Forums / General Questions / HTTPS not showing information....

HTTPS not showing information....

Views: 3,183

Results 21 to 29 of 29
9 Mar 2015, 7:47 PM
#21
micro007 avatar

micro007

New Zenner

Join Date:
Jan 2008
Posts:
43
Plugin Contributions:
0

HTTPS not showing information....

RodG:

I don't wish to confuse you, but there are actually three 'types' of links that can be used.

  1. Absolute links.
    Examples
    http://somesite.com
    http://somesite.com/some/path/file.html
    https://somesite.com
    https://somesite.com/some/path/file.php
    http://yoursite.com
    http://yoursite.com/some/path/file.html
    https://yoursite.com
    https://yoursite.com/some/path/file.php

  2. Relative links.
    Examples
    index.php
    /some/path/file.php
    /some/other/path/file.html

3) Protocol-agnostic links
Examples
//notMySite.com
//YetAnotherSite.com/some/path/file.html

Absolute links are 'robust' but not 'portable' . They can be/are used primarily to force the use of a specific protocol (http, https, ftp. file, etc). Although these links can point to your own domain name this isn't recommended as it causes an additional DNS lookup. It can also make things more complicated than they need be if the site needs to be migrated to a different domain.

Relative links can only be used to link to resources on your own site. In almost all cases these are the best ones to use where and when possible. The code is easily portable and there are no issues with http vs https.

Protocol-agnostic links are somewhat of a hybrid of the Absolute and Relative links. They are used primarily for offsite linking where the protocol either can't be explicitly set or where it isn't practical to do so.

ZenCart makes extensive use of dynamically generated Absolute Links as this enables HTTP/HTTPS to be explicitly given (essential for directing the client between SSL enabled and No SSL parts of the site).
Almost all 'user defined' links (eg, internal EZ-Page links, most links in the template files, and the links in most add-ons that don't need to connect to offsite/external servers will/should be using Relative links.

Protocol-agnostic links should (at least in my opinion) only be used as a last resort in place of Absolute links to external servers if the protocol can't be dynamically assigned.

So, to answer you question as to whether you should go through the site and change all links to be protocol-agnostic, the answer is no. Only change the ones that are actually needed.

Cheers
RodG

   

... and this is why you're totally Zenned, great explanation of the three, I'm 50 and have been doing website design off and on since 1990.... I always learn something new, everyday dude!

10 Mar 2015, 9:53 AM
#22
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: HTTPS not showing information....

micro007:

... and this is why you're totally Zenned, great explanation of the three, I'm 50 and have been doing website design off and on since 1990.... I always learn something new, everyday dude!

Thanks. I appreciate the feedback. More often than not, people don't seem to like having things explained, and would rather have a simple yes, no, or 'here's what you need to do' kind of response. :-(

I try to learn one new thing every day myself, and the teacher/trainer in me compels me to share my learnings with others (whether they like it or not) <g>

Anyway, thanks again, it's good to know my ravings aren't always wasted. :-)

Cheers
RodG

NOTE: We are sorry that Rod is no longer with us.
We are grateful for all his contributions to the Zen Cart community.

Ozpost - The Ultimate Shipping module for Australian Merchants. Click these links for its Homepage, or Download from Zen-Cart.com.

10 Mar 2015, 10:25 AM
#23
mc12345678 avatar

mc12345678

Totally Zenned

Join Date:
Jul 2012
Posts:
16,908
Plugin Contributions:
2

Re: HTTPS not showing information....

RodG:

More often than not, people don't seem to like having things explained, and would rather have a simple yes, no, or 'here's what you need to do' kind of response. :-(

Here, here. Though I know what I write is not always as well organized, usually it is those not directly involved that have issue... Maybe it's also because I'm not a qualified/certified trainer. :)

That post was what I was getting at earlier, but in parts. I think the full explanation in a single post was definitely needed.

ZC Installation/Maintenance Support <- Site
Contribution for contributions welcome...

11 Mar 2015, 5:07 PM
#24
micro007 avatar

micro007

New Zenner

Join Date:
Jan 2008
Posts:
43
Plugin Contributions:
0

Re: HTTPS not showing information....

mc12345678:

Here, here. Though I know what I write is not always as well organized, usually it is those not directly involved that have issue... Maybe it's also because I'm not a qualified/certified trainer. :)

That post was what I was getting at earlier, but in parts. I think the full explanation in a single post was definitely needed.

Yes, I see that now. Thanks as well, I'm digging into the code today of the template I used assuming that this is where the issue lies. I hope its not in the zencart it's self.... will let you know.

11 Mar 2015, 5:08 PM
#25
micro007 avatar

micro007

New Zenner

Join Date:
Jan 2008
Posts:
43
Plugin Contributions:
0

Re: HTTPS not showing information....

How will I know which ones need to be changed?

So, to answer you question as to whether you should go through the site and change all links to be protocol-agnostic, the answer is no. Only change the ones that are actually needed.

Cheers
RodG

11 Mar 2015, 9:23 PM
#26
mc12345678 avatar

mc12345678

Totally Zenned

Join Date:
Jul 2012
Posts:
16,908
Plugin Contributions:
2

Re: HTTPS not showing information....

micro007:

How will I know which ones need to be changed?

Generally speaking (just to get you started), if the address is pointing to your local server, then use relative links. If the address is off-site, then priority would be absolute links followed by agnostic links based on a post that RodG recently made elsewhere... Ie. somewhat addressing a concern you expressed earlier... What if a site doesn't support https and your site is currently serving the page as secure. If the site does not offer a secure link, then either you will have http: for their site and potential message of mixed content, or you can program to not show the link/section of associated text so that such mixed content won't exist.

Placing the agnostic link as a "last" option is easy, but also is depending on the user's browser to properly prefix the uri. All major browsers currently support this option; however, there may be other page errors that might affect the result.

One thing easy to do is to use the developer's toolkit (DTK) found in the admin panel->Tools->developers toolkit.

From there you can search for http: in the lower left hand corner. This will identify all links (and associated code) that use http:... But, not EVERY such reference needs to be rewritten as above. For example an html click tag, <a href="http:... Does not need to be reworked as that is a clickable link that will go to a new/different location. Typical items to modify are those that begin with src=. There are a few others that affect the mixed response; however, I do not recall them all at this point and would suggest performing an internet search for such/similar information.

ZC Installation/Maintenance Support <- Site
Contribution for contributions welcome...

11 Mar 2015, 10:07 PM
#27
micro007 avatar

micro007

New Zenner

Join Date:
Jan 2008
Posts:
43
Plugin Contributions:
0

Re: HTTPS not showing information....

micro007:

How will I know which ones need to be changed?

This is what I get using the chrome tools but I'm not quit sure what or how to find where this is inside the template....

Mixed Content: The page at 'https://tackleandrod.com/index.php?main_page=index' was loaded over a secure connection, but contains a form which targets an insecure endpoint 'http://tackleandrod.com/index.php?main_page=advanced_search_result'. This endpoint should be made available over a secure connection.
index.php:786

Mixed Content: The page at 'https://tackleandrod.com/index.php?main_page=index' was loaded over a secure connection, but contains a form which targets an insecure endpoint 'http://tackleandrod.com/index.php?main_page=advanced_search_result'. This endpoint should be made available over a secure connection.
index.php:1044

Mixed Content: The page at 'https://tackleandrod.com/index.php?main_page=index' was loaded over a secure connection, but contains a form which targets an insecure endpoint 'http://elegantdesignhub.us3.list-manage.com/subscribe/post?u=aec0ecc511b9e4dec6925a777&id=3f25e396e2'. This endpoint should be made available over a secure connection.

'https://tackleandrod.com/includes/templates/edify/images/bgpatterns/wrapper.png' Failed to load resource: the server responded with a status of 404 (Not Found)

these are the errors.... how do I find where they're located in the coding?

12 Mar 2015, 6:02 PM
#28
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: HTTPS not showing information....

micro007:

these are the errors.... how do I find where they're located in the coding?

It looks like they are originating from the 'Information' links in the page footer, so I'd be checking the
/includes/templates/YOUR_TEMPLATE/common/tpl_footer.php and
/includes/modules/YOUR_TEMPLATE/footer.php files.

It is also possible that the URL's aren't in either of these files, but are in a file that is loaded by one of them.

That's about all I can tell you.

Cheers
RodG

NOTE: We are sorry that Rod is no longer with us.
We are grateful for all his contributions to the Zen Cart community.

Ozpost - The Ultimate Shipping module for Australian Merchants. Click these links for its Homepage, or Download from Zen-Cart.com.

13 Mar 2015, 4:11 AM
#29
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: HTTPS not showing information....

It appears to only be Chrome who says the page is insecure in these cases. Chrome is doing it because Google is a bit over-exuberant.

micro007:

Mixed Content: The page at 'https://tackleandrod.com/index.php?main_page=index' was loaded over a secure connection, but contains a form which targets an insecure endpoint 'http://tackleandrod.com/index.php?main_page=advanced_search_result'. This endpoint should be made available over a secure connection.
index.php:786

Mixed Content: The page at 'https://tackleandrod.com/index.php?main_page=index' was loaded over a secure connection, but contains a form which targets an insecure endpoint 'http://tackleandrod.com/index.php?main_page=advanced_search_result'. This endpoint should be made available over a secure connection.
index.php:1044
Whoever built your custom template appears to have changed the original code that Zen Cart uses for building on-site forms. They specifically made the URL be http, instead of letting it be dynamically built as https if the page is in https mode.
For example, the $request_type variable here is what dynamically allows it to select https when on https pages:```
$content .= zen_draw_form('quick_find', zen_href_link(FILENAME_ADVANCED_SEARCH_RESULT, '', $request_type, false), 'get');


I also note that you're using a very obsolete 2010 version of jQuery on the top your page, and then loading another one at the bottom. That slows down your site needlessly.


> **micro007:**
>
> Mixed Content: The page at 'https://tackleandrod.com/index.php?main_page=index' was loaded over a secure connection, but contains a form which targets an insecure endpoint 'http://elegantdesignhub.us3.list-manage.com/subscribe/post?u=aec0ecc511b9e4dec6925a777&id=3f25e396e2'. This endpoint should be made available over a secure connection.You'll have to change that link to be https yourself. 

> **micro007:**
>
> 'https://tackleandrod.com/includes/templates/edify/images/bgpatterns/wrapper.png' Failed to load resource: the server responded with a status of 404 (Not Found)
That means your template file HTML or one of your zillion CSS files is trying to load that particular image file, but it's not present on your server. 

> **micro007:**
>
> these are the errors.... how do I find where they're located in the coding?
The fast way to find out which specific file to edit is by using the Developers Toolkit in your Admin:
<http://www.zen-cart.com/content.php?80-how-do-i-find-out-what-files-to-edit>
<http://www.zen-cart.com/content.php?81-how-do-i-use-the-developers-toolkit>

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.