diff options
author | http://smcv.pseudorandom.co.uk/ <smcv@web> | 2010-11-23 23:59:03 +0000 |
---|---|---|
committer | Joey Hess <joey@kitenet.net> | 2010-11-23 23:59:03 +0000 |
commit | 61218e338a7517b25fc82697c3a11fff1edb6803 (patch) | |
tree | 6f9ee8b754295484017376719e65e21c2ca78410 /doc/todo | |
parent | 9180381728e252cf474eb8a4b0460755b5c28340 (diff) |
another branch
Diffstat (limited to 'doc/todo')
-rw-r--r-- | doc/todo/use_secure_cookies_for_ssl_logins.mdwn | 12 |
1 files changed, 12 insertions, 0 deletions
diff --git a/doc/todo/use_secure_cookies_for_ssl_logins.mdwn b/doc/todo/use_secure_cookies_for_ssl_logins.mdwn new file mode 100644 index 000000000..a91a15b98 --- /dev/null +++ b/doc/todo/use_secure_cookies_for_ssl_logins.mdwn @@ -0,0 +1,12 @@ +[[!template id=gitbranch branch=smcv/ready/sslcookie-auto author="[[smcv]]"]] +[[!tag patch]] + +At the moment `sslcookie => 0` never creates secure cookies, so if you log in +with SSL, your browser will send the session cookie even over plain HTTP. +Meanwhile `sslcookie => 1` always creates secure cookies, so you can't +usefully log in over plain http. + +This branch adds `sslcookie => 0, sslcookie_auto => 1` as an option; this +uses the `HTTPS` environment variable, so if you log in over SSL you'll +get a secure session cookie, but if you log in over HTTP, you won't. +(The syntax for the setup file is pretty rubbish - any other suggestions?) |