Opened 6 years ago

Closed 3 months ago

#6981 closed defect (fixed)

HTTPS redirect for Trac missing

Reported by: slhck Owned by:
Priority: normal Component: trac
Version: unspecified Keywords:
Cc: val.zapod.vz@gmail.com Blocked By:
Blocking: Reproduced by developer: no
Analyzed by developer: no

Description

I noticed that when you open http://trac.ffmpeg.org it doesn't auto-forward you to https://trac.ffmpeg.org, making logins insecure and exposing user passwords and other activity in cleartext.

It'd be great if you could change the server config to always redirect such requests, as is common security practice these days.

Change History (5)

comment:1 by Balling, 4 years ago

Cc: val.zapod.vz@gmail.com added
Status: newopen

Yes, nice one.

comment:2 by llogan, 3 years ago

Also see #7765.

comment:3 by Balling, 14 months ago

Cc: Balling added

Is not that a trac bug?

comment:4 by Balling, 11 months ago

Cc: Balling removed

comment:5 by Marth64, 3 months ago

Resolution: fixed
Status: openclosed

Closing because this exists now. Thank you.

Note: See TracTickets for help on using tickets.