Doesn't that mean that you post the credit card data through an unencrypted connection, and then redirect them to an encrypted one?
Instead, send them to the SSL version of the page one step before-hand, when you're going to generate that form, and pass the session ID in the query string for that step.
In reply to Re: Apache::Session::File and mod_rewrite
by simonm
in thread Apache::Session::File and mod_rewrite
by geektron
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |