canpolat@programming.dev to Programming@programming.devEnglish · 7 months agoYour API Shouldn't Redirect HTTP to HTTPSjviide.iki.fiexternal-linkmessage-square13fedilinkarrow-up1108cross-posted to: hackernews@lemmy.smeargle.fans
arrow-up1108external-linkYour API Shouldn't Redirect HTTP to HTTPSjviide.iki.ficanpolat@programming.dev to Programming@programming.devEnglish · 7 months agomessage-square13fedilinkcross-posted to: hackernews@lemmy.smeargle.fans
minus-squarevithigar@lemmy.calinkfedilinkarrow-up46·edit-27 months agoThis article isn’t about browsers or websites, and even acknowledges in the opening that it makes sense as a usability tradeoff in that context.
minus-squarev9CYKjLeia10dZpz88iU@programming.devlinkfedilinkarrow-up18·7 months agoI clearly didn’t read it. It makes sense, if users aren’t visiting the API then it really doesn’t matter that it’s not redirected on insecure connections.
minus-squarepinchcramp@lemmy.dbzer0.comlinkfedilinkEnglisharrow-up10·edit-27 months ago I clearly didn’t read it. I love the honesty. It’s really refreshing to see someone take accountability instead of becoming defensive.
This article isn’t about browsers or websites, and even acknowledges in the opening that it makes sense as a usability tradeoff in that context.
I clearly didn’t read it. It makes sense, if users aren’t visiting the API then it really doesn’t matter that it’s not redirected on insecure connections.
I love the honesty. It’s really refreshing to see someone take accountability instead of becoming defensive.