Links to WT, from notification emails - http vs. https

Discussion in 'Forum Information and Issues' started by Big Train James, 29 December 2020.

  1. Big Train James

    Big Train James Western Thunderer

    Hi Adrian,
    If I navigate to Western Thunder from either of the links included in a notification email, I'm sent to the unsecured version (http) of the site. When it was suggested a while back, I changed my site bookmark to navigate to the secured version (https).

    This may have always been the case with the notification emails, but I would never have noticed because I never witnessed any issue. Lately however, when sent to the unsecured site, my existing cookie (or whatever it is) isn't recognized, and I am considered to be not logged in. In fact, even after logging into the unsecured site (not initially realizing the situation), I'm still not recognized as having logged in.

    wt-login.JPG

    Granted, this really amounts to a minor inconvenience, but it is a touch annoying. Partly I'm mentioning it to see if there is any way to get the email notification links to point to the secure site. The other reason is this might actually be something meaningful to you as the person tasked with administering the website. Oh, and as a "how things work curiosity" thing, are the secured and unsecured versions of a site considered to be distinct with respect to cookies and passwords?

    And as always, it could simply be down to me doing something wrong. Always a possibility. :oops::rolleyes:

    Cheers,
    Jim
     
  2. adrian

    adrian Flying Squad

    Hi,

    Thanks for flagging that up - I've had a look at the template used to generate the notification email and I think I spotted where the problem was. I think I've sorted it. The next time you get a notification email please can you check if it is now pointing to the https version of the site.

    As for the "secured" and "unsecured" versions and the respective cookies - my understanding is that the same session id cookie is applied to both the secure site and unsecure version which are to the best of purposes identical as we store the absolute minimum possible set of cookies.

    Regards

    Adrian
     
    Big Train James likes this.
  3. Big Train James

    Big Train James Western Thunderer

    Hi Adrian,
    Thanks for your reply. The link from the notification email regarding your reply works perfectly now. It brought me straight to the https site, and correctly recognized any cookies so that I am shown logged in.

    Cheers,
    Jim
     
    adrian likes this.
  4. adrian

    adrian Flying Squad

    Thanks for letting me know.