Closed (won't fix)
Project:
Drupal.org CVS applications
Component:
new project application
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Issue tags:
Reporter:
Created:
26 May 2010 at 18:21 UTC
Updated:
18 Apr 2019 at 20:27 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #1
veracium commentedComment #2
avpadernoHello, and thanks for applying for a CVS account. I am adding the review tags, and some volunteers will review your code, pointing out what needs to be changed.
As per http://drupal.org/cvs-application/requirements, the motivation message should be expanded to contain more details about the features of the proposed module/theme; for modules it should include also a comparison with the existing solutions, while for themes a screenshot is also required.
Comment #3
veracium commentedProblem
A problem faced by many Drupal admins on secure SSL sites is that hardcoded image URLs, created by modules such as ImageCache and Blog API, tend to have non secure URLs[1][2][3]. What happens then is that when the users try to access the page with
https://yoursite.tld, the images get delivered ashttp://yoursite.tld/someimages.png.This causes Internet Explorer to throw the following error:
Security Warning
Do you want to view only the webpage content that was delivered securely?
This Webpage contains content that will not be delivered using a secure HTTPS connection, which could compromise the security of the entire webpage.
Yes | No
Firefox and Chrome also indicate the same, although not so blatantly.
Solution
The proposed solution is to replace all instances of
http://yoursite.tld/someimages.pngwithhttp://yoursite.tld/someimages.pngwhen ever the user is accessing those images from a secure page.The Secure Image module is an implementation of this.
As far as we are aware, this functionality is not a duplicate of another module.
I am also attaching an updated version of the code.
Comment #4
avpadernoThanks for the reply.
Comment #5
wadmiraal commentedHi,
First: http://drupal.org/coding-standards. I always stress this point, but I think it's important that Drupal has a coherent, clean code repository (otherwise no-one would have bothered to write that guide in the first place). It's easier for everyone to find their way when all the code is formatted the same way.
Second, this only works for the body, not for any CCK or custom fields. This is not a blocker of course, but will you consider that for the future as well ? Because this is particularly important for e-commerce like sites. And their images are not likely to be found inside the body field.
[edit: I see that you've put a ToDo list in your code for this]
Otherwise, the code works fine. Good job
Comment #6
avpadernoI take the status has not been correctly set.
Comment #7
wadmiraal commented@kiamlaluno
Oops, sorry :-). I thought it was ok. But when can we set it to R&TBTC ? Or can only admins do that ? Cause I've set another one as well (http://drupal.org/node/798960)...
Comment #9
avpadernoThe comment is wrong.
@wadmiraal: It's fine if you set the status to , but not if the code doesn't respect the namespace. :-)
Comment #10
wadmiraal commented@kiamlaluno
Ok, got it :-)
Comment #11
billynytro commentedWhat is the status of this module? I'm stuck waiting for a fix to this problem before I can go live with my store.
Comment #12
wadmiraal commented@billynytro
Well, if you're really in a hurry, you can always download the alpha version with the first comment, but I wouldn't if I were you :-). Besides, this only works for images inside the body. If you have images for your products in any other field (like CCK), it won't solve the problem (yet - because it is not actually that difficult to get it to work for CCK fields. Just a little hook_nodeapi() on 'validate' and just update all "filefield" type fields...)
Comment #13
avpadernoComment #14
fehin commentedsubscribing
Comment #15
nelslynn commentedsubscribing
Comment #16
Arricc commentedMade a module to fix this problem for a project a few years ago, and finally got round to putting it up on my site.
Too lazy to upload it here and don't have the time to maintain/bugfix at the moment.
http://www.arricc.net/drupal-https-images.php
Comment #17
avpaderno