Thanks, ye I did htaccess it cause I cant get the folder outside of the webroot.
When going to the ssl link, is there a way to send a hash and have the session in the db? maybe this can only work once to prevent fixation?
I wonder how others do this...
Lex