The http_only fix from 11 months ago is tagged as being in the 2.1.9 gem, but the fix isn't in the gem.
Installed the gem with bundler from the rails2 branch and it brought in the fix.
+1, this seems to still be an issue. As above, fixed with:
gem 'authlogic', :git => 'git://github.com/binarylogic/authlogic.git', :branch => 'rails2'
This could still be relevant for people running Rails 2.
👍 Even though this is for Rails 2, can the latest version of this branch be published for people with existing Rails 2 projects?
I have no gem publishing access (and I haven't been helping with authlogic much).
@tiegz What do you think?
Bump to 2.1.10 to release a fixed gem.
Hey all, I yanked the 2.1.9 gem from rubygems, but apparently you can't repush a version number. I just bumped the version in rails2 (which had new stuff anyways) and published the 2.1.10 gem.
Thanks @tiegz! I appreciate you following up on this issue.