Opened 7 years ago

Closed 7 years ago

Last modified 7 years ago

#7650 closed defect (fixed)

"Asymmetric Publications (partial)" rule breaks kingdomofloathing.com

Reported by: zwol Owned by: pde
Priority: Medium Milestone:
Component: HTTPS Everywhere/EFF-HTTPS Everywhere Version:
Severity: Keywords: httpse-ruleset-bug
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

The ruleset Asymmetric-Publications.xml (aka "Asymmetric Publications (partial)") attempts to rewrite all URLs under *.kingdomofloathing.com to HTTPS. If you log into the site with this rule in effect, you will be taken to https://www.kingdomofloathing.com/game.php, which force-redirects to http://www.kingdomofloathing.com/game.php with a <meta http-equiv="refresh"> tag in the HTML (*not* with an HTTP 3xx response code). The ruleset will rewrite this load back to https://, placing the site into an infinite loop.

I don't know how much of the site will refuse to be served over HTTPS. It is possible that just blacklisting game.php would make the ruleset work; however, it seems clearly the intention of the site admins to serve only the login page over HTTPS (optionally), so I'd be inclined to follow suit.

I was going to inquire about the level of HTTPS support in the site's forums but I can't log in there.

Child Tickets

Change History (5)

comment:1 Changed 7 years ago by zwol

Having recovered access to the KoL forums, I posted a query here: http://forums.kingdomofloathing.com/vb/showthread.php?p=4339631

comment:2 Changed 7 years ago by cypherpunks

I just signed up for kingdomofloathing and had to figure out why the browser was thrashing so hard and constantly redirecting. Disabling https everywhere for asymmetric publications fixed the issue.

comment:3 Changed 7 years ago by mikeperry

Keywords: httpse-ruleset-bug added

comment:4 Changed 7 years ago by schoen

Resolution: fixed
Status: newclosed

I'm turning off this rule for the time being, and I'll try to drop a note to the KoL developers to ask about it.

comment:5 Changed 7 years ago by schoen

OK, I have an indirect inquiry in to the developers. :-)

Note: See TracTickets for help on using tickets.