// traffic to https://.

app.use((req, res, next) => {
  if (!req.secure) return res.redirect(301, 'https://' + req.headers.host + req.url);
  next();
});

Verify the fix

Re-run the Served over HTTPS check after deploying. Test config changes in staging first and keep a rollback: a wrong header can break a site faster than a missing one.

Other stacks: nginx · Apache · Caddy · Cloudflare

Scan your site free → Monitor it continuously