<?xml version="1.0" encoding="UTF-8"?> 
<?xml-stylesheet href="https://dev.horde.org/themes/horde//default/feed-rss.xsl" type="text/xsl"?> 
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"> 
 <channel> 
  <title>Sidebar doesn&#039;t respect use_ssl setting</title> 
  <pubDate>Thu, 09 Apr 2026 14:48:25 +0000</pubDate> 
  <link>https://bugs.horde.org/ticket/8528</link> 
  <atom:link rel="self" type="application/rss+xml" title="Sidebar doesn&#039;t respect use_ssl setting" href="https://bugs.horde.org/ticket/8528/rss" /> 
  <description>Sidebar doesn&#039;t respect use_ssl setting</description> 
 
   
   
  <item> 
   <title>The user stays on https after logging in.</title> 
   <description>The user stays on https after logging in.</description> 
   <pubDate>Wed, 26 Aug 2009 10:52:32 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/8528#t55546</link> 
  </item> 
   
  <item> 
   <title>I don&#039;t see this.



1. URL to non-secure page

2. Redirecte</title> 
   <description>I don&#039;t see this.



1. URL to non-secure page

2. Redirected to non-secure login page, with POST action of secure-login page

3. Process login in horde/login.php.  If verified, loads index.php.  index.php either redirects to the original URL if given (see #1) or uses initial application settings.  All of these initial application URLs are generated via url() or applicationUrl() without the force_ssl override.</description> 
   <pubDate>Mon, 31 Aug 2009 17:53:34 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/8528#t55604</link> 
  </item> 
   
  <item> 
   <title>See bugs.horde.org.</title> 
   <description>See bugs.horde.org.</description> 
   <pubDate>Mon, 31 Aug 2009 22:36:07 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/8528#t55610</link> 
  </item> 
   
  <item> 
   <title>Changes have been made in CVS for this ticket:

http://cvs.h</title> 
   <description>Changes have been made in CVS for this ticket:

http://cvs.horde.org/diff.php/horde/templates/index/frames_index.inc?rt=horde&amp;r1=2.46&amp;r2=2.47&amp;ty=u</description> 
   <pubDate>Mon, 31 Aug 2009 23:27:40 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/8528#t55612</link> 
  </item> 
   
  <item> 
   <title>This was only partially broken.  The sidebar link in the fra</title> 
   <description>This was only partially broken.  The sidebar link in the frameset source was not a full URL.  But everything in the main window was correctly loading non-securely.</description> 
   <pubDate>Mon, 31 Aug 2009 23:31:45 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/8528#t55613</link> 
  </item> 
   
  <item> 
   <title>Now I see what the problem is. We no longer redirect after l</title> 
   <description>Now I see what the problem is. We no longer redirect after logging in, thus the frameset is loaded over HTTPS (by means of the login form), while the frames are plain HTTP. This should of course not happen, because it makes the user think he is accessing Horde over HTTPS.

But it&#039;s probably not worth fixing this, when the frameset is going away anyway.</description> 
   <pubDate>Tue, 01 Sep 2009 08:23:04 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/8528#t55617</link> 
  </item> 
   
   
 
 </channel> 
</rss> 
