Comments (21)
Just a bump, as I just ran into this... just noting that schemastore.org providing TLS should not be framed as not holding secrets (as is mentioned in #12 (comment)), but rather that the communication between the client and server should not be open to third-party manipulation or pervasive monitoring (which TLS protects from).
Perhaps Let's Encrypt could be used to provide TLS support for schemastore?
from schemastore.
it's because it's hosted at the same location as another site. The certificate doesn't apply to schemastore.org and therefore gives the error. HTTPS is currently not supported on schemastore.org since no secrets are stored there
from schemastore.
It's on the backlog to provide HTTPS support for the site.
from schemastore.
@styfle Actually, you're seeing the old default cert. Just wait for the dns to propagate fully.
from schemastore.
Thank you for your response.
Unfortunately, when my app is running on https server, when I try to
access (via ajax) I get
"was loaded over HTTPS, but requested an insecure
XMLHttpRequest endpoint
'http://schemastore.org/api/json/catalog.json'
http://schemastore.org/api/json/catalog.json%27. This request has been
blocked; the content must be served over HTTPS."
Trying https gave me the error initially mentioned.
Regards,
Mark
On 4/9/2015 4:01 PM, Mads Kristensen wrote:
it's because it's hosted at the same location as another site. The
certificate doesn't apply to schemastore.org and therefore gives the
error. HTTPS is currently not supported on schemastore.org since no
secrets are stored there—
Reply to this email directly or view it on GitHub
#12 (comment).
from schemastore.
Every azure website has https support on *.azurewebsites.net so you can use https://schemastore.azurewebsites.net for https support until it's enables on the schemastore.org domain.
from schemastore.
I see https://schemastore.azurewebsites.net/api/json/catalog.json as the catalog.
Of course since it's a copy, all of the urls in the catalog point to http://json.schemastore.org/.
However, I am unable to find corresponding items on https://schemastore.azurewebsites.net/
e.g., https://schemastore.azurewebsites.net/bower
yields "The resource you are looking for has been removed, had its name changed, or is temporarily unavailable."
https://schemastore.azurewebsites.net/json/bower
directs to the main page.
Is there a different https url pattern to use?
from schemastore.
There is no official https support yet. You'll have to rewrite the urls yourself to use the azurewebsites.net domain for https.
from schemastore.
Thank you for your response -
I understand that I'd have to rewrite the urls from the catalog, but I don't know what to rewrite them to. I haven't been able to locate them on the the azurewebsites.net domain.
So,
http://schemastore.org/api/json/catalog.json
matches to
https://schemastore.azurewebsites.net/api/json/catalog.json
and
http://schemastore.org/json/
matches to
https://schemastore.azurewebsites.net/json/
But what does, for example,
http://json.schemastore.org/bower
match to?
from schemastore.
https://schemastore.azurewebsites.net/schemas/json/bower.json
from schemastore.
Thanks!
from schemastore.
See this: https://docs.microsoft.com/azure/app-service/app-service-web-tutorial-custom-ssl
from schemastore.
This is still not working for me: https://schemastore.org/json/
This server could not prove that it is schemastore.org; its security certificate is from *.azurewebsites.net. This may be caused by a misconfiguration or an attacker intercepting your connection.
from schemastore.
you should have been redirected to https://www.schemastore.org which works. So does https://json.schemastore.org for the individual schemas
from schemastore.
@madskristensen Indeed, these work:
But searching for "schemastore" results in https://schemastore.org/json/ as the first hit and this does not work:
- https://www.google.com/search?q=schemastore
- https://www.bing.com/search?q=schemastore
- https://schemastore.org/json/
from schemastore.
Once search engines re-index, they will update to point to https://www.schemastore.org. It won't take long
from schemastore.
https://json.schemastore.org/json/ now leads to an error page: "The resource you are looking for has been removed, had its name changed, or is temporarily unavailable."
from schemastore.
@MasterOdin That’s because the json.schemastore.org
subdomain only serves the JSON schema files.
@madskristensen To do that, you’ll need schemastore.org
to serve a correct certificate and respond with a redirect to www.schemastore.org
.
from schemastore.
@ExE-Boss @MasterOdin I only have cert support on subdomains. Btw, http://json.schemastore.org/json results in a 404. There's nothing there. However, http://schemastore.org/json/ redirects correctly to https://www.schemastore.org/json/
from schemastore.
http://schemastore.org redirects to https://schemastore.org
from schemastore.
which redirects to https://www.schemastore.org. You may need to clear your browser data. Use a HTTP header checker tool like this one https://hackertarget.com/http-header-check/
from schemastore.
Related Issues (20)
- Hugo `markup.tableOfContents.endLevel` reject valid values
- Wrong name for schema file: markdown-lint-check.json should be markdown-link-check.json
- Property IPAllowList middlware is not allowed in Traefik v2 static conf according to https://json.schemastore.org/traefik-v2-file-provider.json HOT 1
- Website is down HOT 21
- Allow providing an identifying JSON Path expression in addition to fileMatch? HOT 1
- Typo in catalog for `rustfmt` description
- Missing @ prefixes for eslint-plugins rules HOT 1
- Not Found StrmPrivacy NOX Framework (Service) HOT 1
- All properties for typescript-eslint are marked as not allowed HOT 4
- Google Cloud Build JSON schema's `serviceAccount` field pattern too restrictive HOT 3
- Failing to parse valid cargo-make toml HOT 1
- Hatch schema fails to recognize `env` HOT 2
- Helmfile mislabeling properties as required when using `inherit` HOT 3
- ESLintrc Schema: 'Incorrect Type. Expected "object"' Error When Specifying the @typescript-eslint/consistent-indexed-object-style Rule With a String Option
- Jekyll Schema missing permalink strings for pages HOT 3
- pyproject.toml [project] section with no version gives `is not valid under any of the schemas listed in the 'oneOf' keyword` HOT 1
- Some issue about all types of permalink in jekyll config HOT 1
- Incorrect definition for @typescript-eslint/consistent-type-assertions HOT 1
- Update clangd config file schema with new config options in clangd 18 HOT 2
- `tsconfig` schema: disallow additional properties?
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from schemastore.