View Single Post
  #5  
Old 02-06-2017, 05:10 AM
636387 636387 is offline
Member
 
Join Date: Aug 2011
Posts: 33
Thanks: 96
Thanked 953 Times in 29 Posts
Default Not working on Tor

This isn't actually an issue with Tor browser, but the way that sessions are being handled.

Because we now log in over HTTPS, this then sets a cookie for handling your logged in "session", the cookie is being set over HTTPS but then the rest of site is being served over HTTP. By default there are a few browsers that won't honor the session from HTTPS over HTTP (because the session then becomes insecure / could be hijacked etc.)

To fix this issue, you need to disable "Automatic Secure Cookie Management", as per my attached screenshot.

But ideally the Admins would work towards serving the whole site over HTTPS.
Attached Thumbnails
Cookies-Over-TLS.jpg  
Reply With Quote
The Following 2 Users Say Thank You to 636387 For This Useful Post: