Admin Toolbar Forces https

Options
Since 6.51, any page with the admin toolbar automatically loads in https. This means that content I'm embedding from other sources must also be on https, or it does not load. Since BBNC has become so friendly to 3rd party code with the Unformatted Text part, I have come to rely on embedded content from other sources. Some of that content can only be served by http. That means that any user who is able to create pages on my site gets a crippled view of the site.


I would love to have the option to use http again for some pages that do not display sensitive content.
Tagged:

Comments

  • Hey Jamie,



    This setting still exists under Administration, Sites & settings. The difference is that we've grayed it out for clients who are hosted with us. This is based off of internal and external feedback we've gotten.



    If you have a specific need to change this setting please create a case with us to review it.



    Thanks!


    Karen
  • I agree with Jaime. We rely on unformatted text and image parts for a lot of our pages and it looks weird for a user always logged in to not see anything at all. Most of our users just stay logged in all the time.
  • Hey Everyone,



    We did some digging on this, and now have a more universal answer, so I wanted to post it here.



    The option to allow users to turn off HTTPS for admin pages came up in our recent PCI compliance audit. This is the reason the option was grayed out for hosted clients. Because of this, it is not something we can turn back on.



    If you have a reason that you need the setting to be changed, please create a support case and we'll be happy to look for workarounds with you.



    Thanks!


    Karen
  • Karen - to clarify is the PCI issue the ability for us to change to http ourselves as hosted clients, or changing to http from https at all, regardless of whether BB does it or we do it?



    In our implementation we are in the early stages of deployment and are not going to be implementing t ability to account signup for several months. We have another system for e-commerce that already uses accounts, so we don't want to confuse people by forcing them to have two different accounts. As a result, most of our content can be http for now.
  • Hello Peter,



    Admin pages must be HTTPS if you are hosted by us. The setting still exists in NetCommunity, but it is grayed out of sites that are hosted by Blackbaud.



    Admin pages means if the blue bar is across the top.



    This does not effect the donors or other visitors to your site since they can't get into the admin part of NetCommunity.



    Thanks!


    Karen
  • I'm not sure if this helps in anyway, but our forms are secure through a https environment and we ran into this same issue when attempting to link through our AWS S3 bucket. Our team was able to track down a functional method of handling assets that are being linked through a non-secure environment. This method is called "Protocol Relative Path" and you can read up on the process here: http://www.paulirish.com/2010/the-pro...



    Hope this helps?

Categories