Last modified: 2013-08-30 13:56:11 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T51698, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 49698 - When uploading from Flickr, unencrypted XHRs are sent from client to Flickr despite being on https://
When uploading from Flickr, unencrypted XHRs are sent from client to Flickr d...
Status: RESOLVED FIXED
Product: MediaWiki extensions
Classification: Unclassified
UploadWizard (Other open bugs)
unspecified
All All
: Normal normal with 1 vote (vote)
: ---
Assigned To: Nobody - You can work on this!
https://upload.wikimedia.org/wikipedi...
:
Depends on:
Blocks: ssl 43450
  Show dependency treegraph
 
Reported: 2013-06-17 15:43 UTC by Rainer Rillke @commons.wikimedia
Modified: 2013-08-30 13:56 UTC (History)
4 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Rainer Rillke @commons.wikimedia 2013-06-17 15:43:07 UTC
Original bug title:
When uploading from Flickr, unencrypted XHRs are sent from client to Flickr despite being on https://

(specifically to http://api.flickr.com/services/rest/?)

I think this will be a real issue after Firefox prompts by default when attempt to connect to http while being on https.

I read about the issues with the proxy which can't fetch the images from HTTPS (Bug 42468). If required, you'll have to set up just another proxy forwarding the API requests from the client to flickr's http API:
client <<-- encrypted traffic -->> proxy <<-- unencrypted traffic -->> flickr API

The proposed procedure would also enable you to hide the API - key.
Comment 1 Steinsplitter 2013-08-29 08:17:38 UTC
*** Bug 53522 has been marked as a duplicate of this bug. ***
Comment 2 Rainer Rillke @commons.wikimedia 2013-08-30 05:41:51 UTC
https://gerrit.wikimedia.org/r/81890/
Comment 3 Alex Monk 2013-08-30 13:56:11 UTC
https://gerrit.wikimedia.org/r/81891/ fixed this

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links