SSO should be more secure
The SSO mechanism works great -- but it's horribly insecure if the user is on a public WiFi. It looks like I can set it to HTTPS but the user has to ignore the SSL cert error.
I also think the token should only work once. Or at least that could be an option. I guess I could accomplish this with a very short expiration date but expiring after user would provide a little more security.
We add HTTPS support
Some examples:
For link to your forum:
http://fynydd.userecho.com/forum/4894-general/
You must provide following link:
https://userecho.com/forum/4894-general/?sso_token=your_token
Try and don't hesitate to contact us
PS: Our widget also support SSO + HTTPS now