Join the Mozilla’s Test Days event from 9–15 Jan to test the new Firefox address bar on Firefox Beta 135 and get a chance to win Mozilla swag vouchers! 🎁

Ce site disposera de fonctionnalités limitées pendant que nous effectuons des opérations de maintenance en vue de vous proposer un meilleur service. Si un article ne règle pas votre problème et que vous souhaitez poser une question, notre communauté d’assistance est prête à vous répondre via @FirefoxSupport sur Twitter, et /r/firefox sur Reddit.

Rechercher dans l’assistance

Évitez les escroqueries à l’assistance. Nous ne vous demanderons jamais d’appeler ou d’envoyer un SMS à un numéro de téléphone ou de partager des informations personnelles. Veuillez signaler toute activité suspecte en utilisant l’option « Signaler un abus ».

En savoir plus

Firefox 96 mixed http/https content issues

more options

I manage a website that uses https for logging in or other sensitive data but uses http for non-sensitive data. Beginning with Firefox 96, users who login using https can navigate to any https page on the site using their logged in credentials, but do not have their login credentials when they navigate to http pages. It appears the cookies generated on https pages are not accessible from http pages using the latest version.

Is this a bug in Firefox 96 or a feature?

Bug or not, I understand the obvious advice would be to use https for the entire site. But our site uses a 3rd party app that does not work using https. The second obvious advice would be to get rid of or fix the app so we can use https for the entire site, which will have to happen at some point. But for the meantime, is there a setting in Firefox that will allow users to login to a mixed https/http site using Firefox 96 or are users going to have to use another browser?

I manage a website that uses https for logging in or other sensitive data but uses http for non-sensitive data. Beginning with Firefox 96, users who login using https can navigate to any https page on the site using their logged in credentials, but do not have their login credentials when they navigate to http pages. It appears the cookies generated on https pages are not accessible from http pages using the latest version. Is this a bug in Firefox 96 or a feature? Bug or not, I understand the obvious advice would be to use https for the entire site. But our site uses a 3rd party app that does not work using https. The second obvious advice would be to get rid of or fix the app so we can use https for the entire site, which will have to happen at some point. But for the meantime, is there a setting in Firefox that will allow users to login to a mixed https/http site using Firefox 96 or are users going to have to use another browser?

Solution choisie

Hi, there was an important change related to cookies and http/https in Firefox 96. See:

https://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Releases/96#http

How quickly can you transition to 100% HTTPS?

Lire cette réponse dans son contexte 👍 0

Toutes les réponses (2)

more options

Solution choisie

Hi, there was an important change related to cookies and http/https in Firefox 96. See:

https://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Releases/96#http

How quickly can you transition to 100% HTTPS?

more options

Thank you for your response! This definitely explains what we're experiencing.

Transitioning will be a project with the 3rd party app so it will take some time. But I'll read over the literature you provided and see what I can do to fix the cookie issue.

Thanks again!