Re: Returning to HTTP from HTTPS

From: Date: Tue, 04 Jul 2000 07:15:40 +0000
Subject: Re: Returning to HTTP from HTTPS
Groups: php.general 
Request: Send a blank email to php-general+get-4688@lists.php.net to get a copy of this message
Addressed to: wizkid@jorsm.com (Jerry P.) php-general@lists.php.net ** Reply to note from wizkid@jorsm.com (Jerry P.) Tue, 04 Jul 2000 04:19:40 GMT > > Is there a way to "gracefully" return to HTTP from HTTPS without the > browser displaying the message: Yes, use a link. > Although I'm not passing any sensitive information at this point, the > message I'm getting might be alarming to users. Might be? I'd say the messages on those dialogs were designed by the lawyers to be alraming. > Does anybody have any idea what makes Netscape display one message > over another? The above message occurs when I click on a "Submit" > button that has a <FORM > ACTION="http://mysite.com/nextscript.php3" > METHOD="POST" ...> and it passes a session ID in a hidden field to the > next script. You have sent a secured page, but you are telling the browser to send the data from the fields unsecure. Nextscript.php needs to be secure so any data is sent secured. In nextscript.php3 you can have links, but not <FORM>s that jump to non-secure pages. If you have a chain of <FORM>s they will all have to be secure. It is ok for the viewer to type in an unsecure URL, and it is ok for you to provide links to unsecure pages from secure pages. <FORM Actions need to stay secure, in most cases it is the form data that the viewer wants protected, he doesn't care much if the form you asked him to fill out is sent secure or not, but the data he fills in sure matters. Also, you will find that all images referred to by a secure page must be sent secured. This security thing is serious, you can't just jump in and out at whim. (Just read the dialog boxes when you leave a secured site! :) I don't think it is as serious as the dialogs seem to indicate, but you still have to consider that a large part of your audience will believe those hyped up messages. Rick Widmer Internet Marketing Specialists www.developersdesk.com

« previous php.general (#4688) next »