Just a head-up to avoid mixed mode SSL session hell:

Along with securing all login pages you'll also want to remember to secure /user/reset* aka the link in the "I forgot my password" email that users receive when they request a lost password.

Comments

astonvictor’s picture

Issue summary: View changes
Status: Active » Closed (outdated)

I'm closing it because the issue was created a long time ago without any further steps.

if you still need it then raise a new one.
thanks