Oct 29
kimrvan Ending SSL Connection
Oct 29, 2013; 22:39
kimrvan
Ending SSL Connection
We've been successful in establishing SSL, but when users move to other areas of our website that don't require encryption, https persists.
I've tried:
if(web_request->serverPort == 443) => {
//if(web_request->rawHeader('HTTPS') == 'on') => { // Alternative to checking the port
web_response->replaceHeader('SERVER_PORT' = 80)
web_response->replaceHeader('HTTPS' = false)
web_response->replaceHeader('REMOTE_PORT' = 80)
web_response->replaceHeader('Connection' = 'close') // This works and 'Keep-Alive' parameters disappear too
// web_response->replaceHeader('Set-Cookie' = 'token=deleted; path=/; expires=Thu, 01 Jan 1970 00:00:00 GMT') // Does not affect LassoSessionTracker, of course
web_response->setStatus(307,'Temporary Redirect')
}
When I view the header, I see:
Date: Wed, 30 Oct 2013 02:30:04 GMT
Server: Apache/2.2.24 (Unix) DAV/2 PHP/5.3.26 mod_ssl/2.2.24 OpenSSL/0.9.8y
X-Powered-By: Lasso 9
SERVER_PORT: 80
HTTPS: false
REMOTE_PORT: 80
Connection: close
Set-Cookie: _LassoSessionTracker_foo=bar;expires=Thu, 31-Oct-2013 02:45:04 GMT;path=/
Content-Length: 13341
Content-Type: text/html; charset="UTF-8"
307 Temporary Redirect
But when I log the results, I get:
[2013-10-29 20:29:45] port: 443
[2013-10-29 20:29:45] HTTPS: on
[2013-10-29 20:29:45] HTTPS: keep-alive
Please help the header-noob...
#############################################################
This message is sent to you because you are subscribed to
the mailing list Lasso
Lasso@lists.lassosoft.com
To unsubscribe, E-mail to: <Lasso-unsubscribe@lists.lassosoft.com>
Send administrative queries to <Lasso-request@lists.lassosoft.com>
Oct 29
Tami Williams Re: Ending SSL Connection
Oct 29, 2013; 22:43
Tami Williams
Re: Ending SSL Connection
Oct 29
Jonathan Guthrie Re: Ending SSL Connection
Oct 29, 2013; 23:07
Jonathan Guthrie
Re: Ending SSL Connection
Oct 30
kimv Re: Ending SSL Connection
Re: Ending SSL Connection
Oct 31
jolle Re: Ending SSL Connection
Oct 31, 2013; 05:14
jolle
Re: Ending SSL Connection