add https for production environment prevent xss, csrf attack
add https for production environment
prevent xss, csrf attack