? Error

User tests: Successful: Unsuccessful:

avatar elinw
elinw
3 Oct 2013
avatar elinw elinw - open - 3 Oct 2013
avatar brianteeman
brianteeman - comment - 13 Oct 2013

Please can you create a corresponding item on joomlacode - thanks

avatar beat
beat - comment - 19 Oct 2013

As commented on tracker:

For security reasons, remember-me must always be:

  1. http-only (never accessible by javascript)
  2. https-only if the login happened on https.

I do sincerely not see any reasons to have those user-settable.

avatar beat
beat - comment - 19 Oct 2013

I see that currently they are not set as they should be.

Which is a vulnerability in 3.2.0 beta 1 only.

avatar Bakual
Bakual - comment - 2 Mar 2014

Due to the changes made to remember-me, this one would probably have to be rebuilt from scratch.

avatar Bakual Bakual - close - 2 Mar 2014

Add a Comment

Login with GitHub to post a comment