Protocol-Relative Paths No Longer Recommended

Created on 28 June 2022, over 2 years ago
Updated 4 May 2023, over 1 year ago

Problem/Motivation

Protocol-relative resource links expose websites to man in the middle attacks and are considered an anti-pattern now that the web is moving toward https everywhere.

Steps to reproduce

Load a page where the insight JS is being added. The src for the script tag has a protocol-relative URL.

Proposed resolution

Change to https in the libraries yaml file.

πŸ› Bug report
Status

Needs review

Version

1.0

Component

Code

Created by

πŸ‡ΊπŸ‡ΈUnited States emclaughlin

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.71.5 2024