Oh yeah also another update, I changed the way the HTTPS redirect is done.
Formerly it'd just redirect regardless of any circumstances. Now it only redirects if the Upgrade-Insecure-Requests header is set to "1" which should be less intrusive is some fringe cases. I recommend using HTTPS at all times when possible regardless.