[tor-bugs] #6056 [Website]: We give amazon and google a web bug on our donate page, and the amazon one is http
Tor Bug Tracker & Wiki
torproject-admin at torproject.org
Mon Jun 4 18:03:52 UTC 2012
#6056: We give amazon and google a web bug on our donate page, and the amazon one
is http
---------------------+------------------------------------------------------
Reporter: arma | Owner: phobos
Type: defect | Status: new
Priority: normal | Milestone:
Component: Website | Version:
Keywords: | Parent:
Points: | Actualpoints:
---------------------+------------------------------------------------------
Comment(by phobos):
The payments won't work without the hotlink to their sites. We spent too
long trying to figure it out. The official answer from both is that the
client needs to be served a unique identifier which ties torproject.org to
their payment system or it won't work. When you don't have the identifier,
the user is told it is an invalid cart with Amazon or an empty cart with
Google.
We had this discussion ages ago and decided since it's only one page, we
can live with the risks. Also, amazon/google/paypal should be serving
over https. I don't get a mixed-content warning and the requests all
appear to be https:// for me.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/6056#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list