export const noStore = (headers = new Headers()) => { headers.set("cache-control", "no-store"); return headers; }; export const redirectTo = (location: string) => { const headers = noStore(); headers.set("location", location); return new Response(null, { status: 302, headers }); }; // reverse proxy terminates tls; url.protocol is http inside the worker export const requestOrigin = (url: URL, headers: Headers) => { const forwarded = headers.get("x-forwarded-proto")?.split(",", 1)[0].trim().toLowerCase(); const protocol = forwarded === "http" || forwarded === "https" ? `${forwarded}:` : url.protocol; return `${protocol}//${url.host}`; }; export const isSecureRequest = (url: URL, headers: Headers) => requestOrigin(url, headers).startsWith("https://");