decline, maybe sort of?
Posted by
Beryllium (aka grayman)
Jun 15 '22, 10:43
|
What I'd have to do is say "if this is an officially supported domain, always elevate to HTTPS" yet still allow traffic via HTTP for unofficial domains.
That way IP address based access would also work, in a pinch.
But I'd prefer to go full HTTPS, which would mean dropping support for unofficial domains. A bit of a blocker there, because I don't want to drop that support.
|
Responses:
|