Issue #4445 closed

OpenID, http vs. https distinction? (BB-5094)

Lammert Hilarides
created an issue

I mostly authenticate via OpenID, and today I noticed that when using the URL https://openid.example.com instead of my usual http://openid.example.com that BitBucket offered to sign me up for a new account. Shouldn't both URL's be considered the same user, and therefore both be automatically associated to one account? Right now I can have two accounts on BitBucket linked to the same OpenID account (one with http and the other with https).

Comments (1)

