26 ms·
Could you put your ssl stuff on a different subdomain to prevent the browser from doing this?
by imsteve 19y ago
Could you put your ssl stuff on a different subdomain to prevent the browser from doing this?
- tlrobinson 19y agoSubdomains are also considered different origins. There are other ways around it, like using <script> tags. As far as whether or not that would prevent falling back to non-SSL, I doubt it.
- imsteve 19y agoBut if it can't make the connection to a non-SSL server on that domain then it can't send a cookie, I'd think. Unless it falls over to the non-subdomain.