Index: openacs-4/packages/acs-core-docs/www/security-notes.html =================================================================== RCS file: /usr/local/cvsroot/openacs-4/packages/acs-core-docs/www/security-notes.html,v diff -u -r1.51.2.3 -r1.51.2.4 --- openacs-4/packages/acs-core-docs/www/security-notes.html 27 Jun 2019 18:22:22 -0000 1.51.2.3 +++ openacs-4/packages/acs-core-docs/www/security-notes.html 3 Sep 2021 09:15:28 -0000 1.51.2.4 @@ -9,7 +9,7 @@

HTTPS and the sessions system

If a user switches to HTTPS after logging into the system via HTTP, the user -must obtain a secure token. To insure security, the only way to +must obtain a secure token. To ensure security, the only way to obtain a secure token in the security system is to authenticate yourself via password over an HTTPS connection. Thus, users may need to log on again to a system when switching from HTTP to HTTPS. Note that logging on to a system