Needs work
Project:
Ubercart SSL
Version:
6.x-1.15
Component:
Code
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
12 May 2010 at 20:27 UTC
Updated:
7 Dec 2014 at 22:00 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #1
joelstein commentedHere's a patch.
Comment #2
crystaldawn commentedThats interesting. I dont show notice msgs on my servers at all so this isnt something I see a lot of. Actually my servers dont show error msgs let alone notices. Anyways, this seems like a reasonable fix and actually makes the if statements even more readable with the use of a descriptive function so I like it. I added it in although I've changed it around a bit as I dont like shorthand coding and I added a little more descriptive function name. I prefer much more readable versions of shorthand :)
I used this instead. I assume it will work just fine for you. I am not possitive that the word "on" is used on all servers either but I guess we'll soon see :) Thats the reason why I didnt check for a specific value in the first place. I wasnt sure if 'on' would be returned for all platforms or it's case.
UPDATE: After reading up on $_SERVER['HTTPS'], I was correct in the assumption that the word 'on' is not always returned. It can sometimes be 'ON', 'On', 'Yes', 'Ci' etc depending upon language, platform, customizations, etc. So I've changed it to reflect this. I also read that it will NEVER have the word 'NO' or 'Off'. If it did, it would be considered as 'ON' as per the documentation that says "Set this to a NON-Empty Value". It does not specify that it has to be any value in particular. I bet this is why secure pages fails on some servers completely if it's looking for the word 'on' like you had in your example. Perhaps if that is indeed what they check on, then someone should tell them that it should be changed to something similar to what I've just put up instead.
Comment #3
joelstein commentedSounds good; thanks for the update!
Comment #4
Jeff Burnz commented@#2, OK, so what your saying is that if there is a value its ON, otherwise if it is empty, its OFF, correct?
Comment #5
crystaldawn commentedYesserieBob. Any value == on and no value == off. So checking for == 'on' would be incorrect as the word 'on' is OS/Server/Language/Config dependent.
Comment #8
thinkyhead commentedI'm still seeing this general issue in 6.x-1.28. The code to check for HTTPS is incorrect according to specs. The PHP documentation at first says that $_SERVER['HTTPS'] will simply be set to a "non-empty" value. But it then goes on to say it could be set to "off" in some environments. In my environment (Pantheon) it is suddenly set to "OFF." This caused uc_ssl to go into an infinite redirect loop, taking down our site.
I fixed the code this way:
I removed the isset() test because empty() uses isset() internally.