Solved

Response.redirect from https to http without getting a you are about to leave a secure site message

Posted on 2006-11-23
16
234 Views
Last Modified: 2008-02-01
Hi

Im currently developing 2 pages on a secure https site. When these pages finish processing I need to redirect to a non secure http page.
The problem is page1 calls page 2 (both https pages), page 2 does some processing then redirects to page 3 ( a http) page.
When the form on page 1 is submitting because its being redirected to page 3 a http page, Im getting the error- you are about to be directed to a non secure site do you want to continue.

Any ideas to get around this?

Cheers

Louise
0
Comment
Question by:louise_8
  • 7
  • 4
  • 3
16 Comments
 
LVL 6

Expert Comment

by:hc0904pcd
Comment Utility
Can you modify the process slightly?
I'd suggest that if page3 could remain https, then the user ends up on a secure site - so when they move on from that page they can see what's happening.

A typical use might be sales site - the thank you & receipt page should remain https, so they don't get that warning message while the sale is ongoing, only after it's obviously completed.

Does that help in your case?
0
 

Author Comment

by:louise_8
Comment Utility
Thanks for your suggestion.
Unfortunately Im working on behalf of a client who posts us data from their http site, we process via https and they need the info to go back to their http site :(
0
 
LVL 6

Expert Comment

by:hc0904pcd
Comment Utility
It just occurred to me - I have a page that does just what you're saying.
A client with no scripting or db support, so a form on their site submits to secure script on my site, processes the form, logs the action, and redirects to various pages back at the client site. http to https to http, and I've never had a message about leaving the secure site.
I'll test this and get back to you.
0
 
LVL 6

Expert Comment

by:hc0904pcd
Comment Utility
Okay, I don't think you can do this.

IF a user does not tick the checkbox that says "In the future do not show this warning" then they WILL get an alert warning message every time they enter or leave a secure site. There's no way around that that I know of.
0
 
LVL 6

Expert Comment

by:hc0904pcd
Comment Utility
Is using an xml post an option?
I'm not an expert on that, but it might be worth googling, or asking a question in the xmlsection, as to whether your process could be done using xml and if so can it be transparent to the user
0
 
LVL 58

Accepted Solution

by:
amit_g earned 125 total points
Comment Utility
This is browser setting and can't be overridden from any server side script or trick. There is no way around this so the only solution is to host the last page also in https or let the user click that button. BTW, this is not an error but an informative message for the user given by the browser whenever a sites redirects from https to http.
0
 
LVL 6

Expert Comment

by:hc0904pcd
Comment Utility
thanks Amit.
so an XML post is no different in this respect to an html post?
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 58

Expert Comment

by:amit_g
Comment Utility
XMP post might only help if the third page is not to be shown to the user. Even in that case we might see the warning as again for anything unsecure within the secured page, the browser is supposed to show that warning if the user hasn't instructed it to not show that warning.
0
 

Author Comment

by:louise_8
Comment Utility
Thanks, Ill look up XMP and see if that helps

appreciate your comments guys
0
 

Author Comment

by:louise_8
Comment Utility
XMP doesnt help me :(

Thanks again for your comments
0
 
LVL 6

Expert Comment

by:hc0904pcd
Comment Utility
sorry I couldn't help ...
0
 
LVL 58

Expert Comment

by:amit_g
Comment Utility
As I said earlier, this is client browser setting and it can't be controlled from server using any language.
0
 
LVL 6

Expert Comment

by:hc0904pcd
Comment Utility
my 2 cents worth, either refund points or give them to Amitg. He didn't give you the answer you were looking for, but he was right when he said it couldn't be done, and said why.
0
 
LVL 58

Expert Comment

by:amit_g
Comment Utility
I agree. The answer to this question is that it can't be done and that should be selected as an Accepted answer here. This is also a valid PAQable question as per http:help.jsp#hi54 and http:help.jsp#hi89 . If the questioner has problem with awarding points, I am ok with PAQ/Refund.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Hello, all! I just recently started using Microsoft's IIS 7.5 within Windows 7, as I just downloaded and installed the 90 day trial of Windows 7. (Got to love Microsoft for allowing 90 days) The main reason for downloading and testing Windows 7 is t…
Have you ever needed to get an ASP script to wait for a while? I have, just to let something else happen. Or in my case, to allow other stuff to happen while I was murdering my MySQL database with an update. The Original Issue This was written…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now