@[email protected] to [email protected]English • 6 months agoYour API Shouldn't Redirect HTTP to HTTPSjviide.iki.fiexternal-linkmessage-square13fedilinkarrow-up11arrow-down10cross-posted to: programming
arrow-up11arrow-down1external-linkYour API Shouldn't Redirect HTTP to HTTPSjviide.iki.fi@[email protected] to [email protected]English • 6 months agomessage-square13fedilinkcross-posted to: programming
minus-square@[email protected]linkfedilink0•edit-26 months agoThis article isn’t about browsers or websites, and even acknowledges in the opening that it makes sense as a usability tradeoff in that context.
minus-square@[email protected]linkfedilink0•6 months agoI clearly didn’t read it. It makes sense, if users aren’t visiting the API then it really doesn’t matter that it’s not redirected on insecure connections.
minus-squarepinchcramplinkfedilinkEnglish0•edit-26 months ago I clearly didn’t read it. I love the honesty. It’s really refreshing to see someone take accountability instead of becoming defensive.
This article isn’t about browsers or websites, and even acknowledges in the opening that it makes sense as a usability tradeoff in that context.
I clearly didn’t read it. It makes sense, if users aren’t visiting the API then it really doesn’t matter that it’s not redirected on insecure connections.
I love the honesty. It’s really refreshing to see someone take accountability instead of becoming defensive.