Missing force SSL configuration for incoming communication detected.


When applications process sensitive data, they should default to always use SSL when available. This rule checks if force SSL is enabled at the application level.


This helps avoid attacks like session hijacking. More importantly, unencrypted HTTP communication sends all requests as plain text, meaning anyone listening in can see all the traffic and extract user data.

While you want to avoid sending sensitive data whenever possible, it's unavoidable so protecting the connection is an important method of improving your rails application data security.

✅ To force all traffic to your application to be encrypted though SSL, use the following Rails configuration option:

config.force_ssl = true


Associated CWE

OWASP Top 10