using FORCE_SSL_LOGIN and wp-login.php?redirect_to=somepage sometimes redirects to https
|Reported by:||vanillaxtrakt||Owned by:|
|Severity:||normal||Keywords:||FORCE_SSL_LOGIN FORCE_SSL_ADMIN wp-login.php redirect SSL https|
I'm using Wordpress MU 2.8.6, and this also seems to occur in Wordpress 2.7.1.
If you have FORCE_SSL_LOGIN enabled in wp-config.php, are logged out of Wordpress, and visit any page through wp-login.php?redirect_to=somepage, it will redirect to https.
For example, if you're not logged in and you visit:
after logging in, it will send you to:
or if you visit (once again, you have to be logged out):
it will send you to:
It doesn't appear to do this for backend pages (wp-admin).
This bug shows up particularly when using plugins that make you log in to see protected blog content, such as the More Privacy Options plugin, although the bug manifests itself with or without those plugins installed.
I enabled FORCE_SSL_ADMIN and tested the same thing, and it creates a redirect loop.