Re: svn: /web/php-master/trunk/include/ login.inc
| From: | Richard Quadling | Date: | Wed, 30 Mar 2011 09:13:53 +0000 |
| Subject: | Re: svn: /web/php-master/trunk/include/ login.inc | ||
| References: | 1 2 3 | Groups: | php.webmaster |
| Request: | Send a blank email to php-webmaster+get-10778@lists.php.net to get a copy of this message | ||
On 29 March 2011 21:05, Daniel Brown <danbrown@php.net> wrote:
> On Tue, Mar 29, 2011 at 15:59, Hannes Magnusson
> <hannes.magnusson@gmail.com> wrote:
>> On Tue, Mar 29, 2011 at 19:53, Daniel P. Brown <danbrown@php.net> wrote:
>>> danbrown Tue, 29 Mar 2011 17:53:56
>>> +0000
>>>
>>> Revision:
>>> http://svn.php.net/viewvc?view=revision&revision=309816
>>>
>>> Log:
>>> Add a link and META refresh so we don't have to manually edit the location in the
>>> browser (especially on a mobile device).
>>>
>>
>>
>> Noo.. That defeats the purpose. You are supposed to update your
>> bookmarks and stuff.
>> If you get redirected in any way, or given a simple method to continue
>> anyway.. You'll never update the bookmark.
>
> Does that matter if we're forcing them to use SSL anyway? I don't
> use bookmarks for anything at all, ever, to be honest.... and
> remembering to type in https:// every time is a pain,
> particularly
> when I'm connecting from a mobile device. I'm sure I'm not the only
> one who thinks so, but if you're that much against it, feel free to
> revert it.
>
>
> --
> </Daniel P. Brown>
> Network Infrastructure Manager
> http://www.php.net/
>
> --
> PHP Webmaster List Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
If a site wishes to enforce https, then let it. From a user's
perspective, it makes no difference.
I never type the http://www part of an address anyway.
I think the auto redirect is just fine.
Personally, I'd also drop the 2 second delay and redirect on the
server using a rewrite rule.
Maybe add a message if the redirect was necessary to say that if you
came to the site from a bookmark, then please update it.
But, first of all, fixing the lack of a proper cert would be great.
Being forced to use https (which is fine) and then being told "The
security certificate presented by this website was not issued by a
trusted certificate authority.", THAT is more of an issue that a
simple redirect.
Richard.
--
Richard Quadling
Twitter : EE : Zend
@RQuadling : e-e.com/M_248814.html : bit.ly/9O8vFY