Uploaded image for project: 'Shindig'
  1. Shindig
  2. SHINDIG-1870

Cross-site issue as http scheme is hardcoded in some URI template in container.js

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Open
    • Major
    • Resolution: Unresolved
    • None
    • None
    • None
    • None

    Description

      Some URI templates defined in container.js has scheme hardcoded as 'http'. That leads to cross-site problem as we have Apache Http (configured to use with https) in front of Tomcat + Shindig

      Detail info:

      We have one portal application configured to access via 'https', the embedded shindig server using default container.js (with 'http' in some URL templates) runs on the same host. As our gadgets (ones using OpenSocial API) fetch metadata via Ajax request, the cross-site issue appears

      Attachments

        1. patch
          0.5 kB
          Minh Hoang TO

        Issue Links

          Activity

            People

              Unassigned Unassigned
              mto Minh Hoang TO
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated: