Last modified: 2014-07-23 03:34:02 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T69303, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 67303 - Enable HSTS (HTTP Strict Transport Security) on Wikitech
Enable HSTS (HTTP Strict Transport Security) on Wikitech
Status: RESOLVED FIXED
Product: Wikimedia Labs
Classification: Unclassified
wikitech-interface (Other open bugs)
unspecified
All All
: Unprioritized normal
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-06-30 14:18 UTC by fn84b
Modified: 2014-07-23 03:34 UTC (History)
6 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description fn84b 2014-06-30 14:18:55 UTC
Wikitech requires HTTPS connections (http://wikitech.wikimedia.org redirects to https://wikitech.wikimedia.org), so could we send a Strict-Transport-Security header, so that browsers will automatically use HTTPS even if a link points to HTTP?
Comment 1 Andre Klapper 2014-06-30 18:10:27 UTC
Hi fn84b. Thanks for taking the time to report this!
This particular problem has already been reported into our bug tracking system, but please feel free to report any further issues you find.

*** This bug has been marked as a duplicate of bug 38516 ***
Comment 2 Jan Zerebecki 2014-07-01 08:54:50 UTC
Wikitech can use a different, easier implementation compared to bug 38516 (wikipedia, etc.). As HTTPS can not be disabled in the preferences and as there is no geoip based blacklist for avoiding HTTPS, HSTS can be enabled by always sending the header like the reporter suggested, e.g. via the webserver configuration. (Although we might be able to use the same implementation it still needs to be enabled as wikitech is completely separated.)

The apache configuration for wikitech is at: operations/puppet.git/templates/apache/sites/wikitech.wikimedia.org.erb
Comment 3 fn84b 2014-07-23 03:34:02 UTC
https://gerrit.wikimedia.org/r/148290 fixed this issue.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links