Support » Plugin: Autoptimize » CDN option protocol-relative

  • Hi,
    first of all thanks a lot for your powerfull plugin.

    in your cdn options you give examples of what could look the url: http, https, OR protocol-relative which i’ve used a lot, but according to Paul Irish we should not use protocol-relative anymore (2010 post updated on 2014…) as it open a door for attack.
    Paul Irish post about protocol-relative

    So maybe it would be wise in your admin page to remove protocol-relative text and keep http/https while putting an accent on https use ; those who know don’t make this “error” but i think a lot of people use this protocol (including me).

    What do you think of it?

Viewing 2 replies - 1 through 2 (of 2 total)
  • Plugin Author Optimizing Matters

    (@optimizingmatters)

    hmm, I *might* add a warning on the settings-screen, but in the end allowing protocol-relative URL’s (just like using relative URL’s which suffer from the same shortcoming) is the choice and thus responsibility of the webmaster/ wordpress administrator. if (s)he wants the site to be able to work both in HTTP and HTTPS (which some people still do), then the flexibility of the protocol-relative URL is required.

    I might very well change my mind on this subject though 😉

    your right, the webmaster has to know what she/he is doing after all;
    you are very much welcome to change your mind… or not, it is not critical on this subject.

    Keep going and thanks for your speedy answer.

Viewing 2 replies - 1 through 2 (of 2 total)
  • The topic ‘CDN option protocol-relative’ is closed to new replies.