Do not hardcode CDN mozorg.cdn.mozilla.net

VERIFIED FIXED in 2014-10

Status

addons.mozilla.org Graveyard
Code Quality
P3
normal
VERIFIED FIXED
4 years ago
2 years ago

People

(Reporter: TheOne, Assigned: aspyrine)

Tracking

unspecified
2014-10

Details

(Reporter)

Description

4 years ago
Hardcoding the CDN the way we currently do breaks dev instances if you access them via http as the CDN is CSP whitelisted via https only.

~/mozilla/olympia $ grep -R "mozorg.cdn" *
templates/impala/base.html:    <link href="//mozorg.cdn.mozilla.net/media/css/tabzilla-min.css" rel="stylesheet" />
templates/impala/base.html:    <script src="//mozorg.cdn.mozilla.net/{{ LANG }}/tabzilla/tabzilla.js"></script>
templates/base.html:           <link href="//mozorg.cdn.mozilla.net/media/css/tabzilla-min.css" rel="stylesheet" />
templates/base.html:           <script src="//mozorg.cdn.mozilla.net/{{ LANG }}/tabzilla/tabzilla.js"></script>

(irrelevant results removed)
Priority: -- → P3
Target Milestone: --- → 2014-09
(Reporter)

Comment 1

4 years ago
Can we just

s/=/=https:\/\//

ie insert https:// as I don't see that olympia contains tabzilla?
Assignee: nobody → olivier
(Assignee)

Comment 2

3 years ago
(In reply to Andreas Wagner [:TheOne] from comment #1)
> Can we just
> 
> s/=/=https:\/\//

As suggested, I changed scheme to https in https://github.com/mozilla/olympia/pull/310
(Assignee)

Comment 4

3 years ago
(In reply to Christopher Van Wiemeersch [:cvan] from comment #3)
> I can file a separate bug if you'd wish.

I would take care of this right now, don't bother with another bug :)
Target Milestone: 2014-09 → 2014-10
(Assignee)

Comment 5

3 years ago
> I would take care of this right now, don't bother with another bug :)

Done https://github.com/mozilla/olympia/pull/312
Thanks again! Merged:
https://github.com/mozilla/olympia/commit/8497a03
Status: NEW → RESOLVED
Last Resolved: 3 years ago
Resolution: --- → FIXED

Comment 7

3 years ago
Please add STR here or mark it with [qa-] if no QA is needed.
(Assignee)

Comment 8

3 years ago
1/ Open https://addons-dev.allizom.org/fr/firefox/
2/ View the page source
3/ Check that URLs for mozorg.cdn.mozilla.net start with "https://"
4/ Check that URLs for cdn.optimizely.com start with "https://"

Comment 9

3 years ago
Verified as fixed in FF32(Win7) in marketplace-dev.allizom.org
Postfix screencast: http://screencast.com/t/r0wyCZoULk
Closing.
Status: RESOLVED → VERIFIED
Product: addons.mozilla.org → addons.mozilla.org Graveyard
You need to log in before you can comment on or make changes to this bug.