The Needs Review Queue Bot β tested this issue. It either no longer applies to Drupal core, or fails the Drupal core commit checks. Therefore, this issue status is now "Needs work".
Apart from a re-roll or rebase, this issue may need more work to address feedback in the issue or MR comments. To progress an issue, incorporate this feedback as part of the process of updating the issue. This helps other contributors to know what is outstanding.
Consult the Drupal Contributor Guide β to find step-by-step guides for working with issues.
- Status changed to Postponed: needs info
almost 2 years ago 4:21am 13 February 2023 - π¦πΊAustralia acbramley
3 years without much activity tells me this isn't a major. There's also quite a few headers in play now that will break things if stripped (e.g embedded content via media library)
I'm inclined to mark this as won't fix but would like to see what others think.
- π¬π§United Kingdom longwave UK
I am inclined to agree, given that most reports of this were back in 2016, and it seems to affect HTTP only. This only affects authenticated users and most sites should be on HTTPS especially where authenticated users are involved, so this is perhaps still technically an issue, but only in a configuration that is not really recommended. Let's leave this open for a few more months and then close if there are no further reports.
- Status changed to Closed: outdated
about 1 year ago 9:13am 7 November 2023 - π³πΏNew Zealand quietone
Based on the comments in #50 and #51 I am closing this issue as outdated. If this is incorrect reopen the issue, by setting the status to 'Active', and add a comment explaining what still needs to be done.
Thanks!