Do logged in users need to browse a site over https?
- by Luke
I've never thought it was necessary, but a client has requested that all webpages served to logged in users be delivered over HTTPS.
Aside from the implementation standpoint, which I don't think I'm going to pursue is there any real reason for this request ?
For clarity, the login / logout process, account settings, registration preferences and all user related scripts are served over https. but I can't see the point in my news articles, press releases, events etc... being served in this manner? Am I missing something ?