Users being logged out more often after migration to HTTPS

Viewed 163

I upgraded a website (venuefinder.com) to responsive design a few weeks ago and at the same time, redirected any HTTP traffic to HTTPS. Since then, some users (and the site owner) claim they are unexpectedly logged out of the site even though they have the "remember me" checkbox checked.

What might be causing this? From what I can tell the cookie set is permanent, there is no code which calls FormsAuthentication.SignOut() except for the log out button or if the user is deleted from the database.

Google Analytics confirms the login page is being hit far more often than it was before the code change:

Could this be related to the HTTP > HTTPS migration?

Login page, page views: enter image description here

Google Analytics confirms the login page is being hit far more often than it was before the code change:

I don't even know where to begin to debug this.

I have set a machine key in web.config in case it was something to do with the cookie becoming invalid but it hasn't helped.

0 Answers
Related