From: Václav R. <xro...@gm...> - 2012-04-13 18:55:17
|
Hi If you insist on SSL AJAX login - Cross-Origin Resource Sharing: http://www.w3.org/TR/cors/ But not all browsers support it. Vasek Dne 13. dubna 2012 20:45 Demian Katz <dem...@vi...> napsal(a): > I don't think there's a simple solution here... which is frustrating, since it seems like a perfectly reasonable thing to want to post from a non-SSL page to an SSL page on the same domain. I can understand why Same Origin Policy blocks the reverse case, but this one seems like it should be allowed. Oh well, too late to change it now! > > At Villanova, we resigned ourselves to forcing everything to SSL. There are hacks to avoid SOP, but I wouldn't trust any of them to be stable over time. Another alternative (though not a particularly attractive one) would be to disable the lightbox login and force users into the non-JS mode. It won't look nice, but it should be fully functional. > > Obviously, if you do find a better answer, I'd love to hear about it... but I don't have one on offer, unfortunately. > > - Demian > ________________________________________ > From: Tuan Nguyen [tu...@yo...] > Sent: Friday, April 13, 2012 1:39 PM > To: vuf...@li... > Subject: [VuFind-Tech] ssl ajax login > > Hi all, > > The current ajax login window submits the password in somewhat encrypted form. Our administrator insists that all login information should be sent via HTTPS. We don't want to run VuFind in HTTPS, only the ajax login since the normal login screen is fine, all we had to do is change the form action to use HTTPS. Anyone able to workaround the Same Original Policy restriction when submitting over SSL? > > Thanks, > T > ------------------------------------------------------------------------------ > For Developers, A Lot Can Happen In A Second. > Boundary is the first to Know...and Tell You. > Monitor Your Applications in Ultra-Fine Resolution. Try it FREE! > http://p.sf.net/sfu/Boundary-d2dvs2 > _______________________________________________ > Vufind-tech mailing list > Vuf...@li... > https://lists.sourceforge.net/lists/listinfo/vufind-tech > > ------------------------------------------------------------------------------ > For Developers, A Lot Can Happen In A Second. > Boundary is the first to Know...and Tell You. > Monitor Your Applications in Ultra-Fine Resolution. Try it FREE! > http://p.sf.net/sfu/Boundary-d2dvs2 > _______________________________________________ > Vufind-tech mailing list > Vuf...@li... > https://lists.sourceforge.net/lists/listinfo/vufind-tech |