= Description = ## Please read this page. Lines prefixed with ## such as this one are comments, ## you can remove them (except for those after the "Plan" section.) ## Please follow the instructions given in those comments and the text. ## After creating the bug page, please subscribe to it! We may have questions ## that only you can answer, and if you get email when your bug changes it'll ## be much faster to get it fixed since you can answer the questions! I'm using HTTPS for my moinmoin wiki. Apparently, cookies should then be marked as "secure" by the wiki: * http://it.slashdot.org/article.pl?sid=08/09/09/1558218 * http://it.slashdot.org/comments.pl?sid=958457&cid=24936127 If it's not done, a man-in-the-middle attack can easily steal the cookie despite the secure connection. The attacker can then access the wiki using the victim's user account. == Steps to reproduce == ## Describe the steps needed to reproduce the bug. If we can't reproduce it, we probably can't fix it. 1. Log in to a moinmoin wiki. 2. Inspect the cookie you get. It is not marked as "secure". == Component selection == ## Where you think is this bug happening ? (general, plugin [plugin name], theme [theme name], ... * general == Details == ## If you got a traceback, please save the traceback page as html and attach here: ## [[attachment:traceback.html]] ## if the bug is in this wiki, just kill the table and write: This Wiki. ## If a traceback is not available, please fill in the details here: || '''!MoinMoin Version''' || 1.5.8-5.1ubuntu2 || || '''OS and Version''' || Ubuntu 8.04 || || '''Python Version''' || 2.5.2-0ubuntu1 || || '''Server Setup''' || Apache with HTTPS || || '''Server Details''' || || || '''Language you are using the wiki in''' (set in the browser/UserPreferences) || || == Workaround == ## How to deal with the bug until it is fixed = Discussion = Moin 1.5 is not supported any more, but it will be fixed in the current version 1.7. [[http://fscked.org/blog/how-properly-provide-mixed-http-and-https-support|How to Properly Provide Mixed HTTP and HTTPS Support]] Thanks for fixing the bug! Excellent response time :) = Plan = ## This part is for Moin``Moin developers: * Priority: * Assigned to: * Status: fixed by http://hg.moinmo.in/moin/1.7/rev/be4cefe2a219 (also merged into 1.8) ---- ## If you are a moin core developer, replace the category to Category* in these cases: ## Category MoinMoinNoBug - if this is not a bug. ## Category MoinMoinBugConfirmed - if you can confirm the bug on current code. ## Category MoinMoinBugFixed - after the bug is fixed in current code. CategoryMoinMoinBugFixed