Actions
Feature #3804
closedAuthentication over HTTPS
Start date:
2009-09-02
Due date:
% Done:
0%
Estimated time:
Resolution:
Wont fix
Description
There should be global flag to indicate that login page should be served over HTTPS. As of now once can run whole application over either HTTP or HTTPS. Running everything over HTTPS is overkill and sending user credentials over HTTP is a security whole.
Related issues
Updated by Go MAEDA about 8 years ago
- Related to Feature #24763: Force SSL when Setting.protocol is "https" added
Actions