106
you are viewing a single comment's thread
view the rest of the comments
[-] v9CYKjLeia10dZpz88iU@programming.dev 13 points 1 month ago* (last edited 1 month ago)

I disagree.

You shouldn't serve anything over http. (The article argues that there's risk of leaking user data) Whatever you're using for a webserver should always catch it. A 301/308 redirect is also cached by browsers, so if the mistake is made again, the browser will correct it itself.

If you make it fail, you're just going to result in user confusion. Did they visit the right website? Is their internet down? etc.

[-] vithigar@lemmy.ca 47 points 1 month ago* (last edited 1 month ago)

This article isn't about browsers or websites, and even acknowledges in the opening that it makes sense as a usability tradeoff in that context.

I clearly didn't read it. It makes sense, if users aren't visiting the API then it really doesn't matter that it's not redirected on insecure connections.

[-] pinchcramp@lemmy.dbzer0.com 10 points 1 month ago* (last edited 1 month ago)

I clearly didn’t read it.

I love the honesty. It's really refreshing to see someone take accountability instead of becoming defensive.

load more comments (1 replies)
this post was submitted on 29 May 2024
106 points (96.5% liked)

Programming

16210 readers
26 users here now

Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!

Cross posting is strongly encouraged in the instance. If you feel your post or another person's post makes sense in another community cross post into it.

Hope you enjoy the instance!

Rules

Rules

  • Follow the programming.dev instance rules
  • Keep content related to programming in some way
  • If you're posting long videos try to add in some form of tldr for those who don't want to watch videos

Wormhole

Follow the wormhole through a path of communities !webdev@programming.dev



founded 1 year ago
MODERATORS