Switching from http: to https:

1 view
Skip to first unread message

Jonathan A Rees

unread,
Nov 24, 2015, 3:21:45 PM11/24/15
to opentreeofl...@googlegroups.com
We are getting ready to switch all of the open tree API services over to https:. I wanted to send out a heads-up to alert anyone who has a stake in the URLs we use (working code, documentation, tutorials, etc.).

https://github.com/OpenTreeOfLife/opentree/pull/810

The plan is to use 301 redirects to automatically convert http requests to https, and document the https: URLs as the way to use the API. This is not a done deal, so now is the time to review and discuss!

Use of https: URLs is unaffected.
Use of http: URLs with GET (not POST) is unaffected (most tools will redirect automatically).
POST to http: URLs through the python 'requests' library is unaffected.
POST to http: URLs with 'curl' requires use of the -L --post301 curl flags.
POST to http: URLs through 'wget' only works with the very latest (Nov 15) version of wget.

There are two reasons for this:
1. It was the most economical way we could figure out to repair an obscure but very serious curator webapp login bug
2. It is the way the Web is going in response to escalating attacks on privacy and communication integrity  (this is certainly post hoc as a justification, but it is true)

Jonathan

Mark Holder

unread,
Nov 25, 2015, 8:40:55 AM11/25/15
to opentreeofl...@googlegroups.com
Hi Jonathan,
Thanks for the announcement and summary of the implications.

I say: go for it.

The current curator bug is almost certainly a more serious problem
than anything ripple effects involving updating clients of the API.

Mark
> --
> You received this message because you are subscribed to the Google Groups
> "Open Tree of Life - Software Development" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to opentreeoflife-so...@googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.



--
Mark Holder

mtho...@gmail.com
mtho...@ku.edu
http://phylo.bio.ku.edu/mark-holder

==============================================
Department of Ecology and Evolutionary Biology
University of Kansas
6031 Haworth Hall
1200 Sunnyside Avenue
Lawrence, Kansas 66045

lab phone: 785.864.5789
fax (shared): 785.864.5860
==============================================
Reply all
Reply to author
Forward
0 new messages