HTTP not redirecting to HTTPS on

Philipp Richter richterphilipp.pops at
Tue Sep 11 19:05:03 AEST 2018


I noticed that accessing did not automatically
redirect to HTTPS. The validation link sent in the e-mail also doesn't
have https:// prepended to it.
This is a bit risky while registering or logging in. This was first
apparent from which linked to
the http unsecured patchwork page, they already committed a forced
https:// on the link.

I would strongly suggest forcing a 301 redirect to the https version
of the site in the webserver configuration.

Thank you for hearing me out.

Best Regards,
Philipp Richter

More information about the Patchwork mailing list