https://bugzilla.wikimedia.org/show_bug.cgi?id=37790
jeremyb <bugzilla+org.wikime...@tuxmachine.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|RESOLVED |REOPENED CC| |lvi...@wikimedia.org Resolution|FIXED |--- --- Comment #11 from jeremyb <bugzilla+org.wikime...@tuxmachine.com> --- https://shop.wikimedia.org/ seems ok. or not, now is 502. and now fixed again? some outstanding issues: * make links from pages like https://shop.wikimedia.org/pages/privacy-policy (and other pages like https://shop.wikimedia.org/pages/about-wikimedia ) to WMF wikis or other parts of the shop site use HTTPS (or protorel) * https://shop.wikimedia.org/products/wikipedia-globe-sweats has mixed-content warnings and also probably violates the site's privacy policy (3rd-party cookies that are not really necessary) and when loading the facebook widget passes in a URL as param with HTTP as protocol (not HTTPS)[0] * fonts pulled from google rather than WMF or shopify. (again, possible privacy policy violation? CC luis to look into these parts) * https://shop.wikimedia.org/account/register POSTs to HTTPS and then (if e.g. you submit a blank form or have some other error) sends you a 302 to the cleartext (HTTP) site. [0] Blocked loading mixed active content "http://platform.twitter.com/widgets.js" @ https://shop.wikimedia.org/products/wikipedia-globe-sweats Blocked loading mixed active content "http://assets.pinterest.com/js/pinit.js" @ https://shop.wikimedia.org/products/wikipedia-globe-sweats GET https://www.facebook.com/plugins/like.php?href=http://shop.wikimedia.org/products/wikipedia-globe-sweats&send=false&layout=button_count&width=120&show_faces=false&action=like&colorscheme=light&font&height=21 [HTTP/1.1 200 OK 405ms] -- You are receiving this mail because: You are on the CC list for the bug. _______________________________________________ Wikibugs-l mailing list Wikibugs-l@lists.wikimedia.org https://lists.wikimedia.org/mailman/listinfo/wikibugs-l