Login Register






Mixed content filter_list
Author
Message
Mixed content #1
So, I love that you actually give a rats ass and go with SSL but mixed content warnings is something I hate more than not having SSL available.

Ever since I started working on my own MyBB forum I've slowly been thinking about it and pretty much settled down on a method to fix it and to provide somewhat more secure environment for members.

The concept is to proxy images using the [ img ] tag through Google User Content proxy which is used by Gmail to secure images that you've received. It is free and available for public usage and pretty simple to implement into MyBB but I assume the owner around here is cautious and wants to look over it himself. A very, very bad example of usage is this code here :
PHP Code:
<?php $prefix = 'https://images2-focus-opensocial.googleusercontent.com/gadgets/proxy?url='; $suffix = '&container=focus&gadget=a&no_expand=1&resize_h=0&rewriteMime=image%2F*'; $pattern = '/(<img [^>]* ?src=)["\']?(https?:\/\/[^"\' ]+)["\']?([^>]+>)/ism'; // Get the image URI if(isset($_GET['URI'])) { if(empty($_GET['URI'])) { echo "No image url detected"; } else { $lol = htmlspecialchars($_GET['URI']); echo "<img src=\"" . $prefix, $lol, $suffix . "\">"; } } else { echo "No image url detected."; } ?>
Do not use the script above in any real case, it is easy to circumvent it.

I wrote it up just to test how it works, the proxy. And I recommend you do the same.
It is an easy method to fix mixed content coming from external web sites in posts.

About avatars I would assume most, if not all avatars are uploaded or using Gravatar.. Having only those two options was my solution to fix the avatars portion of a setup on MyBB using SSL without any mixed content warnings.

So, that basically is my idea.. Fix the mixed content issue on the web site using some method at least is the suggestion. The rest is just an idea of how that could be accomplished. [/size]


RE: Mixed content #2
I agree with this. Maybe not this, though.
Quote:using Gravatar.


RE: Mixed content #3
This wouldn't fix signature/thread images, unless I misunderstood. I agree mixed content sucks, though.
[Image: 7ajmN5P.jpg]

Telegram: Oni_SL (Link)


RE: Mixed content #4
(02-22-2016, 01:14 AM)Oni Wrote: This wouldn't fix signature/thread images, unless I misunderstood. I agree mixed content sucks, though.

I think he is referencing this - http://i.imgur.com/iVKn4MY.png - which is caused mainly by images.


RE: Mixed content #5
(02-22-2016, 01:19 AM)primitiv Wrote: I think he is referencing this - http://i.imgur.com/iVKn4MY.png - which is caused mainly by images.

From my understanding this isn't possible to add, without modifying core files. Which, I tend to avoid. Keep in mind there are multiple images that could be considered mixed content (avatar, signature, images used in threads).
[Image: 7ajmN5P.jpg]

Telegram: Oni_SL (Link)


RE: Mixed content #6
(02-22-2016, 01:14 AM)Oni Wrote: This wouldn't fix signature/thread images, unless I misunderstood. I agree mixed content sucks, though.

Yes, this would exactly fix images in threads and signatures. That is the purpose of this, the image would then be posted to us, the users through Google user-content proxy, same as with images on Gmail and other services on google.

(02-22-2016, 07:35 PM)Oni Wrote: From my understanding this isn't possible to add, without modifying core files. Which, I tend to avoid. Keep in mind there are multiple images that could be considered mixed content (avatar, signature, images used in threads).

Images are near always the reason behind mixed content, sometimes it is the fault of using http for jquery but that is much more rare than images.

But, yes, you are right, this isn't possible without modifying core files however it isn't much that you would need to modify, it is literally two lines inside class_parser.php and very simple to implement if you don't care about encoding the image link. That would take care of images inside threads as well user submitted images on the forum.

Administrators control over avatars sucks in MyBB, you don't have the ability to forbid external link as avatar and so on. This is my current problem in fixing the avatars problem for SSL. Gravatar support on MyBB is terrible and I don't like it as it is. It shouldn't be that it takes the email you submit but the email you already have on your account. But Gravatar is the perfect solution with the option to upload avatars and remove external avatars aside from gravatar completely out. Both gives user reasonable space to choose how he wants his avatar to be submitted instead of forcing gravatar.

But if you have a very strict policy on not modifying core files which I do understand it might be possible to create a plugin to take care of the avatar problem and include a custom BB code for images. I think that is possible, but not perfectly sure.

(02-22-2016, 01:13 AM)primitiv Wrote: I agree with this. Maybe not this, though.


Only having two options for avatars would be the best solution, thus; Gravatar and upload. Gravatar already provides SSL for images which can be used and then you're site would do to. Then disallow external avatars aside from Gravatar. However; like mentioned before, Gravatar support in MyBB sucks and is done terribly. Might be able to do that better with a plugin.


tl;dr
This fixes images in signatures and threads with two modifications to core files. Small price to pay in my opinion.
Avatars would require some more modification, possibly just through templates but I've not inspected that much.

EDIT:
Avatars can be fixed in postbit_avatars & members_avatars in the members templates. But that would mean all images, gravatar, from there and other sites are proxied through google. Still better as it has no mixed user-content issues then.

EDIT 2:
There is one problem with this method though, right click and view image would result in you getting a p.txt file to download (which is the image). The proxy is intended on proxying everything which is why we need to supply the mime type in the url for the image to be embedded on the site. Could craft up some javascript to fix it, right click view would return the actual link instead. Should work and possible in theory.

@Oni
if you want to see how it works on my testing site, then find my IP address and view it. It should be open and you not requiring a registration except if you want to view profiles.

My last edit:
It is simple to fix the issue with p.txt with a small set of jquery lines. Easy, so if you want to clean up any little piece of mixed content, there is your solution.

EDIT:
FML, It seems like as soon as the jquery has happened, it complains about mixed content. hmmm... I need more complete solution for this. Maybe I should create my own menu for the right click. But as said, this is perfectly possible to get rid of all mixed content warnings and the content in general.