I am using Revo 2.2.0 with RevoSSL 1.0.3 to manage swapping between http and https pages on a website (https pages are quote forms which include personal information). All is working as expected for a period of time (maybe 24 hours) and then the website stops swapping correctly and results in the quote pages being displayed as 'http' as opposed to 'https' - if you then move focus back to a normal web page (http) the CSS formatting is all lost and the page is displayed as text....Disaster!
Clearing the cache solves the issue, but i can't log-on on the website every day/couple of hours, to clear the cache and solve this issue. Does anyone have any ideas on what could be the problem, or has anyone ever had this issue before. I recently upgraded to RevoSSL 1.0.3 which solved the issue for a short period of time
help please!
-
☆ A M B ☆
- 3,141 Posts
I have no idea about what RevoSSL does, but it would be great to find out why the CSS is lost. Next time it happens, open the browsers' developers tools and check the Console tab for any errors, as well as the Network tab to see what is happening with your CSS files. I suspect it may be that you did not call the <base> tag uncached or other rewrites are not handled properly, but knowing what goes wrong exactly would help debugging..
-
☆ A M B ☆
- 24,524 Posts
The problem is that it's loading a page requested with SSL, but the .css files are trying to load without it. Your browsers won't let the non-SSL items (the .css files) through. You need to have your base tag's system setting be uncached so that it will use the http or https that the page request used:
<base href="[[!++base_url]]">
-
☆ A M B ☆
- 24,524 Posts
Actually it's usually site_url which will prepend the whole
http://domain.com/ part. Using base_url will most likely just prepend a / (being the base of the web root). The main point is to be sure that it's uncached - has the ! in the tag.
Hi Susan, yes it definitely has the ! in the tag and is uncached. Any other ideas?
I have xFPC installed, could this be the problem?
Should i uncheck the 'cachable' checkbox on all pages?
Many thanks for your help.
-
☆ A M B ☆
- 3,141 Posts
When serving the site over HTTPS, all the CSS files also need to be served over HTTPS - if they are not, they will be blocked by the browser as insecure content. So make sure that your CSS files are served over HTTPS too.
The uncached base tag (site_url) should help with that, however you may have full links to the CSS causing it to load over HTTP instead of HTTPS.
-
☆ A M B ☆
- 33 Posts
I came up with a way to serve up HTTP and HTTPS pages on one of my sites, that works with my multiple contexts and with Wayfinder. It might be helpful to what you're doing.
https://forums.modx.com/thread/90594/ssl---configuring-modx-for-http-and-https#dis-post-496684