[Xerte] Re: Query about Xerte https access

Smith, John J.J.Smith at gcu.ac.uk
Wed Jul 24 20:12:54 BST 2013


Surely that's up to be server to decide...

If server doesn't support and you set the base url https:// then what happens?

I'm not saying I'm right - 50% of the time i'm probably not - how do others do it?

I see your point that in some cases there may be a need, but would thwarting default if nothing was requested not be http? Like if you omit the port then you get 80... Unless you've changed the server config...

Or we set the base and redirect all http to https...

I dont really know... I just remember seeing the script or style tags in tow source code for play (or somewhere else) that are written by some _ function and one block was all relative and the other block all hardwired and thinking "that's odd"

Regards

John Smith
Learning Technologist
School of Health and Life Sciences

Sent from Samsung Galaxy SII



"Pat @ Pgogy" <xerte at pgogywebstuff.com> wrote:


LTI stuff / password play

And how do we know you have https?

On 24 Jul 2013, at 19:51, "Smith, John" <J.J.Smith at gcu.ac.uk> wrote:

> Same as request? When wouldn't you know?
>
> I'd just use the $_SERVER object to work it out... No?
>
> Regards
>
> John Smith
> Learning Technologist
> School of Health and Life Sciences
>
> Sent from Samsung Galaxy SII
>
>
>
> "Pat @ Pgogy" <xerte at pgogywebstuff.com> wrote:
>
>
> How would you handle requests where you don't know?
>
> On 24 Jul 2013, at 18:54, "Smith, John" <J.J.Smith at gcu.ac.uk> wrote:
>
>> Is it not better than being hardwired?
>>
>> If we access on https then that's used, if we access on http then that's used... Or am i missing something??
>>
>> Regards
>>
>> John Smith
>> Learning Technologist
>> School of Health and Life Sciences
>>
>> Sent from Samsung Galaxy SII
>>
>>
>>
>> "Pat @ Pgogy" <xerte at pgogywebstuff.com> wrote:
>>
>>
>> Does that matter?
>>
>> On 24 Jul 2013, at 18:36, "Smith, John" <J.J.Smith at gcu.ac.uk> wrote:
>>
>>> Surely you can just work out the url in PHP and pass in if required though...
>>>
>>> What if site can be accessed at either http or https... You don't know upfront which scheme will be used...
>>>
>>> Regards
>>>
>>> John Smith
>>> Learning Technologist
>>> School of Health and Life Sciences
>>>
>>> Sent from Samsung Galaxy SII
>>>
>>>
>>>
>>> "Pat @ Pgogy" <xerte at pgogywebstuff.com> wrote:
>>>
>>>
>>> Until you use flash
>>>
>>> On 24 Jul 2013, at 18:18, "Smith, John" <J.J.Smith at gcu.ac.uk> wrote:
>>>
>>>> Why do we even still hardwire the scheme and url in site_details anyway?
>>>>
>>>> All site specific urls should be relative no? Relative to the current scheme and current domain...
>>>>
>>>> Regards
>>>>
>>>> John Smith
>>>> Learning Technologist
>>>> School of Health and Life Sciences
>>>>
>>>> Sent from Samsung Galaxy SII
>>>>
>>>>
>>>>
>>>> "Pat @ Pgogy" <xerte at pgogywebstuff.com> wrote:
>>>>
>>>>
>>>> It's probably because the site URL is set as http
>>>>
>>>> Try setting the site URL to https
>>>>
>>>> On 24 Jul 2013, at 16:36, Jamie Wood <jwood at lincoln.ac.uk> wrote:
>>>>
>>>>> Hi,
>>>>>
>>>>> We're running a Xerte project here at Lincoln and have come across a problem with Chrome (and other browsers) running Xerte over https. I've copied over a query from our Centre for Educational Research and Development below about this technical issue. Can anyone help with this and the questions in the paragraphs within the dotted lines below?
>>>>>
>>>>> ------------
>>>>> The issue seems to be that Chrome has a problem with running Xerte securely over https. It says that although https is turned on on our server, some of the files are non-securely 'leaking' over http. It seems to be especially strict about this, compared to other browsers. If I turn off https altogether and, this is key, remove all cookies and browsing history from Chrome, then it performs perfectly OK over http.
>>>>>
>>>>> The problem we have is that to use university logins, we need to run it over https, and if the tool is going to be used by 100+ people, this is by far the preferred method of login.
>>>>>
>>>>> Jamie, please could you write to the mailing list, copying me in, reporting this problem and asking for advice? How are other institutions running it successfully over https? Why is Xerte serving certain files over http, when https is being requested? This seems like a bug and a security issue with Xerte to me.
>>>>> -------------------
>>>>>
>>>>>
>>>>> Bests
>>>>> Jamie
>>>>>
>>>>>
>>>>> Dr Jamie Wood
>>>>> Lecturer in History,
>>>>> School of Humanities,
>>>>> University of Lincoln,
>>>>> Brayford Pool,
>>>>> Lincoln LN6 7TS
>>>>>
>>>>> Email: jwood at lincoln.ac.uk<mailto:jwood at lincoln.ac.uk>
>>>>> Tel.: +44(0)1522 837389
>>>>> Website: http://staff.lincoln.ac.uk/jwood
>>>>> Twitter: @woodjamie99<https://twitter.com/woodjamie99>
>>>>>
>>>>> _______________________________________________
>>>>> Xerte mailing list
>>>>> Xerte at lists.nottingham.ac.uk
>>>>> http://lists.nottingham.ac.uk/mailman/listinfo/xerte
>>>>> This message and any attachment are intended solely for the addressee and may contain confidential information. If you have received this message in error, please send it back to me, and immediately delete it.   Please do not use, copy or disclose the information contained in this message or in any attachment.  Any views or opinions expressed by the author of this email do not necessarily reflect the views of the University of Nottingham.
>>>>>
>>>>> This message has been checked for viruses but the contents of an attachment
>>>>> may still contain software viruses which could damage your computer system, you are advised to perform your own checks. Email communications with the University of Nottingham may be monitored as permitted by UK legislation.
>>>>
>>>> _______________________________________________
>>>> Xerte mailing list
>>>> Xerte at lists.nottingham.ac.uk
>>>> http://lists.nottingham.ac.uk/mailman/listinfo/xerte
>>>> This message and any attachment are intended solely for the addressee and may contain confidential information. If you have received this message in error, please send it back to me, and immediately delete it.   Please do not use, copy or disclose the information contained in this message or in any attachment.  Any views or opinions expressed by the author of this email do not necessarily reflect the views of the University of Nottingham.
>>>>
>>>> This message has been checked for viruses but the contents of an attachment
>>>> may still contain software viruses which could damage your computer system, you are advised to perform your own checks. Email communications with the University of Nottingham may be monitored as permitted by UK legislation.
>>>>
>>>>
>>>>
>>>>
>>>>
>>>> Glasgow Caledonian University is a registered Scottish charity, number SC021474
>>>>
>>>> Winner: Times Higher Education's Widening Participation Initiative of the Year 2009 and Herald Society's Education Initiative of the Year 2009.
>>>> http://www.gcu.ac.uk/newsevents/news/bycategory/theuniversity/1/name,6219,en.html
>>>>
>>>> Winner: Times Higher Education's Outstanding Support for Early Career Researchers of the Year 2010, GCU as a lead with Universities Scotland partners.
>>>> http://www.gcu.ac.uk/newsevents/news/bycategory/theuniversity/1/name,15691,en.html
>>>>
>>>> _______________________________________________
>>>> Xerte mailing list
>>>> Xerte at lists.nottingham.ac.uk
>>>> http://lists.nottingham.ac.uk/mailman/listinfo/xerte
>>>> This message and any attachment are intended solely for the addressee and may contain confidential information. If you have received this message in error, please send it back to me, and immediately delete it.   Please do not use, copy or disclose the information contained in this message or in any attachment.  Any views or opinions expressed by the author of this email do not necessarily reflect the views of the University of Nottingham.
>>>>
>>>> This message has been checked for viruses but the contents of an attachment
>>>> may still contain software viruses which could damage your computer system, you are advised to perform your own checks. Email communications with the University of Nottingham may be monitored as permitted by UK legislation.
>>>
>>> _______________________________________________
>>> Xerte mailing list
>>> Xerte at lists.nottingham.ac.uk
>>> http://lists.nottingham.ac.uk/mailman/listinfo/xerte
>>> This message and any attachment are intended solely for the addressee and may contain confidential information. If you have received this message in error, please send it back to me, and immediately delete it.   Please do not use, copy or disclose the information contained in this message or in any attachment.  Any views or opinions expressed by the author of this email do not necessarily reflect the views of the University of Nottingham.
>>>
>>> This message has been checked for viruses but the contents of an attachment
>>> may still contain software viruses which could damage your computer system, you are advised to perform your own checks. Email communications with the University of Nottingham may be monitored as permitted by UK legislation.
>>>
>>>
>>>
>>>
>>>
>>> Glasgow Caledonian University is a registered Scottish charity, number SC021474
>>>
>>> Winner: Times Higher Education's Widening Participation Initiative of the Year 2009 and Herald Society's Education Initiative of the Year 2009.
>>> http://www.gcu.ac.uk/newsevents/news/bycategory/theuniversity/1/name,6219,en.html
>>>
>>> Winner: Times Higher Education's Outstanding Support for Early Career Researchers of the Year 2010, GCU as a lead with Universities Scotland partners.
>>> http://www.gcu.ac.uk/newsevents/news/bycategory/theuniversity/1/name,15691,en.html
>>>
>>> _______________________________________________
>>> Xerte mailing list
>>> Xerte at lists.nottingham.ac.uk
>>> http://lists.nottingham.ac.uk/mailman/listinfo/xerte
>>> This message and any attachment are intended solely for the addressee and may contain confidential information. If you have received this message in error, please send it back to me, and immediately delete it.   Please do not use, copy or disclose the information contained in this message or in any attachment.  Any views or opinions expressed by the author of this email do not necessarily reflect the views of the University of Nottingham.
>>>
>>> This message has been checked for viruses but the contents of an attachment
>>> may still contain software viruses which could damage your computer system, you are advised to perform your own checks. Email communications with the University of Nottingham may be monitored as permitted by UK legislation.
>>
>> _______________________________________________
>> Xerte mailing list
>> Xerte at lists.nottingham.ac.uk
>> http://lists.nottingham.ac.uk/mailman/listinfo/xerte
>> This message and any attachment are intended solely for the addressee and may contain confidential information. If you have received this message in error, please send it back to me, and immediately delete it.   Please do not use, copy or disclose the information contained in this message or in any attachment.  Any views or opinions expressed by the author of this email do not necessarily reflect the views of the University of Nottingham.
>>
>> This message has been checked for viruses but the contents of an attachment
>> may still contain software viruses which could damage your computer system, you are advised to perform your own checks. Email communications with the University of Nottingham may be monitored as permitted by UK legislation.
>>
>>
>>
>>
>>
>> Glasgow Caledonian University is a registered Scottish charity, number SC021474
>>
>> Winner: Times Higher Education's Widening Participation Initiative of the Year 2009 and Herald Society's Education Initiative of the Year 2009.
>> http://www.gcu.ac.uk/newsevents/news/bycategory/theuniversity/1/name,6219,en.html
>>
>> Winner: Times Higher Education's Outstanding Support for Early Career Researchers of the Year 2010, GCU as a lead with Universities Scotland partners.
>> http://www.gcu.ac.uk/newsevents/news/bycategory/theuniversity/1/name,15691,en.html
>>
>> _______________________________________________
>> Xerte mailing list
>> Xerte at lists.nottingham.ac.uk
>> http://lists.nottingham.ac.uk/mailman/listinfo/xerte
>> This message and any attachment are intended solely for the addressee and may contain confidential information. If you have received this message in error, please send it back to me, and immediately delete it.   Please do not use, copy or disclose the information contained in this message or in any attachment.  Any views or opinions expressed by the author of this email do not necessarily reflect the views of the University of Nottingham.
>>
>> This message has been checked for viruses but the contents of an attachment
>> may still contain software viruses which could damage your computer system, you are advised to perform your own checks. Email communications with the University of Nottingham may be monitored as permitted by UK legislation.
>
> _______________________________________________
> Xerte mailing list
> Xerte at lists.nottingham.ac.uk
> http://lists.nottingham.ac.uk/mailman/listinfo/xerte
> This message and any attachment are intended solely for the addressee and may contain confidential information. If you have received this message in error, please send it back to me, and immediately delete it.   Please do not use, copy or disclose the information contained in this message or in any attachment.  Any views or opinions expressed by the author of this email do not necessarily reflect the views of the University of Nottingham.
>
> This message has been checked for viruses but the contents of an attachment
> may still contain software viruses which could damage your computer system, you are advised to perform your own checks. Email communications with the University of Nottingham may be monitored as permitted by UK legislation.
>
>
>
>
>
> Glasgow Caledonian University is a registered Scottish charity, number SC021474
>
> Winner: Times Higher Education’s Widening Participation Initiative of the Year 2009 and Herald Society’s Education Initiative of the Year 2009.
> http://www.gcu.ac.uk/newsevents/news/bycategory/theuniversity/1/name,6219,en.html
>
> Winner: Times Higher Education’s Outstanding Support for Early Career Researchers of the Year 2010, GCU as a lead with Universities Scotland partners.
> http://www.gcu.ac.uk/newsevents/news/bycategory/theuniversity/1/name,15691,en.html
> _______________________________________________
> Xerte mailing list
> Xerte at lists.nottingham.ac.uk
> http://lists.nottingham.ac.uk/mailman/listinfo/xerte

_______________________________________________
Xerte mailing list
Xerte at lists.nottingham.ac.uk
http://lists.nottingham.ac.uk/mailman/listinfo/xerte

Glasgow Caledonian University is a registered Scottish charity, number SC021474

Winner: Times Higher Education’s Widening Participation Initiative of the Year 2009 and Herald Society’s Education Initiative of the Year 2009.
http://www.gcu.ac.uk/newsevents/news/bycategory/theuniversity/1/name,6219,en.html

Winner: Times Higher Education’s Outstanding Support for Early Career Researchers of the Year 2010, GCU as a lead with Universities Scotland partners.
http://www.gcu.ac.uk/newsevents/news/bycategory/theuniversity/1/name,15691,en.html


More information about the Xerte mailing list