{"id":19033402,"date":"2026-09-30T17:46:57","date_gmt":"2026-09-30T17:46:57","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/https-check-fails-behind-nginx-proxy\/"},"modified":"2026-09-30T17:46:57","modified_gmt":"2026-09-30T17:46:57","slug":"https-check-fails-behind-nginx-proxy","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/https-check-fails-behind-nginx-proxy\/","title":{"rendered":"%{HTTPS} check fails behind nginx proxy"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">WP Fastest Cache 1.5.2, PHP 8.3, Apache behind nginx (ISPmanager shared hosting; nginx terminates TLS and proxies to Apache over HTTP), Cloudflare in front.<br \/><br \/>Every cached page ends with <code>&lt;!-- via php --&gt;<\/code>, and the time to first byte stays at 0.4\u20130.9 s. The <code>.htaccess<\/code> rules never match, because the first condition is:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">RewriteCond %{HTTPS} on<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Behind a proxy that terminates TLS, Apache sees the connection as plain HTTP, so <code>%{HTTPS}<\/code> is off, even though the visitor uses HTTPS. The proxy does send <code>X-Forwarded-Proto: https<\/code>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Workaround:<\/strong> this change makes Apache serve the cache directly (TTFB dropped to about 80 ms):<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">RewriteCond %{HTTPS} on [OR]<br \/>RewriteCond %{HTTP:X-Forwarded-Proto} https<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But WP Fastest Cache overwrites it whenever the settings are saved.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Request:<\/strong> could the generated rules also accept <code>%{HTTP:X-Forwarded-Proto} https<\/code> (and perhaps <code>%{HTTP:X-Forwarded-SSL} on<\/code>), or offer a setting for it? This setup is common on shared hosting and behind Cloudflare with Flexible SSL.<\/p>\n","protected":false},"template":"","class_list":["post-19033402","topic","type-topic","status-publish","hentry","topic-tag-cloudflare","topic-tag-htaccess","topic-tag-https","topic-tag-nginx","topic-tag-reverse-proxy"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19033402","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19033402\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=19033402"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}