CVS edit link for veracium

I have created a new module to ensure that all image URLs from a site respect https:// secure SSL links. This solves the problem discussed here:
http://drupal.org/node/671920
http://drupal.org/node/548858
CommentFileSizeAuthor
#3 secure_image.tar_.gz1.13 KBveracium
#1 secure_image.tar_.gz903 bytesveracium

Comments

veracium’s picture

Status: Postponed (maintainer needs more info) » Needs review
StatusFileSize
new903 bytes
avpaderno’s picture

Status: Needs review » Needs work
Issue tags: +Module review

Hello, and thanks for applying for a CVS account. I am adding the review tags, and some volunteers will review your code, pointing out what needs to be changed.

As per http://drupal.org/cvs-application/requirements, the motivation message should be expanded to contain more details about the features of the proposed module/theme; for modules it should include also a comparison with the existing solutions, while for themes a screenshot is also required.

veracium’s picture

StatusFileSize
new1.13 KB

Problem

A problem faced by many Drupal admins on secure SSL sites is that hardcoded image URLs, created by modules such as ImageCache and Blog API, tend to have non secure URLs[1][2][3]. What happens then is that when the users try to access the page with https://yoursite.tld, the images get delivered as http://yoursite.tld/someimages.png.

This causes Internet Explorer to throw the following error:

Security Warning

Do you want to view only the webpage content that was delivered securely?

This Webpage contains content that will not be delivered using a secure HTTPS connection, which could compromise the security of the entire webpage.

Yes | No

 

Firefox and Chrome also indicate the same, although not so blatantly.

 

Solution

The proposed solution is to replace all instances of http://yoursite.tld/someimages.png with http://yoursite.tld/someimages.png when ever the user is accessing those images from a secure page.

The Secure Image module is an implementation of this.

 

As far as we are aware, this functionality is not a duplicate of another module.

I am also attaching an updated version of the code.

avpaderno’s picture

Status: Needs work » Needs review

Thanks for the reply.

wadmiraal’s picture

Status: Needs review » Reviewed & tested by the community

Hi,

First: http://drupal.org/coding-standards. I always stress this point, but I think it's important that Drupal has a coherent, clean code repository (otherwise no-one would have bothered to write that guide in the first place). It's easier for everyone to find their way when all the code is formatted the same way.

Second, this only works for the body, not for any CCK or custom fields. This is not a blocker of course, but will you consider that for the future as well ? Because this is particularly important for e-commerce like sites. And their images are not likely to be found inside the body field.
[edit: I see that you've put a ToDo list in your code for this]

Otherwise, the code works fine. Good job

avpaderno’s picture

Status: Reviewed & tested by the community » Needs work

I take the status has not been correctly set.

wadmiraal’s picture

@kiamlaluno

Oops, sorry :-). I thought it was ok. But when can we set it to R&TBTC ? Or can only admins do that ? Cause I've set another one as well (http://drupal.org/node/798960)...

avpaderno’s picture

  1. See http://drupal.org/coding-standards to understand how a module should be written. In particular see how functions, Drupal variables, global variables, and constants defined from the module should be named; see how the code should be formatted.
  2. /**
     * Implementation of hook_nodeapi()
     */
    function escape_string_for_regex($str)
    {
    

    The comment is wrong.

@wadmiraal: It's fine if you set the status to reviewed & tested from the community, but not if the code doesn't respect the namespace. :-)

wadmiraal’s picture

@kiamlaluno

Ok, got it :-)

billynytro’s picture

What is the status of this module? I'm stuck waiting for a fix to this problem before I can go live with my store.

wadmiraal’s picture

@billynytro

Well, if you're really in a hurry, you can always download the alpha version with the first comment, but I wouldn't if I were you :-). Besides, this only works for images inside the body. If you have images for your products in any other field (like CCK), it won't solve the problem (yet - because it is not actually that difficult to get it to work for CCK fields. Just a little hook_nodeapi() on 'validate' and just update all "filefield" type fields...)

avpaderno’s picture

Status: Needs work » Closed (won't fix)
fehin’s picture

subscribing

nelslynn’s picture

Component: Miscellaneous » miscellaneous

subscribing

Arricc’s picture

Made a module to fix this problem for a project a few years ago, and finally got round to putting it up on my site.

Too lazy to upload it here and don't have the time to maintain/bugfix at the moment.

http://www.arricc.net/drupal-https-images.php

avpaderno’s picture

Component: miscellaneous » new project application
Issue summary: View changes