Closed Bug 896745 Opened 11 years ago Closed 8 years ago

https://opendesktop.org/ does not work properly because of mixed content blocking

Categories

(Web Compatibility :: Site Reports, defect)

defect
Not set
major

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: mwobensmith, Assigned: adamopenweb)

References

()

Details

(Whiteboard: [mcb-chrome][mcb-ie][mcb-no-contact] [sitewait])

Mixed content blocking is a feature that prevents insecure elements on secure pages from loading. In Firefox 23, this feature will default to blocking "active" insecure content, which may break some web sites. 

More information on Firefox's Mixed Content Blocker is below: 
http://blog.mozilla.org/tanvi/2013/04/10/mixed-content-blocking-enabled-in-firefox-23/

The site is also broken in Chrome 28 and IE10.

The security feature is currently breaking the HTTPS version of opendesktop.org.  The following HTTP assets are blocked:

 Blocked loading mixed active content "http://opendesktop.org/styles/global-style.css" @ https://opendesktop.org/
 Blocked loading mixed active content "http://opendesktop.org/styles/style-opendesktop.css" @ https://opendesktop.org/
 Blocked loading mixed active content "http://opendesktop.org/fancybox/jquery.fancybox-1.3.4.css" @ https://opendesktop.org/
 Blocked loading mixed active content "http://opendesktop.org/scripts/jquery-1.5.2.min.js" @ https://opendesktop.org/
 Blocked loading mixed active content "http://opendesktop.org/fancybox/jquery.fancybox-1.3.4.pack.js" @ https://opendesktop.org/
 Blocked loading mixed active content "http://opendesktop.org/scripts/helperfunctions.js" @ https://opendesktop.org/
 Blocked loading mixed active content "http://partner.googleadservices.com/gampad/google_service.js" @ https://opendesktop.org/
 Blocked loading mixed active content "http://pagead2.googlesyndication.com/pagead/show_ads.js" @ https://opendesktop.org/
Blocked loading mixed active content "http://web-static.ea.com/atlas/sw-combine/1374078725/aa9b219f67624074aa6ae611eb06bda0.js?v=1374078725" @ https://www.ea.com/
Blocked loading mixed active content "http://web-static.ea.com/atlas/sw-combine/1374078725/36a1a0d2fdf1f7ba7dcc49241f559ca1.js?v=1374078725" @ https://www.ea.com/
Blocked loading mixed active content "http://connect.facebook.net/en_US/all.js#xfbml=1" @ https://www.ea.com/
Blocked loading mixed active content "http://static.ak.fbcdn.net/connect.php/js/FB.Share" @ https://www.ea.com/
Blocked loading mixed active content "http://platform.twitter.com/widgets.js" @ https://www.ea.com/
Blocked loading mixed active content "http://display.digitalriver.com/?aid=244&tax=eapmg" @ https://www.ea.com/
Blocked loading mixed active content "http://resources.ea.com/omniture/utils.js" @ https://www.ea.com/
Blocked loading mixed active content "http://resources.ea.com/omniture/s_code_remote_v02.js" @ https://www.ea.com/
Blocked loading mixed active content "http://resources.ea.com/omniture/omniture_wrapper.js" @ https://www.ea.com/


This issue should also exist for your IE and Chrome users (although I have not confirmed on IE).

To fix this security issue, serve the content over HTTPS and change the link in the HTML source to point to the https:// version of the content.

This was originally reported by a user in bug https://bugzilla.mozilla.org/show_bug.cgi?id=844556#c29
I filled out their Contact feedback form.  Not sure if that will end up making it to their web developers or not.
@tanvi:(In reply to Tanvi Vyas [:tanvi] from comment #1)
> I filled out their Contact feedback form.  Not sure if that will end up
> making it to their web developers or not.

Probably not, I just tried to sent the site a message, both via Firefox and Rekonq, and Rekonq showed a notification page, whereas FF did not.  I will send them a message to this bug report.
Component: English US → Desktop
Still some problems here.
If we're going to contact them, here are some possible contact points:
Twitter: https://twitter.com/fkarlitschek
Contactlink: https://opendesktop.org/feedback/
Whiteboard: [mcb-chrome][mcb-ie][mcb-no-contact] → [mcb-chrome][mcb-ie][mcb-no-contact] [contactready]
Reached out via twitter.
https://twitter.com/AdamOpenWeb/status/728374722325565440
Assignee: english-us → astevenson
Status: NEW → ASSIGNED
Whiteboard: [mcb-chrome][mcb-ie][mcb-no-contact] [contactready] → [mcb-chrome][mcb-ie][mcb-no-contact] [sitewait]
I'm not seeing any mcb issues on this page now in Firefox Nightly 51. Closing as fixed.
Status: ASSIGNED → RESOLVED
Closed: 8 years ago
Resolution: --- → FIXED
Product: Tech Evangelism → Web Compatibility
You need to log in before you can comment on or make changes to this bug.