Project

General

Profile

Actions

Bug #35449

closed

https (SSL) for extension images

Added by Xaver Maierhofer over 12 years ago. Updated over 10 years ago.

Status:
Closed
Priority:
Could have
Assignee:
-
Category:
Extension Manager
Target version:
-
Start date:
2012-04-01
Due date:
% Done:

0%

Estimated time:
TYPO3 Version:
4.6
PHP Version:
5.3
Tags:
Complexity:
Is Regression:
No
Sprint Focus:

Description

First thx for ssl secure ter images.

Secure connection for extension-icons in em search.
Only problem is typo3.org is only hoster with a valid SSL certificate.
If backend is SSL with icons must load from typo3.org.

e.g. (i don't know the code ;) )
if(SSL){
$mirror['imageurl'] = "https://typo3.org/fileadmin/"
}

Actions #1

Updated by Georg Ringer over 12 years ago

  • Subject changed from https (SSL) for extansion images to https (SSL) for extension images
Actions #3

Updated by Xaver Maierhofer over 12 years ago

if i have random mirror, i get the image from http://tar.mittenwald or http://typo3.org/fileadmin and no https

Actions #4

Updated by Jigal van Hemert over 12 years ago

  • Status changed from New to Needs Feedback

What is the exact problem with the extension icons not being fetched through an SSL connection? It's from a different domain than your backend, so it would not use the same certificate anyway.

Actions #5

Updated by Xaver Maierhofer over 12 years ago

If i have a lot of personal informations in backend to handle and an SSL certificate.

I use this settings:
$TYPO3_CONF_VARS['BE']['lockSSL'] = '1';
$TYPO3_CONF_VARS['BE']['lockSSLPort'] = '443';

And if any source without a ssl certificate is loaded -> the addressbar will turn normal (white).
If you go back to list to handle personal informations the addressbar won't ensure everything is encrypted, because with frames the content (mainframe isn't reloaded).

Actions #6

Updated by Jigal van Hemert over 12 years ago

This requires a change in the mirror list file I'm afraid. There are installation which are limited in the external domains they have access to. In such cases there is a specific mirror selected.
Also, a mirror might have a different host and/or path for secure images (e.g. Twitter has http://a0.twitter.com/... for avatar images and https://si0.twitter.com/... for avatars over SSL). So, we need to add host_ssl and path_ssl to the mirror list.
If a random mirror is used the code should select one of the mirrors which has a secure host/path setting.

First it should be determined if the mirror file can be expanded.

Actions #7

Updated by Alexander Opitz about 11 years ago

  • Status changed from Needs Feedback to New
  • Is Regression set to No
Actions #8

Updated by Wouter Wolters over 10 years ago

  • Status changed from New to Closed

We do not show a mirror image anymore in the newest Extension Manager. This is obsolete now.

Actions

Also available in: Atom PDF