Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Hosted webrepl can't work due to HSTS #65

Open
ulope opened this issue Aug 13, 2021 · 1 comment
Open

Hosted webrepl can't work due to HSTS #65

ulope opened this issue Aug 13, 2021 · 1 comment

Comments

@ulope
Copy link

ulope commented Aug 13, 2021

The server serving micropython.org is configured to send a HSTS header. This means all connections are forcibly upgraded to TLS (which in general is a good thing).

However the webrepl doesn't work over HTTPS (#15), therefore the hosted webrepl isn't usable for anyone.

Since the HSTS header doesn't set includeSubdomains it should be possible (depending on the hosting setup) to host the webrepl at e.g. webrepl.micropython.org without HTTPS.

@ma261065
Copy link
Sponsor

I'm surprised that after three years this hasn't been changed. Is there a reason that the hosted webrepl can't be configured to not send the HSTS header?

As mentioned by @ulope the hosted version is useless - no one can make use of it, as every modern browser will redirect to https.

I mean, our glorious weather service manages to do it...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants