The module http://drupal.org/project/securepages_prevent_hijack is an important enhancement for securepages. I think it should be listed on the project page, like:

Users who are looking for protection against a sniffer reading form data in the clear should use securepages. If you also want to prevent the "hijack" of a user's session then you will need to also use the Securepages Hijack Prevention module.

Comments

joelstein’s picture

What about just merging the two together, since in most cases people need both anyway? Are they maintained by the same person?

greggles’s picture

That does seem better to me as well to merge them. I don't know why they are separate. They are not the same author.

gordon’s picture

Basically the reason I have not included this patch was because it was going to break things that I am in the process of implementing such as shared ssl support.

greggles’s picture

Sure, but you could add it to the project page for users of the 6.x-1.* (I assume your new features will be in a 2.x branch).

Anonymous’s picture

Mod parent up.

It seems absurd that securepages does not do this out of the box. Glad there is already a plan to integrate these.

mlncn’s picture

Status: Needs review » Fixed

The project page currently has this text:

Related modules:

Users of this module should consider using Secure Pages Hijack Prevention which makes "mixed mode" SSL more secure.

greggles’s picture

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.