I’m playing with 2.2 and right away something changed and it appears we’ll actually have to address this.
<form method="post" action="http://example.com/" >Needs to be over https. How?
What I’ve done since was not fill out the “URL to the root directory of your site” option and forced https through htaccess. Yes, that broke logout redirects, but small price for security compliance. Now that field is required.
One other real quick test, can you verify {redirect} is working on 2.2?