Forum Discussion
Kanghis_23583
Nimbostratus
Feb 10, 2009http to https redirect
This is a fairly common task: a shopping cart application requires us to secure the transaction. Without the big-ip in place, the flow redirects any request to http:/this.domain.com/this/directory t...
AndrewO_4840
Nimbostratus
Feb 12, 2009Posted By dmkang on 02/10/2009 2:19 PM
{ HTTP::redirect https://"this.domain/"[getfield [HTTP::uri] ? 2]}
} If you're trying to protect the page submission (which is implied by mentioning the form parameters) then you're wasting your time here.
By the time this connection hits your Big/IP the user has already submitted the form via (insecure) HTTP. All you're doing is saying 'oh, you should have submitted that form via (secure) HTTPS, so try again'.
From the user's security standpoint they're already blown.
You really need to catch the page before the form is submitted and make sure that the form is submitted securely in the first place (potentially by having the write rewrite the leading page to make sure the form action points to the secure URL.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects