Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

HTTPS Only #76

Closed
joshfriend opened this issue Feb 13, 2020 · 2 comments
Closed

HTTPS Only #76

joshfriend opened this issue Feb 13, 2020 · 2 comments
Labels
bug

Comments

@joshfriend
Copy link

@joshfriend joshfriend commented Feb 13, 2020

The website currently supports both HTTP and HTTPS but only has a 301 redirect to the secure version on the main page. If a user visits the site via a non-https share link (as I did), the site will not direct them to a secure version if they want to look up their own info. Given that the info required to look up a ballot is enough PII to easily go find more PII about the user, this should probably only operate over HTTPS.

@jacebrowning jacebrowning added the bug label Feb 13, 2020
@jacebrowning

This comment has been minimized.

Copy link
Member

@jacebrowning jacebrowning commented Feb 13, 2020

@joshfriend This should be fixed now.

http://share.michiganelections.io/elections/38/precincts/1209/ redirects to HTTPS. Please let us know if you see something different.

@joshfriend

This comment has been minimized.

Copy link
Author

@joshfriend joshfriend commented Feb 13, 2020

Perfect 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
2 participants
You can’t perform that action at this time.