Page 1 of 1

FEU - not logged in on insecure pages

Posted: Thu Feb 09, 2017 12:56 am
by rotezecke
I have a website where most pages are insecure: "http://www.somedomain.com". I installed FEU (2.3) and placed the login form on a secure page. Note: my secure URL looks like this "https://secure.somedomain.com". When doing it this way, none of the insecure pages recognise that the user is logged in. Any idea what to do in these situations?


----------------------------------------------

Cms Version: 2.1.6

Installed Modules:

CGBlog: 1.14.1
CGExtensions: 1.53.17
CGFeedback: 1.8.2
CGSimpleSmarty: 2.1.6
CGSmartImage: 1.21.5
CMSContentManager: 1.1.4
CMSMailer: 6.2.14
Captcha: 0.5.3
DesignManager: 1.1.1
FileManager: 1.5.2
FormBuilder: 0.8.1.4
FrontEndUsers: 2.3
JQueryTools: 1.3.9
ModuleManager: 2.0.5
Navigator: 1.0.3
News: 2.50.6
Search: 1.50.2


Config Information:

php_memory_limit:
max_upload_size: 16000000
url_rewriting: mod_rewrite
page_extension: .html
query_var: page
auto_alias_content: true
locale:
set_names: true
timezone: Australia/Brisbane
permissive_smarty: false


Php Information:

phpversion: 7.0.15
md5_function: On (True)
json_function: On (True)
gd_version: 2
tempnam_function: On (True)
magic_quotes_runtime: Off (False)
E_ALL: 32759
E_STRICT: 2048
E_DEPRECATED: 8192
test_file_timedifference: No time difference found
test_db_timedifference: No time difference found
create_dir_and_file: 1
memory_limit: 256M
max_execution_time: 30
register_globals: Off (False)
output_buffering: 4096
disable_functions:
open_basedir:
test_remote_url: Success
file_uploads: On (True)
post_max_size: 16M
upload_max_filesize: 16M
session_save_path: /tmp (0700)
session_use_cookies: On (True)
xml_function: On (True)
xmlreader_class: On (True)
check_ini_set: On (True)
curl: On


Performance Information:

allow_browser_cache: Off (False)
browser_cache_expiry: 0
php_opcache: Off (False)
smarty_cache: Off (False)
smarty_compilecheck: Off (False)
smarty_cache_udt: Off (False)
auto_clear_cache_age: On (True)

Server Information:

Server Software: Apache
Server Api: cgi-fcgi
Server Os: Linux 2.6.32-673.8.1.lve1.4.3.el6.x86_64 On x86_64
Server Db Type: MySQL (mysqli)
Server Db Version: 10.0.25
Server Db Grants: Found a "GRANT ALL" statement that appears to be suitable


Permission Information:

tmp: /home/x/public_html/tmp (0755)
tmp_cache: /home/x/public_html/tmp/cache (0755)
templates_c: /home/x/public_html/tmp/templates_c (0755)
modules: /home/x/public_html/modules (0755)
uploads: /home/x/public_html/uploads (0755)
File Creation Mask (umask): /home/x/public_html/tmp/cache (0755)
config_file: 0444

----------------------------------------------

Re: FEU - not logged in on insecure pages

Posted: Fri Feb 10, 2017 8:08 am
by velden
I *think* it has to do with how a FEU cookie is set for the FEU user. It's path might be limited to that specific (sub)domain (www.) and perhaps even limited to https only.

If it's not in the configuration options of FEU you might be able to alter this settings using an UDT connected to some FEU event (if exist).

Of course you first want to check and test all this using a web developer tool like firebug.

Some reference: http://php.net/manual/en/function.setcookie.php