Just a head-up to avoid mixed mode SSL session hell:
Along with securing all login pages you'll also want to remember to secure /user/reset* aka the link in the "I forgot my password" email that users receive when they request a lost password.
Just a head-up to avoid mixed mode SSL session hell:
Along with securing all login pages you'll also want to remember to secure /user/reset* aka the link in the "I forgot my password" email that users receive when they request a lost password.
Comments
Comment #1
astonvictor commentedI'm closing it because the issue was created a long time ago without any further steps.
if you still need it then raise a new one.
thanks