Broken (Invalidated) HTTPS on the main web-site

Discussion about forum rules, new moderators, website content, website layout, VideoLAN artwork etc..
Forum rules
Please read the forum's rules carefully before posting. This forum should not be used to post VLC usage related questions.
AntonB
New Cone
New Cone
Posts: 9
Joined: 27 May 2017 20:36

Broken (Invalidated) HTTPS on the main web-site

Postby AntonB » 27 May 2017 20:53

I could not find the relevant mailing list, therefore I post this here. If you know how to, please relate this to the relevant people.

Few pages on the main web-site http://www.videolan.org has a few pages with HTTP links, although those pages and resources are available over HTTPS. This creates a potential problem (user leaving secure HTTPS) and breaks Chrome's security validation (no green padlock next on the left of the address bar).

This issue is misleading people, like in https://forum.videolan.org/viewtopic.php?f=10&t=134384.

Here the pages without a padlock: List of pages relying on or linking to HTTP resources, yet passing green padlock check:
List is in the comments because of limit of 5 URLs per post.

Issue and Fix:
The source and page links have "http://" hardwritten in, instead of "//".
Please note that HTTPS Everywhere from Electronic Frontier Foundation automatically rewrites the links to HTTPS (and everything works properly), so fix is as simple as replacing "http://" with "//".

AntonB
New Cone
New Cone
Posts: 9
Joined: 27 May 2017 20:36

Re: Broken (Invalidated) HTTPS on the main web-site

Postby AntonB » 27 May 2017 22:15

If VideoLAN website is hosted somewhere on a public repo supporting pull requests, please let me know: I'll propose the changes directly there (to save both your and my time).

List of pages relying on or linking to HTTP resources, yet passing green padlock check (shortened):
  • In the <header> the link to RSS feed uses HTTP, supports HTTPS
  • The Thank You page http://www.videolan.org/thank_you.html uses HTTP, supports HTTPS:
  • Facebook and Twitter are linked to with HTTP (but, of course, will upgrade to HTTPS)

    I realized that there are simply too many resources to list here (that would be spamming), so I'll stop here.

    P.S.: Is anyone reading this?

AntonB
New Cone
New Cone
Posts: 9
Joined: 27 May 2017 20:36

Re: Broken (Invalidated) HTTPS on the main web-site

Postby AntonB » 28 May 2017 07:33

I think I have found the correct place for these edits on the VideoLAN GitLab pages: https://code.videolan.org/VideoLAN.org/websites.
I will try to implement these changes and get them approved. Unfortunately, I do not think I can delete the original post (except for "reporting" it), so I'll just leave it here. Sorry :(.

Jean-Baptiste Kempf
Site Administrator
Site Administrator
Posts: 37523
Joined: 22 Jul 2005 15:29
VLC version: 4.0.0-git
Operating System: Linux, Windows, Mac
Location: Cone, France
Contact:

Re: Broken (Invalidated) HTTPS on the main web-site

Postby Jean-Baptiste Kempf » 28 May 2017 10:45

Some of the issues reported are now fixed.
Jean-Baptiste Kempf
http://www.jbkempf.com/ - http://www.jbkempf.com/blog/category/Videolan
VLC media player developer, VideoLAN President and Sites administrator
If you want an answer to your question, just be specific and precise. Don't use Private Messages.

AntonB
New Cone
New Cone
Posts: 9
Joined: 27 May 2017 20:36

Re: Broken (Invalidated) HTTPS on the main web-site

Postby AntonB » 28 May 2017 20:38

Thank you very much!

Unfortunately, there are more issues. I would like to help and I believe the most efficient way is for me to propose the changes in the code and submit them for review (instead of listing them here and then checking that they were fixed). Is that possible? Also, I recently sent an email to <www-doc[AT]videolan.org>, I believe you are on it.

Jean-Baptiste Kempf
Site Administrator
Site Administrator
Posts: 37523
Joined: 22 Jul 2005 15:29
VLC version: 4.0.0-git
Operating System: Linux, Windows, Mac
Location: Cone, France
Contact:

Re: Broken (Invalidated) HTTPS on the main web-site

Postby Jean-Baptiste Kempf » 29 May 2017 16:54

Sure.
Jean-Baptiste Kempf
http://www.jbkempf.com/ - http://www.jbkempf.com/blog/category/Videolan
VLC media player developer, VideoLAN President and Sites administrator
If you want an answer to your question, just be specific and precise. Don't use Private Messages.


Return to “Forum, Website and Artwork discussion”

Who is online

Users browsing this forum: No registered users and 5 guests