summaryrefslogtreecommitdiff
path: root/doc/todo
diff options
context:
space:
mode:
authorhttp://smcv.pseudorandom.co.uk/ <smcv@web>2010-11-23 23:59:03 +0000
committerJoey Hess <joey@kitenet.net>2010-11-23 23:59:03 +0000
commit61218e338a7517b25fc82697c3a11fff1edb6803 (patch)
tree6f9ee8b754295484017376719e65e21c2ca78410 /doc/todo
parent9180381728e252cf474eb8a4b0460755b5c28340 (diff)
another branch
Diffstat (limited to 'doc/todo')
-rw-r--r--doc/todo/use_secure_cookies_for_ssl_logins.mdwn12
1 files changed, 12 insertions, 0 deletions
diff --git a/doc/todo/use_secure_cookies_for_ssl_logins.mdwn b/doc/todo/use_secure_cookies_for_ssl_logins.mdwn
new file mode 100644
index 000000000..a91a15b98
--- /dev/null
+++ b/doc/todo/use_secure_cookies_for_ssl_logins.mdwn
@@ -0,0 +1,12 @@
+[[!template id=gitbranch branch=smcv/ready/sslcookie-auto author="[[smcv]]"]]
+[[!tag patch]]
+
+At the moment `sslcookie => 0` never creates secure cookies, so if you log in
+with SSL, your browser will send the session cookie even over plain HTTP.
+Meanwhile `sslcookie => 1` always creates secure cookies, so you can't
+usefully log in over plain http.
+
+This branch adds `sslcookie => 0, sslcookie_auto => 1` as an option; this
+uses the `HTTPS` environment variable, so if you log in over SSL you'll
+get a secure session cookie, but if you log in over HTTP, you won't.
+(The syntax for the setup file is pretty rubbish - any other suggestions?)