To force traffic to use the HTTPS protocol, the most common method is to implement request redirection through the .htaccess file, the following is a basic description of the .htaccess file and the procedure:
.An .htaccess file is a simple text file with the name “.htaccess” that contains additional settings passed to the web server that can support some of the more complex features of a website.
If you are using a script created by someone else (including a content management system such as WordPress), you can usually find an existing .htaccess file in your website's htdocs folder; if you don't already have one, you will need to create it yourself - it is recommended that you use a file manager to create one! This is because some systems (especially Windows) do not support .htaccess files well, and a file manager can help you avoid problems during the creation process.
Once you have found or created the .htaccess file, you can edit it using a file manager, or any text editor (e.g. Notepad), by adding the following lines of code to the file:
RewriteEngine On
RewriteCond %{HTTP:X-Forwarded-Proto} !https
RewriteCond %{HTTPS} off
RewriteCond %{HTTP:CF-Visitor} ! {"scheme": "https"}
RewriteRule (. *) https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
Source : https://forum.infinityfree.com/docs?topic=49322
Using an .htaccess File to Set Up a Forced Redirect from HTTP to HTTPS: A Checklist Before Getting Started
When creating technical tutorials, the biggest pitfall is copying commands verbatim while ignoring differences in the environment. Different system versions, web servers, plugin combinations, and permission settings can all affect the final outcome. Before proceeding, it’s recommended that you document your current configuration and, if necessary, create a snapshot or backup. That way, even if you make a mistake during the process, you can quickly roll back the changes.
We recommend confirming the following before proceeding
- System and Software Versions:Verify the versions of Windows, Debian, Nginx, Apache, WordPress, or related tools.
- Permissions:When dealing with credentials, certificates, or configuration files, first verify that the current user has sufficient permissions.
- Backup:Before modifying a configuration file, make a copy of the original file first. For WordPress sites, it’s also recommended to back up the database.
- Test Method:Validate your changes after each step; don't wait until you've finished making all the changes to troubleshoot.
Troubleshooting Approach
When you encounter an error, first determine at which layer it occurred: the browser, DNS, server, application, plugin, or permissions. Breaking the problem down into smaller parts is more effective than repeatedly searching through an entire error message. For issues involving WordPress, Nginx, certificates, and proxies, logs are usually more reliable than front-end pages.
If the paths or menus in this tutorial differ from those in your environment, refer to your system’s current display first, and then use the keywords to locate the corresponding features. This is especially true for the Windows Control Panel, the WordPress plugin menu, and cloud service consoles, as their access points are frequently updated with new versions.
Recommendations for Follow-up Maintenance
Completing a fix does not mean the problem is permanently resolved. We recommend documenting key commands, modified files, modification times, and verification results. These records can save a significant amount of troubleshooting time when you later migrate servers, upgrade plugins, or change themes.











