by default, since the ruby 1.8 version now has a ruby18 explicit FLAVOR.
Force SSL/TLS in your rack app: Redirects all "http" requests to "https" Set Strict-Transport-Security header Flag all cookies as "secure" OK claudio@