]> sipb.mit.edu Git - ikiwiki.git/commitdiff
another branch
authorhttp://smcv.pseudorandom.co.uk/ <smcv@web>
Tue, 23 Nov 2010 23:59:03 +0000 (23:59 +0000)
committerJoey Hess <joey@kitenet.net>
Tue, 23 Nov 2010 23:59:03 +0000 (23:59 +0000)
doc/todo/use_secure_cookies_for_ssl_logins.mdwn [new file with mode: 0644]

diff --git a/doc/todo/use_secure_cookies_for_ssl_logins.mdwn b/doc/todo/use_secure_cookies_for_ssl_logins.mdwn
new file mode 100644 (file)
index 0000000..a91a15b
--- /dev/null
@@ -0,0 +1,12 @@
+[[!template id=gitbranch branch=smcv/ready/sslcookie-auto author="[[smcv]]"]]
+[[!tag patch]]
+
+At the moment `sslcookie => 0` never creates secure cookies, so if you log in
+with SSL, your browser will send the session cookie even over plain HTTP.
+Meanwhile `sslcookie => 1` always creates secure cookies, so you can't
+usefully log in over plain http.
+
+This branch adds `sslcookie => 0, sslcookie_auto => 1` as an option; this
+uses the `HTTPS` environment variable, so if you log in over SSL you'll
+get a secure session cookie, but if you log in over HTTP, you won't.
+(The syntax for the setup file is pretty rubbish - any other suggestions?)