Opened 19 months ago
Last modified 4 weeks ago
#9406 new defect
Trac allows unencrypted (http) logins
|Reported by:||Michael Witten||Owned by:|
|Version:||unspecified||Keywords:||http https security password login|
|Blocking:||Reproduced by developer:||no|
|Analyzed by developer:||no|
This page (http vs https) should not be functional:
I was at that link when my browser warned me that entering my password would not be secure; that page should probably be disabled under an unencrypted (http) connection, or perhaps redirect to an encrypted connection (https).
Change History (3)
comment:1 by , 19 months ago
Last edited 19 months ago by (previous) (diff)
comment:2 by , 9 months ago
Looks like new cert no longer allows for https://fate-suite.ffmpeg.org/ to be protected. Unfortunate.
comment:3 by , 4 weeks ago
That is still a problem, though Chrome now more or less blocks http logins.
Note: See TracTickets for help on using tickets.
Yeah. Also static resources should be upgraded.