Force https is set to true
It's not
I think it should be set, as the installation process was done via https
Labels |
Added:
?
|
Category | ⇒ | com_installer Feature Request |
Status | New | ⇒ | Discussion |
Even one "accidental" login over http can compromise. There should be at least a checkbox in the installer.
An option is an acceptable thing. An arbitrary behavior based on whether one specific request is issued over HTTPS IMO is not.
Labels |
Added:
J3 Issue
|
Status | Discussion | ⇒ | New |
Title |
|
||||||
Build | staging | ⇒ | 4.0-dev |
Features are only available to be applied to J4. Adjusting labels to J4.
Unsubscribing this issue as I don't use Joomla anymore.
Status | New | ⇒ | Closed |
Closed_Date | 0000-00-00 00:00:00 | ⇒ | 2021-08-24 17:23:37 |
Closed_By | ⇒ | jwaisner |
Status | Closed | ⇒ | New |
Labels |
Removed:
?
|
Status | New | ⇒ | Closed |
Closed_By | jwaisner | ⇒ | joomla-cms-bot |
Set to "closed" on behalf of @jwaisner by The JTracker Application at issues.joomla.org/joomla-cms/19444
The force SSL setting shouldn't be arbitrarily enabled in the installer because the request which causes the configuration to be written was performed over HTTPS.