Suggestion Login page should force HTTPS

    • Thread starter Deleted member 392097
    • Start date
    D

    Deleted member 392097

    Guest
    I recently noticed that there is an HTTP version of the StarMade Registry and in fact seemingly all StarMade sites. The HTTP one is the default one I got to and the one linked from the HTTP version of the site. To prevent users sending their information as plain-text over the network all the links to the StarMade Registry login page (at least) should be the HTTPS versions, and there really shouldn't be an HTTP version of the page as it should be secure in all circumstances. There are many pages where it simply doesn't matter, but the ones where it does you should find an insecure version as well.
     
    Last edited by a moderator:

    DukeofRealms

    Count Duku
    Joined
    Sep 4, 2013
    Messages
    1,475
    Reaction score
    1,616
    • Schine
    The HTTP one is the default one I got to and the one linked from the HTTP version of the site. To prevent users sending their information as plain-text over the network all the links to the StarMade Registry login page (at least) should be the HTTPS versions
    This is because you were using our old (no longer supported) theme framework. I have set your account to use the default one, which has all links to the Registry in HTTPS. I've also changed the old theme to use HTTPS as well, just in case there are others who have this set.

    As for your request to force HTTPS over registry.star-made.org, a task for this has been created: ⚓ T1745 Force HTTPS for Citizen's Registry
     
    D

    Deleted member 392097

    Guest
    This is because you were using our old (no longer supported) theme framework. I have set your account to use the default one, which has all links to the Registry in HTTPS. I've also changed the old theme to use HTTPS as well, just in case there are others who have this set.
    Right, thank you. As I haven't been on for a while I don't know how it went with the changing of the theme framework, that is I don't know if you announced it or what happened. But I think it might be useful for those still running the old one and unaware of it for there to be some sort of notice about this on the old one. Perhaps at the top of every page there should be a little band at the top informing them of this, and giving them the option to ignore the message or change to the new one. Just that when I came on there didn't seem to be anything obvious informing me of this so I don't know how I would have found out if I hadn't have posted this thread.
     

    DukeofRealms

    Count Duku
    Joined
    Sep 4, 2013
    Messages
    1,475
    Reaction score
    1,616
    • Schine
    Right, thank you. As I haven't been on for a while I don't know how it went with the changing of the theme framework, that is I don't know if you announced it or what happened. But I think it might be useful for those still running the old one and unaware of it for there to be some sort of notice about this on the old one. Perhaps at the top of every page there should be a little band at the top informing them of this, and giving them the option to ignore the message or change to the new one. Just that when I came on there didn't seem to be anything obvious informing me of this so I don't know how I would have found out if I hadn't have posted this thread.
    To get the old theme, you must enable it, it's not on by default.

    2016-07-29_2248.png

    There are only a few people who have the old theme enabled. You may have changed it by accident at some point. There is a warning when you choose it.
     
    D

    Deleted member 392097

    Guest
    To get the old theme, you must enable it, it's not on by default.

    View attachment 29835

    There are only a few people who have the old theme enabled. You may have changed it by accident at some point. There is a warning when you choose it.
    That's strange, I don't think I enabled it... When was it depreciated? And did all with the default get switched over automatically to the new one? Because then that is most strange...
     

    DukeofRealms

    Count Duku
    Joined
    Sep 4, 2013
    Messages
    1,475
    Reaction score
    1,616
    • Schine
    Four months ago. Yes, everyone was automatically moved over to the new (now default) theme.
     
    D

    Deleted member 392097

    Guest
    Four months ago. Yes, everyone was automatically moved over to the new (now default) theme.
    Then that is most strange because I haven't been on the site since last June as far as I know and would have been using the then default. Unless the new and old ones were available then? But I still think I would have kept with the default so that is very odd...
     

    DukeofRealms

    Count Duku
    Joined
    Sep 4, 2013
    Messages
    1,475
    Reaction score
    1,616
    • Schine
    Then that is most strange because I haven't been on the site since last June as far as I know and would have been using the then default. Unless the new and old ones were available then? But I still think I would have kept with the default so that is very odd...
    We have had different themes in the past, you may have chosen a non-default theme.
     

    DukeofRealms

    Count Duku
    Joined
    Sep 4, 2013
    Messages
    1,475
    Reaction score
    1,616
    • Schine
    What are you using for your avatar? It doesn't look like it uploaded correctly.
     
    D

    Deleted member 392097

    Guest
    What are you using for your avatar? It doesn't look like it uploaded correctly.
    Oh, so it's not just me who can't see it on certain pages (I can see it on some)? It should be a png of a Panda with its hand over its mouth...
     
    D

    Deleted member 392097

    Guest
    Could you try and reupload the file?
    Ok, I have re-uploaded it and now it is visible for me seemingly everywhere now. Maybe it was because I uploaded it using the old framework?

    Here is what the settings looked like before I changed it just now:

    No_Images_StarMade_Avatar_Settings.png

    But now they show what I have selected. Strangely though I'm pretty sure I had already set the Featured Badges option ages ago, but maybe changing the framework shook things up a little.
     
    D

    Deleted member 392097

    Guest
    I just thought I should let you know that when I go to any page, the links at the top (e.g.: Home, NEWS, etc...) which are not links to the same domain and matching sub-domain are HTTP links, whereas if I go to a page which has the same sub-domain then the link is in HTTPS. So for instance I will get to the HTTP version of the registry login page if I navigate from the home page or any other page whose sub-domain (if any) and top domain are not an exact match. This occurs both when logged in and when not logged in.