Page MenuHomePhabricator

When uploading from Flickr, unencrypted XHRs are sent from client to Flickr despite being on https://
Closed, ResolvedPublic

Description

Original bug title:
When uploading from Flickr, unencrypted XHRs are sent from client to Flickr despite being on https://

(specifically to http://api.flickr.com/services/rest/?)

I think this will be a real issue after Firefox prompts by default when attempt to connect to http while being on https.

I read about the issues with the proxy which can't fetch the images from HTTPS (Bug 42468). If required, you'll have to set up just another proxy forwarding the API requests from the client to flickr's http API:
client <<-- encrypted traffic -->> proxy <<-- unencrypted traffic -->> flickr API

The proposed procedure would also enable you to hide the API - key.


Version: unspecified
Severity: normal
URL: https://upload.wikimedia.org/wikipedia/commons/2/27/Bypass_https_security_warning_Firefox_23.png

Details

Reference
bz49698

Event Timeline

bzimport raised the priority of this task from to Medium.Nov 22 2014, 1:58 AM
bzimport added a project: UploadWizard.
bzimport set Reference to bz49698.
bzimport added a subscriber: Unknown Object (MLST).
  • Bug 53522 has been marked as a duplicate of this bug. ***
Gilles raised the priority of this task from Medium to Unbreak Now!.Dec 4 2014, 10:23 AM
Gilles added a project: Multimedia.
Gilles moved this task from Untriaged to Done on the Multimedia board.
Gilles lowered the priority of this task from Unbreak Now! to Medium.Dec 4 2014, 11:21 AM
Restricted Application added a subscriber: Matanya. · View Herald Transcript