From: lpsolit%gmail.com <> Date: Mon, 22 Aug 2005 02:27:40 +0000 (+0000) Subject: Bug 300093: index.cgi remains unsecure when the SSL parameter is set to "authenticate... X-Git-Tag: bugzilla-2.21.1~102 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=353e7fc0eadd7f3622d036713aa402ce5868ac9a;p=thirdparty%2Fbugzilla.git Bug 300093: index.cgi remains unsecure when the SSL parameter is set to "authenticated sessions" - Patch by Frédéric Buclin r/a=justdave --- diff --git a/index.cgi b/index.cgi index bc3a1272fc..694292fc7b 100755 --- a/index.cgi +++ b/index.cgi @@ -43,6 +43,12 @@ Bugzilla->login(LOGIN_OPTIONAL); ############################################################################### my $cgi = Bugzilla->cgi; +# Force to use HTTPS unless Param('ssl') equals 'never'. +# This is required because the user may want to log in from here. +if (Param('sslbase') ne '' and Param('ssl') ne 'never') { + $cgi->require_https(Param('sslbase')); +} + my $template = Bugzilla->template; # Return the appropriate HTTP response headers. diff --git a/template/en/default/global/useful-links.html.tmpl b/template/en/default/global/useful-links.html.tmpl index 5a01a5703d..2ac89f91c6 100644 --- a/template/en/default/global/useful-links.html.tmpl +++ b/template/en/default/global/useful-links.html.tmpl @@ -29,7 +29,7 @@