Re: svn: /web/php-master/trunk/include/ login.inc

From: Date: Wed, 30 Mar 2011 09:13:53 +0000
Subject: Re: svn: /web/php-master/trunk/include/ login.inc
References: 1 2 3  Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-10778@lists.php.net to get a copy of this message
On 29 March 2011 21:05, Daniel Brown <danbrown@php.net> wrote: > On Tue, Mar 29, 2011 at 15:59, Hannes Magnusson > <hannes.magnusson@gmail.com> wrote: >> On Tue, Mar 29, 2011 at 19:53, Daniel P. Brown <danbrown@php.net> wrote: >>> danbrown                                 Tue, 29 Mar 2011 17:53:56 >>> +0000 >>> >>> Revision: >>> http://svn.php.net/viewvc?view=revision&revision=309816 >>> >>> Log: >>> Add a link and META refresh so we don't have to manually edit the location in the >>> browser (especially on a mobile device). >>> >> >> >> Noo.. That defeats the purpose. You are supposed to update your >> bookmarks and stuff. >> If you get redirected in any way, or given a simple method to continue >> anyway.. You'll never update the bookmark. > >    Does that matter if we're forcing them to use SSL anyway?  I don't > use bookmarks for anything at all, ever, to be honest.... and > remembering to type in https:// every time is a pain, > particularly > when I'm connecting from a mobile device.  I'm sure I'm not the only > one who thinks so, but if you're that much against it, feel free to > revert it. > > > -- > </Daniel P. Brown> > Network Infrastructure Manager > http://www.php.net/ > > -- > PHP Webmaster List Mailing List (http://www.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php > > If a site wishes to enforce https, then let it. From a user's perspective, it makes no difference. I never type the http://www part of an address anyway. I think the auto redirect is just fine. Personally, I'd also drop the 2 second delay and redirect on the server using a rewrite rule. Maybe add a message if the redirect was necessary to say that if you came to the site from a bookmark, then please update it. But, first of all, fixing the lack of a proper cert would be great. Being forced to use https (which is fine) and then being told "The security certificate presented by this website was not issued by a trusted certificate authority.", THAT is more of an issue that a simple redirect. Richard. -- Richard Quadling Twitter : EE : Zend @RQuadling : e-e.com/M_248814.html : bit.ly/9O8vFY

« previous php.webmaster (#10778) next »