Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow session cookies over HTTP if APP_URL starts with http:// #2462

Merged
merged 1 commit into from
Sep 27, 2024

Conversation

williamjallen
Copy link
Collaborator

#2458 removed the requirement for production sites to operate over HTTPS, but did not change the configuration option which allows session cookies to be sent over HTTP. This PR changes that option to allow session cookies to work over HTTP. Operating a CDash site over HTTP is insecure and is not recommended for most users.

User sessions don't really make sense for a HTTP site, since sessions cannot be secured. If there is interest and financial support in the future, it may be interesting to investigate simply turning off the ability to log in altogether for HTTP sites.

Closes #2461

Copy link
Member

@josephsnyder josephsnyder left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@josephsnyder josephsnyder added this pull request to the merge queue Sep 27, 2024
Merged via the queue into Kitware:master with commit b1d3bd6 Sep 27, 2024
6 checks passed
@williamjallen williamjallen deleted the allow-http-sessions branch September 30, 2024 00:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Return to 419 page after login successfully
2 participants