mardi 25 juillet 2017

Consistent user authorization across url with/without www

I need to clarify a fundamental concept (beginner here).

In a Django web app I'm practicing on, I notice that if one logs in via going to example.com, they remain logged out on www.example.com (and can then go on to create a clone account).

1) Why does this happen?

2) What's the standard practice to iron out this issue? I.e., give one consistent experience across www and no-www.

In case the answer is as basic as just a redirection, I could use some pointers and an illustrative example there too - I'm using nginx reverse proxy with gunicorn.




Aucun commentaire:

Enregistrer un commentaire