Should the image tag only work with https links?

Hey GGG,

Not sure if this is a bug per se; I think it's more of an oversight.

I'm connecting to your site using https, and most of the time my browser is satisfied the connection is fully secure. I noticed earlier today that sometimes the padlock icon representing a secure connection vanishes, and I spent a while trying to figure out why. It's http links in image tags.

Is this a big deal? Probably not, and I totally understand if you're not excited about tweaking the image tag to only accept https links - breaking hundreds or more of posts in the process. But with web browsers employing increasingly scary messages about insecure connections, I just wanted to let you know about this in case you weren't aware of it. If it's possible to leave existing posts alone, but not accept future posts if a http link is in an image tag, that might be worth considering.

tl;dr: Image tag can cause images to be loaded over a http connection, which doesn't go unnoticed by the web browser. There may come a day when browsers start complaining about this.

Steps to reproduce this
  • For an example of this phenomenon, go to this thread.
  • Check your connection. It should be https, but not fully secure.
  • Look at this post from k1rage. It has a http link in image tags.
  • Quote their post, and click on the Preview button.
  • Check your connection. It should be https, but not fully secure.
  • Edit the url to make it a https link, then click on the Preview button.
  • Check your connection. It should be https. Fully secure!

If when you test this someone has recently posted using another http url in image tags, it might break the test. You should be able to test it in another thread, or even start your own.

What I used while testing this
This should be reproducible for everyone.

Nevertheless, here's what I was using while testing;
  • Browser: Vivaldi x64 v1.8.770.50. (Based on Chromium v57.0.2987.111)
  • OS: Linux Mint 18.1 Sarena.


Testing in Vivaldi?
If you're testing in Vivaldi, here's what to look for.

This is a fully secure connection;


This page has http urls in image tags;

“Please understand that imposing strong negative views regarding our team on to other players when you are representing our most helpful forum posters is not appropriate.” — GGG 2022

----

I'm not 'Sarno' on Discord. I don't know who that is.
Last bumped on Mar 29, 2017, 12:25:55 PM
This thread has been automatically archived. Replies are disabled.

Report Forum Post

Report Account:

Report Type

Additional Info