3 ms·
Thanks. HTTPS is now live. :)
by aparks517 10y ago
Thanks. HTTPS is now live. :)
- bencollier49 10y agoBut you've got the secret site key in your server logs as it's in all the GET statements. Don't use third-party log analysis would be the suggestion I suppose.
- lettersdigits 10y agoi didn't even think about that angle (being careful from third party logs for http GETs with sensitive info in the url). thanks
- lettersdigits 10y agoi think it's not enough: one of the comments of the question here: http://stackoverflow.com/questions/499591/are-https-urls-encrypted http://stackoverflow.com/questions/499591/are-https-urls-enc... says: "It's probably a bad idea to put confidential data in the URL anyway. It will be displayed in the browser's address bad too, remember? People don't like it if their password is visible to anyone who happens to glance at the screen" you can just display a form with an input field for the secret key, which will be HTTP POSTed and only THEN you should display the account's data (while the url doesn't disclose the secret key)