View Single Post
  #7  
Old 02-16-2017, 03:46 AM
toddman1111's Avatar
toddman1111 toddman1111 is offline
Senior Member
 
Join Date: May 2005
Posts: 287
Thanks: 10,532
Thanked 1,787 Times in 214 Posts
Default

Thank you very much.

Actually, I had been hoping a admin would actually reply to the message.

Once again, thank you. Most helpful.

Regards...


Quote:
Originally Posted by 636387 View Post
This isn't actually an issue with Tor browser, but the way that sessions are being handled.

Because we now log in over HTTPS, this then sets a cookie for handling your logged in "session", the cookie is being set over HTTPS but then the rest of site is being served over HTTP. By default there are a few browsers that won't honor the session from HTTPS over HTTP (because the session then becomes insecure / could be hijacked etc.)

To fix this issue, you need to disable "Automatic Secure Cookie Management", as per my attached screenshot.

But ideally the Admins would work towards serving the whole site over HTTPS.
Reply With Quote