Opened 4 years ago

Last modified 14 months ago

#6981 open defect

HTTPS redirect for Trac missing

Reported by: slhck Owned by:
Priority: normal Component: trac
Version: unspecified Keywords:
Cc: Blocked By:
Blocking: Reproduced by developer: no
Analyzed by developer: no


I noticed that when you open it doesn't auto-forward you to, making logins insecure and exposing user passwords and other activity in cleartext.

It'd be great if you could change the server config to always redirect such requests, as is common security practice these days.

Change History (2)

comment:1 by Balling, 3 years ago

Cc: added
Status: newopen

Yes, nice one.

comment:2 by llogan, 14 months ago

Also see #7765.

Note: See TracTickets for help on using tickets.