#!/bin/sh

# FIXME: Detect upgraded connections, deliver original 401 text in this case

echo "Status: 301 Moved Permanently"
# Do not use REDIRECT_SCRIPT_URL! Not only is it missing the QUERY_STRING, but URL-encodings are decoded and thus allow header injection!
echo "Location: https://${SERVER_NAME}${REQUEST_URI}"
echo "Content-Type: text/html"
echo
echo "<!DOCTYPE HTML PUBLIC \"-//IETF//DTD HTML 2.0//EN\">"
echo "<html><head>"
echo "<title>Secure Authentication Required</title>"
echo "</head><body>"
echo "<h1>Secure Authentication Required</h1>"
echo "<p>Authentication information must not"
echo "be transmitted over insecure channels."
echo "You are redirected to the requested"
echo "document using a secure channel.</p>"
echo "<hr>"
echo "<address>${SERVER_SOFTWARE} Server at <a href="mailto:${SERVER_ADMIN}">${SERVER_NAME}</a> Port ${SERVER_PORT}</address> "
echo "</body></html>"
