Opened 7 years ago

Closed 7 years ago

Last modified 7 years ago

#8572 closed defect (fixed)

CloudFront CDN "Access Denied" with HTTPS

Reported by: vegbrasil Owned by: yan
Priority: High Milestone: HTTPS-E 3.2
Component: HTTPS Everywhere/EFF-HTTPS Everywhere Version: HTTPS-E 3.1.4
Severity: Keywords: httpse-ruleset-bug
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

Some sites that uses CloudFront as a CDN service, should recive "Access Denied" if you force HTTPS.

Appears that not all the sites pay for use HTTPS on CloudFront.

Example: Droplr (sharing service) - http://d.pr/i/6s2f or http://d.pr/i/6s2f+  with the CloudFront rule active will get "Access Denied".

Thanks!

Child Tickets

Change History (6)

comment:1 Changed 7 years ago by pde

Owner: changed from pde to yan
Status: newassigned

comment:2 Changed 7 years ago by pde

Milestone: HTTPS-E 3.1.5

comment:3 Changed 7 years ago by yan

Status: assignedneeds_review

I fixed this for Droplr specifically: https://github.com/diracdeltas/https-everywhere/commit/0b1af020b523e6e5fb72d899d19f458316204023

Let me know if you have more examples of this bug.

thanks!
-yan

comment:4 in reply to:  3 ; Changed 7 years ago by yan

Replying to yan:

I fixed this for Droplr specifically: https://github.com/diracdeltas/https-everywhere/commit/0b1af020b523e6e5fb72d899d19f458316204023

Let me know if you have more examples of this bug.

thanks!
-yan

edited commit message: https://github.com/diracdeltas/https-everywhere/commit/72c9bc2a3b48a72c8280c365460f1966b77858a4

comment:5 in reply to:  4 Changed 7 years ago by pde

Resolution: fixed
Status: needs_reviewclosed

Merged in 3.0, and cherry-picked into master.

I think I got both of your commit messages into the history :). Changing a commit message is consequence-free (and easy with "git commit --amend") until you've pushed it; after that there are ways to do a destructive update (git push -f) that may or may not cause consequences/merges/problems later.

edited commit message: https://github.com/diracdeltas/https-everywhere/commit/72c9bc2a3b48a72c8280c365460f1966b77858a4

comment:6 in reply to:  3 Changed 7 years ago by pde

Replying to yan:

Let me know if you have more examples of this bug.

Also, yes, there will be more of these :)

Note: See TracTickets for help on using tickets.