Skip to content

HTTP-only install must not silently loop on login #139

Description

@OriginDevIT

SESSION_COOKIE_SECURE gated on an env var gives an escape hatch but no diagnostic. An operator who leaves it secure on a plain-HTTP install sees a login form that accepts correct credentials and redirects back to itself with no message. The wizard or the login view should detect a request over http with secure cookies enabled and say so. Follow-up to #127.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions