(RESOLVED) Will it ever be implemented? HTTPS

(RESOLVED) Will it ever be implemented? HTTPS

Author
Discussion

Unexpected Item In Bagging Area

7,030 posts

190 months

Sunday 8th January 2017
quotequote all

Tonsko

6,299 posts

216 months

Sunday 8th January 2017
quotequote all
Yes, the latter. Been around for a while i think, not a a fan of the format.

George111

6,930 posts

252 months

Sunday 8th January 2017
quotequote all
Unexpected Item In Bagging Area said:
Ah, not seen that before. Thanks biggrin

PoleDriver

28,647 posts

195 months

Sunday 8th January 2017
quotequote all
Started, coded and run by PetrolTed, who has a bit of history of this kind of thing! winkwhistle

CoolHands

18,689 posts

196 months

Sunday 8th January 2017
quotequote all
do you have to be registered to see the forum? Cos I can't see one.

thebraketester

14,247 posts

139 months

Sunday 8th January 2017
quotequote all
Just to bring this thread to a close.

OP. The answer is, NO.

•**TOPIC CLOSED**•

All that jazz

7,632 posts

147 months

Monday 9th January 2017
quotequote all
CoolHands said:
do you have to be registered to see the forum? Cos I can't see one.
Yes it's one of those stty arrangements where you have to be logged in to view anything. I just don't even bother with such sites.

DS197

Original Poster:

992 posts

107 months

Monday 9th January 2017
quotequote all
thebraketester said:
Just to bring this thread to a close.

OP. The answer is, NO.

•**TOPIC CLOSED**•
Thank you my good sir, although I did not see any reason for why you must shout no.

All that jazz said:
Yes it's one of those stty arrangements where you have to be logged in to view anything. I just don't even bother with such sites.
Agreed!

All that jazz

7,632 posts

147 months

Tuesday 10th January 2017
quotequote all
shout

Where are the PH Staff? Could it be that they are deliberately avoiding this thread? I note that they are active in other feedback threads.

Where are thou, Racing Pete, Ollie M, PH Dom, Jack Mansfield et al, to assure us that https will be implemented by the end of this month as promised?

randlemarcus

13,528 posts

232 months

Tuesday 10th January 2017
quotequote all
While they are copying and pasting the code, could they look at a couple of other bits in the logon page as well? biggrin

Google Chrome said:
Refused to load the script 'data:application/javascript;base64,dmFyIHV0YWc9e2xpbms6ZnVuY3Rpb24oKXt9fQ==' because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-inline' http://static.pistonheads.comhttp://tags.tiqcdn.com/utag/haymarket/pistonheads-...http://ad.crwdcntrl.nethttp://widgets.getsitecontrol.comhttp://gscst-84a.kxcdn.com 'unsafe-eval' http://www.google-analytics.com/https://www.google-analytics.com/ ".

head.js:1 Synchronous XMLHttpRequest on the main thread is deprecated because of its detrimental effects to the end user's experience. For more help, check https://xhr.spec.whatwg.org/.
send @ head.js:1
login:1 Refused to load the script 'data:application/javascript;base64,dmFyIHV0YWc9e2xpbms6ZnVuY3Rpb24oKXt9fQ==' because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-inline' http://static.pistonheads.comhttp://tags.tiqcdn.com/utag/haymarket/pistonheads-...http://ad.crwdcntrl.nethttp://widgets.getsitecontrol.comhttp://gscst-84a.kxcdn.com 'unsafe-eval' http://www.google-analytics.com/https://www.google-analytics.com/ ".

login:1 Refused to load the image 'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAACklEQVR4nGMAAQAABQABDQottAAAAABJRU5ErkJggg==' because it violates the following Content Security Policy directive: "img-src *".

feef

5,206 posts

184 months

dmsims

6,539 posts

268 months

Friday 13th January 2017
quotequote all
anonymous said:
[redacted]
Really why on earth would you put FQDN's in ?

<link rel="stylesheet" type="text/css" href="http://static.pistonheads.com/3354/Assets/bundles/uhcss.css" />

<link rel="stylesheet" href="http://static.pistonheads.com/3354/Assets/bundles/idserverstyles.css" />

<!--[if IE 8]><link href='http://static.pistonheads.com/3354/Assets/css/ie8.css' rel='stylesheet' type='text/css' media='all' /><![endif]-->



<script type="text/javascript" src="http://static.pistonheads.com/3354/Assets/bundles/head.js"></script>
<script type="text/javascript" src="http://static.pistonheads.com/3354/Assets/bundles/idserverscripts.js"></script>

<script type="text/javascript" src="//tags.tiqcdn.com/utag/haymarket/pistonheads-sso/prod/utag.sync.js"></script>
<script src="http://static.pistonheads.com/3354/Assets/bundles/uhscripts.js" type="text/javascript"></script>

GreigM

6,728 posts

250 months

Friday 13th January 2017
quotequote all
dmsims said:
Really why on earth would you put FQDN's in ?
You mean as opposed to relative URLs? I presume it is because www.pistonheads.com is not the same server as static.pistonheads.com, so can't be resolved locally.

I don't really see the problem with that however (apart from the fact that static.pistonheads.com isn't https either).

feef

5,206 posts

184 months

Friday 13th January 2017
quotequote all
dmsims said:
anonymous said:
[redacted]
Really why on earth would you put FQDN's in ?

<link rel="stylesheet" type="text/css" href="http://static.pistonheads.com/3354/Assets/bundles/uhcss.css" />

<link rel="stylesheet" href="http://static.pistonheads.com/3354/Assets/bundles/idserverstyles.css" />

<!--[if IE 8]><link href='http://static.pistonheads.com/3354/Assets/css/ie8.css' rel='stylesheet' type='text/css' media='all' /><![endif]-->



<script type="text/javascript" src="http://static.pistonheads.com/3354/Assets/bundles/head.js"></script>
<script type="text/javascript" src="http://static.pistonheads.com/3354/Assets/bundles/idserverscripts.js"></script>

<script type="text/javascript" src="//tags.tiqcdn.com/utag/haymarket/pistonheads-sso/prod/utag.sync.js"></script>
<script src="http://static.pistonheads.com/3354/Assets/bundles/uhscripts.js" type="text/javascript"></script>
What's to say the code isn't being generated dynamically?

768

13,706 posts

97 months

Friday 13th January 2017
quotequote all
Does that make a difference?

Tankrizzo

7,278 posts

194 months

Friday 13th January 2017
quotequote all
feef said:
What's to say the code isn't being generated dynamically?
Given what we know about the failings of the current site, and it's written in Classic, I'd find that highly unlikely.

dmsims

6,539 posts

268 months

Friday 13th January 2017
quotequote all
feef said:
dmsims said:
anonymous said:
[redacted]
Really why on earth would you put FQDN's in ?

<link rel="stylesheet" type="text/css" href="http://static.pistonheads.com/3354/Assets/bundles/uhcss.css" />

<link rel="stylesheet" href="http://static.pistonheads.com/3354/Assets/bundles/idserverstyles.css" />

<!--[if IE 8]><link href='http://static.pistonheads.com/3354/Assets/css/ie8.css' rel='stylesheet' type='text/css' media='all' /><![endif]-->



<script type="text/javascript" src="http://static.pistonheads.com/3354/Assets/bundles/head.js"></script>
<script type="text/javascript" src="http://static.pistonheads.com/3354/Assets/bundles/idserverscripts.js"></script>

<script type="text/javascript" src="//tags.tiqcdn.com/utag/haymarket/pistonheads-sso/prod/utag.sync.js"></script>
<script src="http://static.pistonheads.com/3354/Assets/bundles/uhscripts.js" type="text/javascript"></script>
What's to say the code isn't being generated dynamically?
Is that a serious question? rofl

Tankrizzo

7,278 posts

194 months

Friday 13th January 2017
quotequote all
anonymous said:
[redacted]
Nothing, especially if you're using it as a CDN which it looks like they are.

dmsims

6,539 posts

268 months

Friday 13th January 2017
quotequote all
I should have been more specific

IF

src=//


had been used switching to https would have been an (even more) trivial task



768

13,706 posts

97 months

Friday 13th January 2017
quotequote all
That's just a 2 second sed replacement.

Mind you, I can't think of any one involved with this that should take much more time.