Re: [Tiki-devel] "Stay in SSL" login option at t.o websites
Jonny Bradley via TikiWiki-devel <[email protected]>
| Newsgroups | gmane.comp.cms.tiki.devel |
|---|---|
| Message-ID | <[email protected]> |
Thanks Jean-Marc, so the default should be “n” from now on? jonny > On 10 Mar 2021, at 01:07, Jean-Marc Libs <[email protected]> wrote: > > > Agreed. Since the tiki.org sites all are configured with SSL, allowing non-SSL access makes no sense anymore. Once upon a time there was concern about the extra CPU consumed by browsers for SSL encryption but nowadays much more CPU is eaten by javascript than SSL. > > Plus, tiki.org forces https so not staying in SSL mode is not even possible. > > I switched it off: > The following change has been applied > Preference feature show stay in ssl mode disabled (Preference name: feature_show_stay_in_ssl_mode) > We can switch it on again if anyone can come up with a reason. > > Cheers, > J-M >> On Tue, Mar 9, 2021 at 12:49 PM Bsfez Tiki via TikiWiki-devel <[email protected]> wrote: >> Hi Jonny, >> >> It is not the option itself for Tiki that is bothering me. >> >> It is the option visible on t.o websites login modal. >> I think t.o is the only place where I see such checkbox about ssl and it look oldish to me. >> >> <Screen Shot 2021-03-09 at 13.46.12 .png> >> >>> On 9 Mar 2021, at 12:40 , Jonny Bradley via TikiWiki-devel <[email protected]> wrote: >>> >>> Hi Bernard >>> >>> I can't see much advantage in removing it, it's advanced and defaults to "y". >>> >>> We would have to be careful about enabling ssl using the install process as if the server's not set up correctly you can get locked out of your site, so it would have to be tested somehow, but would be "nice to have" (low priority imho ;) >>> >>> jonny >>> >>> >>> >>>> On 9 Mar 2021, at 05:24, Bsfez Tiki via TikiWiki-devel <[email protected]> wrote: >>>> >>>> Hello, >>>> >>>> I think SSL should be used anywhere and we should remove the option "Stay in ssl mode" on t.o website. >>>> It look like old days. ;-) >>>> >>>> About this, while it is important to keep "non-ssl" option at install, shoudln’t we adapt a bit our default settings? >>>> >>>> Bernard >>>> >>>> _______________________________________________ >>>> TikiWiki-devel mailing list >>>> [email protected] >>>> https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel >>> >>> >>> >>> _______________________________________________ >>> TikiWiki-devel mailing list >>> [email protected] >>> https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel >> >> _______________________________________________ >> TikiWiki-devel mailing list >> [email protected] >> https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel > _______________________________________________ > TikiWiki-devel mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel _______________________________________________ TikiWiki-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel