CBSubs and https

12 years 9 months ago #170583 by byrannewell
CBSubs and https was created by byrannewell
Although I want people to feel secure when entering credit card information, the https part of the site seems to have a problem. Specifically, when the user is finished with the CBSubs part of the transaction, when they click any link on the site, all links are now HTTPS, not HTTP.

First, I need to switch them back to HTTP. Secondly, it seems that the entire session is not encrypted, and the browser throws a security warning, stating in effect that some parts of the session are encrypted, and some are not. Is it possible to make people feel even better about putting in their credit card info, and make the entire session encrypted? My certificate is valid, and issued for my site.

Please Log in to join the conversation.

12 years 9 months ago #170696 by krileon
Replied by krileon on topic Re: CBSubs and https

Although I want people to feel secure when entering credit card information, the https part of the site seems to have a problem. Specifically, when the user is finished with the CBSubs part of the transaction, when they click any link on the site, all links are now HTTPS, not HTTP.

Once switchover is made to HTTPS a user can't switch back without causing a browser security error. They only way to switch back is for the user to manually navigate back to HTTP. Posting from HTTPS and HTTP isn't valid as it will say the user is posting to HTTP and the post data would be insecure. In most cases if you've the certificate it's best to just keep them in HTTPS at all times.

First, I need to switch them back to HTTP. Secondly, it seems that the entire session is not encrypted, and the browser throws a security warning, stating in effect that some parts of the session are encrypted, and some are not. Is it possible to make people feel even better about putting in their credit card info, and make the entire session encrypted? My certificate is valid, and issued for my site.

Please check within CBSubs > Settings > Credit-cards that you've set "User login session on https switchover:" to "Logout user from http on https switchover" and "Credit-Card Form http(s) mode:" is set to "HTTPS (normal secure mode required for normal credit-cards)". This could also mean content you've added to descriptions or maybe a custom button image is configured with HTTP instead of HTTPS.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in to join the conversation.

Moderators: beatnantkrileon
Time to create page: 0.208 seconds