Mixed content 01-28-2016, 12:16 AM
#1
So, I love that you actually give a rats ass and go with SSL but mixed content warnings is something I hate more than not having SSL available.
Ever since I started working on my own MyBB forum I've slowly been thinking about it and pretty much settled down on a method to fix it and to provide somewhat more secure environment for members.
The concept is to proxy images using the [ img ] tag through Google User Content proxy which is used by Gmail to secure images that you've received. It is free and available for public usage and pretty simple to implement into MyBB but I assume the owner around here is cautious and wants to look over it himself. A very, very bad example of usage is this code here :
Do not use the script above in any real case, it is easy to circumvent it.
I wrote it up just to test how it works, the proxy. And I recommend you do the same.
It is an easy method to fix mixed content coming from external web sites in posts.
About avatars I would assume most, if not all avatars are uploaded or using Gravatar.. Having only those two options was my solution to fix the avatars portion of a setup on MyBB using SSL without any mixed content warnings.
So, that basically is my idea.. Fix the mixed content issue on the web site using some method at least is the suggestion. The rest is just an idea of how that could be accomplished. [/size]
Ever since I started working on my own MyBB forum I've slowly been thinking about it and pretty much settled down on a method to fix it and to provide somewhat more secure environment for members.
The concept is to proxy images using the [ img ] tag through Google User Content proxy which is used by Gmail to secure images that you've received. It is free and available for public usage and pretty simple to implement into MyBB but I assume the owner around here is cautious and wants to look over it himself. A very, very bad example of usage is this code here :
PHP Code:
<?php
$prefix = 'https://images2-focus-opensocial.googleusercontent.com/gadgets/proxy?url=';
$suffix = '&container=focus&gadget=a&no_expand=1&resize_h=0&rewriteMime=image%2F*';
$pattern = '/(<img [^>]* ?src=)["\']?(https?:\/\/[^"\' ]+)["\']?([^>]+>)/ism';
// Get the image URI
if(isset($_GET['URI'])) {
if(empty($_GET['URI'])) {
echo "No image url detected";
} else {
$lol = htmlspecialchars($_GET['URI']);
echo "<img src=\"" . $prefix, $lol, $suffix . "\">";
}
} else {
echo "No image url detected.";
}
?>I wrote it up just to test how it works, the proxy. And I recommend you do the same.
It is an easy method to fix mixed content coming from external web sites in posts.
About avatars I would assume most, if not all avatars are uploaded or using Gravatar.. Having only those two options was my solution to fix the avatars portion of a setup on MyBB using SSL without any mixed content warnings.
So, that basically is my idea.. Fix the mixed content issue on the web site using some method at least is the suggestion. The rest is just an idea of how that could be accomplished. [/size]


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)












![[Image: 7ajmN5P.jpg]](https://i.imgur.com/7ajmN5P.jpg)