I tried to install the module, but found that it does not work for example.com/user authentication. The thing is that I don not have a user login form on my site, it is turned off. If anyone needs authentication he should go to example.com/user/.

Comments

avf’s picture

Assigned: Unassigned » avf
Category: feature » bug
Status: Active » Fixed

This should work now.

Anonymous’s picture

Status: Fixed » Closed (fixed)
sergserv’s picture

Status: Closed (fixed) » Active

I do not see it is working.

1. If I enable the "Login block" and type in it a username and a password then I see the redirection to the https://sitename. However, if I use sitename/user for logging in then there is nothing happens.

2. After authorization using the "Login block" the whole site keeps running through https://, that does not seem right.

avf’s picture

It does work if you use the HEAD version. I've fixed it, but screwed up the tagging when I was trying to commit the change... I'm still trying to figure this out.

Nick Urban’s picture

The version you can download still doesn't work, but it's an easy fix.

To make this work for /user logins, insert:

|| ($form_id == 'user_login' && variable_get('securelogin_loginform', TRUE) == TRUE)

after line 87 in securelogin.module.

abhayuser’s picture

Yes, this secure login works for me.
When i login to the site with http://www.abh.com after login. i got redirected to https://www.abc.com
But for this u need to have valid ssl certificate and need to make one change in sites/defaults/setting.php
Just remove comment from $base_url and give ur sites's https url
:)

gorilla_ch’s picture

sergserv, have you solved the problem, or Nick Urban, have you tried your small code change?

I believe I am in the same situation of sergserv. I turn off the login block. I follow what Nick Urban said to change the code. But /user or /user/register does not work.

When you hover over the login button in "http://example.com/user", you see it will be redirected to "https://example.com/user". However nothing happens after you click the button. same happens to "http://example.com/user/register".

If there is no https redirection, everything works just fine.

gagarine’s picture

The fix on comment #5 work, but you don't see a https on the /user page anyway the form is https protected. I know this ok for the security but the user don't know that and prefer a "yellow url" when he write a passwd ;).

avf’s picture

Status: Active » Closed (fixed)

CVS is now fixed, so this should now be fixed.