HTTP not redirecting to HTTPS on patchwork.ozlabs.org

Philipp Richter richterphilipp.pops at gmail.com
Tue Sep 11 19:05:03 AEST 2018


Hello,

I noticed that accessing patchwork.ozlabs.org did not automatically
redirect to HTTPS. The validation link sent in the e-mail also doesn't
have https:// prepended to it.
This is a bit risky while registering or logging in. This was first
apparent from https://buildroot.org/contribute.html which linked to
the http unsecured patchwork page, they already committed a forced
https:// on the link.

I would strongly suggest forcing a 301 redirect to the https version
of the site in the webserver configuration.

Thank you for hearing me out.

Best Regards,
Philipp Richter


More information about the Patchwork mailing list