Feature #3804

Authentication over HTTPS

Added by Vinod Singh over 13 years ago. Updated over 9 years ago.

Status:NewStart date:2009-09-02
Priority:NormalDue date:
Assignee:-% Done:


Target version:-


There should be global flag to indicate that login page should be served over HTTPS. As of now once can run whole application over either HTTP or HTTPS. Running everything over HTTPS is overkill and sending user credentials over HTTP is a security whole.

Related issues

Related to Redmine - Feature #24763: Force SSL when Setting.protocol is "https" New


#1 Updated by Dipan Mehta over 9 years ago

I disagree!

There is no point in running only Login page in HTTPS and then let your session cookies visible to the rest of the world through HTTP only for some eavesdropper to hijack you once you logged in!

Everything should be HTTPS or HTTP only!

#2 Updated by Go MAEDA almost 6 years ago

  • Related to Feature #24763: Force SSL when Setting.protocol is "https" added

Also available in: Atom PDF