[wp-trac] [WordPress Trac] #9207: redirect_to wp-admin Should Force SSL If FORCE_SSL_ADMIN is enabled

WordPress Trac noreply at wordpress.org
Sat Apr 6 20:36:05 UTC 2013


#9207: redirect_to wp-admin Should Force SSL If FORCE_SSL_ADMIN is enabled
-----------------------------------------+-----------------------------
 Reporter:  g30rg3x                      |       Owner:  hakre
     Type:  defect (bug)                 |      Status:  accepted
 Priority:  normal                       |   Milestone:  Future Release
Component:  Security                     |     Version:  2.9
 Severity:  normal                       |  Resolution:
 Keywords:  has-patch reporter-feedback  |
-----------------------------------------+-----------------------------
Changes (by keytuna):

 * cc: keytuna (added)


Comment:

 Attempted to reproduce issue with version 3.5.1 of WordPress, XAMPP 1.8.1,
 and Curl 7.29.0.

 Used default settings, attempted with this command:

     curl -v -X POST http://localhost/wordpress/wp-
 login.php?redirect_to=http%3A%2F%2Flocalhost%2wordpress%2Fwp-
 admin%2Findex.php

 Expected to see a 302 redirect, found a 200 OK response.

 Is anyone else still able to reproduce this issue?

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/9207#comment:12>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list