Problem
The session cookie is marked Secure unless SESSION_SECURE=false is set. Browsers only keep a Secure cookie over https or on localhost. Someone installing on a home server and opening http://192.168.1.20:7000 therefore cannot get past the setup code (#664): the code is accepted, the cookie is dropped, and the same page comes back. Before #664 the same thing made every login fail on such a site.
The setup-code page explains this in small print, but nothing detects it.
Ideas
- Decide
Secure per request: set it when the request arrived over https (directly, or X-Forwarded-Proto: https from a trusted proxy) and leave it off otherwise.
- Or detect the loop (right code, no cookie on the next request) and show a clear message with the fix.
Follow-up to #664.
Problem
The session cookie is marked
SecureunlessSESSION_SECURE=falseis set. Browsers only keep a Secure cookie over https or onlocalhost. Someone installing on a home server and openinghttp://192.168.1.20:7000therefore cannot get past the setup code (#664): the code is accepted, the cookie is dropped, and the same page comes back. Before #664 the same thing made every login fail on such a site.The setup-code page explains this in small print, but nothing detects it.
Ideas
Secureper request: set it when the request arrived over https (directly, orX-Forwarded-Proto: httpsfrom a trusted proxy) and leave it off otherwise.Follow-up to #664.