If you've ever used
SqurrelMail
you'll know that it uses SSL for the login then 'drops' back into regular HTTP for the regular stuff. Simple. Inspires confidence.
It occurs to me that there are few palces in TWiki where teh same kind of thing needs to be aplied.
Obviously:
- The registration process. In Dakar that includes entering the activation code that was mailed to the user.
- Changing and/or resetting passwords
- Certain administration functions
Is there any (
simple) way to selelctively enabale SSL for some, possibly arbitrary, topics?
Of course the basic Apache login popup that appears whenever authrization is needed (e.g. to edit a topic) needs to be secured as well.
Either that or completely replace the authenticaton model and make it more like other web applications where there is a clear login button.
See also:
--
AntonAylward - 28 Jun 2005