Re: RFC: New AlwaysSecureGlob directive
Jon Jensen <[email protected]>
| Newsgroups | gmane.comp.web.interchange.users |
|---|---|
| Message-ID | <alpine.LFD.2.20.1703251928000.2392@cevzz> |
On Sun, 26 Mar 2017, Peter wrote: > On 26/03/17 13:38, Jon Jensen wrote: >> But for many legacy sites it's still going to be years before we can do >> that due to numerous dependencies on the plain HTTP URLs. > > This depends largely on sites dependence on hard-coded URLs. If sites > (even legacy ones) stick the use of the [area] tag and other mechanisms > that check VendURL then the transition is relatively easy. No, it's not because of that at all. There are no hardcoded URLs in the site this was developed for. It's needed because of 3rd-party external stuff (analytics, remarketing, etc.) that doesn't work with HTTPS yet, which requires parts of the site to stay plain HTTP. That which means [area] has to be able to generate both HTTP & HTTPS. Jon -- Jon Jensen End Point Corporation https://www.endpoint.com/