Details
-
Sub-task
-
Status: Closed
-
Major
-
Resolution: Won't Do
-
Trunk
-
None
-
None
-
Bug Crush Event - 21/2/2015
Description
When doing OFBIZ-6849 I forgot to take care of the https attribute of the security element used in controllers.
It's not used anymore since we used HTTPS everywhere but in request listed in http.request-map.list property of url.properties. It's even enforced by HSTS for requests that are not listed in this property.
So I'll remove the https attribute and remove its usage in in controllers.
This is part of handling a security issue, so will be backported in supported branches when needed.
Attachments
Issue Links
- is a clone of
-
OFBIZ-6849 Use only HTTPS in OFBiz
- Closed