A cookie with your coffee?

General information and announcements regarding the FlatPress project
Post Reply
User avatar
fraenkiman
Posts: 368
Joined: Thu Feb 03, 2022 7:25 pm
Location: Berlin, Germany
Contact:

A cookie with your coffee?

Post by fraenkiman » Sun Apr 14, 2024 2:45 pm

Hello everyone,

FlatPress supports both HTTP and HTTPS connections.
However, HTTP connections pose an increased security risk.
@prbt2016 has noticed that when using an HTTP connection, FlatPress equips the cookies with incorrect attributes and flags. As a result, it is not possible to log in to the admin area because the browser rejects the fp-sess, fp-user and fp-pass cookies.

This raises the question of whether FlatPress should still support HTTP connections in development and productive operation in the future. I have created an issue about this.

What do you think about this?

Don't eat so many cookies!

With best regards
Frank
:pencil: You are strong in PHP and Java Script? :point_right: Then help us to improve FlatPress. :point_left:

:exploding_head: Looking for ideas, templates, examples and answers to frequently asked questions?
:bulb: You'll find it here.

My :de: FlatPress-Blog: https://frank-web.dedyn.io

User avatar
Arvid
FlatPress Coder
Posts: 625
Joined: Sat Jan 26, 2019 7:40 pm
Contact:

Re: A cookie with your coffee?

Post by Arvid » Sat Apr 20, 2024 12:01 pm

Hi, interesting topic and worth discussing.

My 2 cents: Yes, FlatPress should work on HTTP-only servers. There might be reasons we don't know (testing, internal use, you name it) - we should leave every user the freedom of choice. But of course we'll keep encouraging users to go secure!

What do the others think?
Are you running FlatPress HTTP-only - and why?

Happy to receive your opinions!
All the best,
Arvid

User avatar
Arvid
FlatPress Coder
Posts: 625
Joined: Sat Jan 26, 2019 7:40 pm
Contact:

Re: A cookie with your coffee?

Post by Arvid » Sat Apr 20, 2024 7:41 pm

Feedback by Felix on Mastodon:
On some hosts there may be no choice. For example InfinityFree doesn't seem to provide automatic HTTPS on free accounts.

Post Reply

Who is online

Users browsing this forum: No registered users and 0 guests