call jquery through https in backend

Found a bug? Tell us!!
bernd_d
Regular
Posts: 466
Joined: Thu Jun 03, 2010 9:28 am
Contact:

call jquery through https in backend

Post by bernd_d » Thu Jul 25, 2013 8:35 am

I don't know where i could find/fix it, but within backend jquery from google is loading with http:

Code: Select all

<script src="http://ajax.googleapis.com/ajax/libs/jquery/1/jquery.min.js" type="text/javascript"></script>
Could we/you change this to https? yellowled already did it within 2k11 for webfonts too.

User avatar
Timbalu
Regular
Posts: 4598
Joined: Sun May 02, 2004 3:04 pm

Re: call jquery through https in backend

Post by Timbalu » Thu Jul 25, 2013 9:06 am

Serendipity core does not bundle jquery via google, AFAIK!! Only locally!
https://github.com/s9y/Serendipity/comm ... /jquery.js

So why should we need to do this via https?

And even if, web fonts and js libraries are no secure data (in my eyes), why should any want to tunnel this through https, loosing performances?
Regards,
Ian

Serendipity Styx Edition and additional_plugins @ https://ophian.github.io/ @ https://github.com/ophian

User avatar
garvinhicking
Core Developer
Posts: 30020
Joined: Tue Sep 16, 2003 9:45 pm
Location: Cologne, Germany
Contact:

Re: call jquery through https in backend

Post by garvinhicking » Thu Jul 25, 2013 9:35 am

Hi!

This could come from an event plugin... but which one :)

Regards,
Garvin
# Garvin Hicking (s9y Developer)
# Did I help you? Consider making me happy: http://wishes.garv.in/
# or use my PayPal account "paypal {at} supergarv (dot) de"
# My "other" hobby: http://flickr.garv.in/

User avatar
garvinhicking
Core Developer
Posts: 30020
Joined: Tue Sep 16, 2003 9:45 pm
Location: Cologne, Germany
Contact:

Re: call jquery through https in backend

Post by garvinhicking » Thu Jul 25, 2013 9:39 am

Hi!

Ah, found them. Bayes, template_editor and the jquery plugin itself. Changed them all to https.

Regards,
Garvin
# Garvin Hicking (s9y Developer)
# Did I help you? Consider making me happy: http://wishes.garv.in/
# or use my PayPal account "paypal {at} supergarv (dot) de"
# My "other" hobby: http://flickr.garv.in/

User avatar
Timbalu
Regular
Posts: 4598
Joined: Sun May 02, 2004 3:04 pm

Re: call jquery through https in backend

Post by Timbalu » Thu Jul 25, 2013 9:44 am

Even if I still remain to my question, the 2.0 solution using "//" only is better! :)
Regards,
Ian

Serendipity Styx Edition and additional_plugins @ https://ophian.github.io/ @ https://github.com/ophian

bernd_d
Regular
Posts: 466
Joined: Thu Jun 03, 2010 9:28 am
Contact:

Re: call jquery through https in backend

Post by bernd_d » Thu Jul 25, 2013 9:48 am

garvinhicking wrote:Ah, found them. Bayes, template_editor and the jquery plugin itself. Changed them all to https.
I found the same one, but you have been faster than me ;)

User avatar
garvinhicking
Core Developer
Posts: 30020
Joined: Tue Sep 16, 2003 9:45 pm
Location: Cologne, Germany
Contact:

Re: call jquery through https in backend

Post by garvinhicking » Thu Jul 25, 2013 10:14 am

Hm, true. Forgot about that again, this "//" is something new for me. Go ahead if you'd like to change this ;)

Regards,
Garvin
# Garvin Hicking (s9y Developer)
# Did I help you? Consider making me happy: http://wishes.garv.in/
# or use my PayPal account "paypal {at} supergarv (dot) de"
# My "other" hobby: http://flickr.garv.in/

User avatar
yellowled
Regular
Posts: 7036
Joined: Fri Jan 13, 2006 12:46 pm
Location: Eutin, Germany
Contact:

Re: call jquery through https in backend

Post by yellowled » Thu Jul 25, 2013 11:16 am

garvinhicking wrote:Forgot about that again, this "//" is something new for me.
It is BTW the way Google recommends to reference assets hosted on their CDN, see https://developers.google.com/speed/lib ... #Libraries

YL
amazon Wishlist - Serendipity-Podcast (German only, sorry)

User avatar
yellowled
Regular
Posts: 7036
Joined: Fri Jan 13, 2006 12:46 pm
Location: Eutin, Germany
Contact:

Re: call jquery through https in backend

Post by yellowled » Thu Jul 25, 2013 11:33 am

garvinhicking wrote:Go ahead if you'd like to change this ;)
✔ Done

YL
amazon Wishlist - Serendipity-Podcast (German only, sorry)

bernd_d
Regular
Posts: 466
Joined: Thu Jun 03, 2010 9:28 am
Contact:

Re: call jquery through https in backend

Post by bernd_d » Thu Jul 25, 2013 11:43 am

Thank you :)

User avatar
Timbalu
Regular
Posts: 4598
Joined: Sun May 02, 2004 3:04 pm

Re: call jquery through https in backend

Post by Timbalu » Thu Jul 25, 2013 12:08 pm

Agreed!

Anyway, but what about my question? I still do not really see the benefit of changing to http(s)ecure.
Http and https are equal in trace routing, as long all traceservers also support https, the only difference is that a man-in-the-middle can't read my data as plaintext, which IMO isn't really a matter with (font/js)-CDN-libraries...

A YUI-Dev says this: http://wonko.com/post/javascript-ssl-cdn
Regards,
Ian

Serendipity Styx Edition and additional_plugins @ https://ophian.github.io/ @ https://github.com/ophian

User avatar
onli
Regular
Posts: 2231
Joined: Tue Sep 09, 2008 10:04 pm
Contact:

Re: call jquery through https in backend

Post by onli » Thu Jul 25, 2013 12:12 pm

The browser shows a warning if you include stuff via http on a https-site, and normally refuses to load the unsafe content.

User avatar
Timbalu
Regular
Posts: 4598
Joined: Sun May 02, 2004 3:04 pm

Re: call jquery through https in backend

Post by Timbalu » Thu Jul 25, 2013 12:29 pm

But the issue on changing this from http to https was not an error, I presume.
So, is that an answer to my originating question? Google serves both.

I know riding this (dead) horse is like playing in the sand, but secured traces mean more costs, more power, and less nature environment at least ... ;-) (*)

(*) and make the work more hard for our friends in overseas...!
Regards,
Ian

Serendipity Styx Edition and additional_plugins @ https://ophian.github.io/ @ https://github.com/ophian

User avatar
onli
Regular
Posts: 2231
Joined: Tue Sep 09, 2008 10:04 pm
Contact:

Re: call jquery through https in backend

Post by onli » Thu Jul 25, 2013 12:43 pm

Ian, that is one of the situatuions where I don't know if you understand what I sayed and the issue at all or if I'm missing the point ;)

The site YL linked would include jQuery in this way:

Code: Select all

<script src="//ajax.googleapis.com/ajax/libs/jquery/1.10.2/jquery.min.js"></script>
While I know that this didn't work a few browser-versions ago when I tried to use that, that switches between https and http depending on the protocol used on the parent site. It is just no option to include stuff via http on a https-site as long as the browser throws a warning when doing that.

The alternative is not to use http regardless but to host the stuff locally, which we do (from 1.7 on? at least in 2.0).

User avatar
Timbalu
Regular
Posts: 4598
Joined: Sun May 02, 2004 3:04 pm

Re: call jquery through https in backend

Post by Timbalu » Thu Jul 25, 2013 12:55 pm

Well, if you leave me the choice, I'd say definitely the last!
Please read that thread again to see my means.
Regards,
Ian

Serendipity Styx Edition and additional_plugins @ https://ophian.github.io/ @ https://github.com/ophian

Post Reply