4 ms·
Does this support HTTPS? I'm building an app using Bottle as the framework and getting HTTPS to work properly (with a proper certificate) has been a nightmare.
by F00Fbug 8y ago
Does this support HTTPS?
I'm building an app using Bottle as the framework and getting HTTPS to work properly (with a proper certificate) has been a nightmare. I think I fixed it after a full day of research and tinkering yesterday.
This app is super small... maybe 5 users simultaneously, so I don't need the overkill of Django or integrating with something on Apache or Nginx.
REMI looks pretty straightforward and lightweight; even without HTTPS it looks useful... I'll give it a whirl and keep it in my bag of tricks!
- amasad 8y agoYeah. Here is a remi app on https https://tictactoe--amasad.repl.co https://tictactoe--amasad.repl.co
- deleted 8y ago[deleted]
- dddomodossola 8y agoyes, https is supported. you have to config 3 parameters in the "start" function call: certfile: ssl certificale filename keyfile: ssl key file ssl_version: authentication version (i.e. ssl.PROTOCOL_TLSv1_2). If None, disables ssl encription
- F00Fbug 8y agoAwesome! That's great news! I may try to rewrite some parts of my app and see if REMI is a good fit. Bottle is great if you have a simple use case... but getting HTTPS going was horrible. I can't count how many back-end engines I tried (cherrypi, paste, cheroot, gevent, waitress, etc.). Finally got it working on gunicorn. I'd love to find a framework that abstracts all this away so I don't have to think about it...
- dddomodossola 8y agoI hope you will feel ok with remi. ;-)
- nicolaslem 8y agoJust my two cents, but there are good reasons why Python web frameworks are encouraged to sit behind a reverse proxy: - Security, most WSGI servers are not designed to handle bad actors like intentionally slow clients. It is usually trivial for a client to DoS your application. - Separation of concerns, letting your framework focus on its core job rather than pilling features related to crypto and certificate renewal. The fact that you struggled getting HTTPS to work probably means that you were heading the wrong direction. I suggest to take a look at Caddy[0]. It is a small, handles HTTPS automatically and is super easy to put in front of a Python application. [0] https://caddyserver.com/docs/proxy https://caddyserver.com/docs/proxy
- dddomodossola 8y agocorrect, good point of view. thank you for the advice