Well... frankly... thats unacceptible.
If the entire forum is behind SSL then any image any posts that's offsite will generate a message indicating there's mixed secure/insecure data and prompt them if its ok or not... totally useless and a crappy user experience.
I want to secure people's logins - based on what I'm finding I'm just going to have to have my members login when the SSL session expires.
FWIW I have it currently setup so their PMs are also SSL encrypted.
|