IMCDb Forum
General  » Site moving to a new server
Category :  
« Previous topic
Reminder of the previous message
Direct link to this message Edit  Quote  Add this message as quote for multiple quotes  Delete  Top  Bottom
Site moving to a new server
Published 19/05/2018 @ 18:05:40, By ElSaxo
Can I say that I don't see the logic behind forcing https only for the login page and not the entire site?


Direct link to this message Edit  Quote  Add this message as quote for multiple quotes  Delete  Top  Bottom
Site moving to a new server
Published 19/05/2018 @ 23:15:47, By antp
Because the sensitive info that is transmitted is your username/password, so why force it by default in case someone is browsing as visitor in http-only (in case for some reason https does not work for him).
Once logged in you would stay in https, of course (I should then force the cookie & session to be useable in https only).

Latest Edition: 19/05/2018 @ 23:16:38
Direct link to this message Edit  Quote  Add this message as quote for multiple quotes  Delete  Top  Bottom
Site moving to a new server
Published 20/05/2018 @ 22:11:29, By ElSaxo
I've an idea of the advantages of https connection, especially in security terms. But still doesn't make much sense to don't force https for everyone, including "casual visitors". Why for them https shouldn't work, unless someone is still using Windows 98 or exclusively relies on wifi hotspots?
Direct link to this message Edit  Quote  Add this message as quote for multiple quotes  Delete  Top  Bottom
Site moving to a new server
Published 20/05/2018 @ 23:10:29, By antp
In case there is a problem with the certificate on the site or its config :grin:
Add Reply  - Category :  
Sign In  :: Sign Up  :: Lost your login or your password?
KelCommunity.be :: © 2004-2018 Akretio SPRL :: Powered by Kelare