ipfs/ipfs-companion

Disabling on specific host should reload page from HTTPS

Open

#864 geöffnet am 9. Apr. 2020

Auf GitHub ansehen
 (0 Kommentare) (0 Reaktionen) (0 zugewiesene Personen)JavaScript (364 Forks)batch import
P2effort/hoursexp/beginnergood first issuehelp wantedkind/bugstatus/readytopic/security

Repository-Metriken

Stars
 (1.992 Stars)
PR-Merge-Metriken
 (Durchschn. Merge 53T 3h) (1 gemergte PR in 30 T)

Beschreibung

Filling from mobile so we don't forget. Good first issue if someone wants to fix this via a PR before I get to it next week.

Right now, when IPFS integrations are disabled via a toggle, extension assumes http://.

Most servers redirect http://https://, or have HSTS set up, but Companion should default to https://, because if someone did not set up redirect to a secure context, there is a risk of the same website being loaded from http.

Easy fix is to use https:// in the line below:

https://github.com/ipfs-shipyard/ipfs-companion/blob/06227a244d357e2969b52f01dda8ee13df286446/add-on/src/popup/browser-action/store.js#L196

Contributor Guide