HTTPS now available on L19!

Tell the community about tournaments, new go sites, software updates, etc.
Post Reply
User avatar
apetresc
Lives with ko
Posts: 256
Joined: Wed Apr 21, 2010 3:42 pm
Rank: AGA 1k
GD Posts: 1190
KGS: apetresc
IGS: apetresc
OGS: apetresc
Universal go server handle: apetresc
Location: Waterloo, Ontario (Canada)
Has thanked: 110 times
Been thanked: 146 times
Contact:

HTTPS now available on L19!

Post by apetresc »

Hey everyone! As has been requested a few times now, lifein19x19.com now supports HTTPS: https://lifein19x19.com.

What This Means
For the non-technically-inclined among us, this basically means that L19 is a little bit safer today than it was yesterday. HTTPS protects against a certain class of attacks that would theoretically allow a malicious network to intercept your L19 traffic (most importantly, your password). There's absolutely no reason to believe this kind of attack was ever used - it's just a best practice to avoid it.

How To use It
All you have to do to take advantage of this is to use https:// instead of http:// when you visit lifein19x19.com from now on, so please update your bookmarks :) Once you do, you should see that comforting green lock:
Image


In order to make 100% sure that everything is working cleanly with HTTPS, I'm going to leave the site with HTTP still enabled for the next 7 days, during which time HTTPS is optional but I highly encourage everyone to try it out and test it. After the 7 days are up, assuming no unfixed issues arise, I'm going to make HTTPS the default and all the old http:// links will simply redirect to https://. This shouldn't require any change whatsoever to your browsing patterns, just carry on as you were before!

Known Issues
  • During the beta, it will still be possible for someone on HTTP to upload an attachment to a post and embed it (through, say,
Other than that, everything should work exactly as well as it has before :) In particular, I've gone over all old
The road to wisdom? Well, it's plain, and simple to express: Err, and err, and err again; but less, and less, and less!
Image Image Image Image
User avatar
apetresc
Lives with ko
Posts: 256
Joined: Wed Apr 21, 2010 3:42 pm
Rank: AGA 1k
GD Posts: 1190
KGS: apetresc
IGS: apetresc
OGS: apetresc
Universal go server handle: apetresc
Location: Waterloo, Ontario (Canada)
Has thanked: 110 times
Been thanked: 146 times
Contact:

Re: HTTPS now available on L19!

Post by apetresc »

Since there didn't seem to be any problems reported for HTTPS, it is now the default - any requests to http://lifein19x19.com will be automatically redirected to https://lifein19x19.com!
The road to wisdom? Well, it's plain, and simple to express: Err, and err, and err again; but less, and less, and less!
Image Image Image Image
Bill Spight
Honinbo
Posts: 10905
Joined: Wed Apr 21, 2010 1:24 pm
Has thanked: 3651 times
Been thanked: 3373 times

Re: HTTPS now available on L19!

Post by Bill Spight »

I am seeing many game records in old posts that do not display. Rather annoying. :(
The Adkins Principle:
At some point, doesn't thinking have to go on?
— Winona Adkins

Visualize whirled peas.

Everything with love. Stay safe.
User avatar
apetresc
Lives with ko
Posts: 256
Joined: Wed Apr 21, 2010 3:42 pm
Rank: AGA 1k
GD Posts: 1190
KGS: apetresc
IGS: apetresc
OGS: apetresc
Universal go server handle: apetresc
Location: Waterloo, Ontario (Canada)
Has thanked: 110 times
Been thanked: 146 times
Contact:

Re: HTTPS now available on L19!

Post by apetresc »

Bill Spight wrote:I am seeing many game records in old posts that do not display. Rather annoying. :(
Oh! Can you link me an example or two? I thought I had fixed all of those instances, but I might have missed some.
The road to wisdom? Well, it's plain, and simple to express: Err, and err, and err again; but less, and less, and less!
Image Image Image Image
Uberdude
Judan
Posts: 6727
Joined: Thu Nov 24, 2011 11:35 am
Rank: UK 4 dan
GD Posts: 0
KGS: Uberdude 4d
OGS: Uberdude 7d
Location: Cambridge, UK
Has thanked: 436 times
Been thanked: 3718 times

Re: HTTPS now available on L19!

Post by Uberdude »

Perhaps the problem with embedded game records is because the download link in the sgf tag is plain http? I just made a post in which I uploaded an sgf, previewed to get the download url and then copy-pasted that into sgf tags. It was http and the game didn't load. I've just edited it to be https and it now works.
User avatar
apetresc
Lives with ko
Posts: 256
Joined: Wed Apr 21, 2010 3:42 pm
Rank: AGA 1k
GD Posts: 1190
KGS: apetresc
IGS: apetresc
OGS: apetresc
Universal go server handle: apetresc
Location: Waterloo, Ontario (Canada)
Has thanked: 110 times
Been thanked: 146 times
Contact:

Re: HTTPS now available on L19!

Post by apetresc »

Uberdude wrote:Perhaps the problem with embedded game records is because the download link in the sgf tag is plain http? I just made a post in which I uploaded an sgf, previewed to get the download url and then copy-pasted that into sgf tags. It was http and the game didn't load. I've just edited it to be https and it now works.
Yup, that's the issue I called out in the original post - and it shouldn't happen for any new posts now that it's HTTPS by default, since any links you right-click-copy should also be HTTPS. I had also fixed it for any posts made prior to last week. Have any slipped through the cracks?
The road to wisdom? Well, it's plain, and simple to express: Err, and err, and err again; but less, and less, and less!
Image Image Image Image
Bill Spight
Honinbo
Posts: 10905
Joined: Wed Apr 21, 2010 1:24 pm
Has thanked: 3651 times
Been thanked: 3373 times

Re: HTTPS now available on L19!

Post by Bill Spight »

apetresc wrote:
Bill Spight wrote:I am seeing many game records in old posts that do not display. Rather annoying. :(
Oh! Can you link me an example or two? I thought I had fixed all of those instances, but I might have missed some.
OK. :)

forum/viewtopic.php?p=127483#p127483

forum/viewtopic.php?p=208998#p208998

forum/viewtopic.php?p=219192#p219192

forum/viewtopic.php?p=215478#p215478

forum/viewtopic.php?p=207232#p207232

Surely there are more. :)
The Adkins Principle:
At some point, doesn't thinking have to go on?
— Winona Adkins

Visualize whirled peas.

Everything with love. Stay safe.
User avatar
apetresc
Lives with ko
Posts: 256
Joined: Wed Apr 21, 2010 3:42 pm
Rank: AGA 1k
GD Posts: 1190
KGS: apetresc
IGS: apetresc
OGS: apetresc
Universal go server handle: apetresc
Location: Waterloo, Ontario (Canada)
Has thanked: 110 times
Been thanked: 146 times
Contact:

Re: HTTPS now available on L19!

Post by apetresc »

Bill Spight wrote:
apetresc wrote:
Bill Spight wrote:I am seeing many game records in old posts that do not display. Rather annoying. :(
Oh! Can you link me an example or two? I thought I had fixed all of those instances, but I might have missed some.
OK. :)

forum/viewtopic.php?p=127483#p127483

forum/viewtopic.php?p=208998#p208998

forum/viewtopic.php?p=219192#p219192

forum/viewtopic.php?p=215478#p215478

forum/viewtopic.php?p=207232#p207232

Surely there are more. :)

Woah! Not sure why my regex missed them the first time :oops: ... either way, they're fixed now! Thanks for the catches :)

Like I said, these kinds of errors won't happen anymore now that HTTPS is forced (unless someone were to go out of their way to remove the 's' from the link they copied), but I guess some old ones slipped through the cracks.
The road to wisdom? Well, it's plain, and simple to express: Err, and err, and err again; but less, and less, and less!
Image Image Image Image
User avatar
apetresc
Lives with ko
Posts: 256
Joined: Wed Apr 21, 2010 3:42 pm
Rank: AGA 1k
GD Posts: 1190
KGS: apetresc
IGS: apetresc
OGS: apetresc
Universal go server handle: apetresc
Location: Waterloo, Ontario (Canada)
Has thanked: 110 times
Been thanked: 146 times
Contact:

Re: HTTPS now available on L19!

Post by apetresc »

(Actually, one thing I forgot to mention - the first link you posted was actually not caused by the HTTPS bug at all. It's just a bad link to OGS, not L19. The link itself is dead on OGS' site, so there's not much I can do about that...)
The road to wisdom? Well, it's plain, and simple to express: Err, and err, and err again; but less, and less, and less!
Image Image Image Image
Bill Spight
Honinbo
Posts: 10905
Joined: Wed Apr 21, 2010 1:24 pm
Has thanked: 3651 times
Been thanked: 3373 times

Re: HTTPS now available on L19!

Post by Bill Spight »

The Adkins Principle:
At some point, doesn't thinking have to go on?
— Winona Adkins

Visualize whirled peas.

Everything with love. Stay safe.
Kirby
Honinbo
Posts: 9553
Joined: Wed Feb 24, 2010 6:04 pm
GD Posts: 0
KGS: Kirby
Tygem: 커비라고해
Has thanked: 1583 times
Been thanked: 1707 times

Re: HTTPS now available on L19!

Post by Kirby »

I fixed/updated that one.
be immersed
Kirby
Honinbo
Posts: 9553
Joined: Wed Feb 24, 2010 6:04 pm
GD Posts: 0
KGS: Kirby
Tygem: 커비라고해
Has thanked: 1583 times
Been thanked: 1707 times

Re: HTTPS now available on L19!

Post by Kirby »

I searched the site a bit through google, and found the posts below, which also included non-https urls for L19:
viewtopic.php?p=15176&f=4#p15176
forum/viewtopic.php?p=15061&f=57#p15061
https://www.lifein19x19.com/forum/viewt ... 44#p119544
https://www.lifein19x19.com/forum/viewt ... 46#p119546
https://www.lifein19x19.com/forum/viewt ... 47#p119547
https://www.lifein19x19.com/forum/viewt ... 49#p119549
https://www.lifein19x19.com/forum/viewt ... 50#p119550
https://www.lifein19x19.com/forum/viewt ... 61#p119561
https://www.lifein19x19.com/forum/viewt ... 62#p119562
https://www.lifein19x19.com/viewtopic.p ... 64#p119564
https://www.lifein19x19.com/viewtopic.p ... 68#p119568
https://www.lifein19x19.com/viewtopic.p ... 94#p119594
https://www.lifein19x19.com/viewtopic.p ... 47#p119647
https://www.lifein19x19.com/viewtopic.p ... 52#p119652
https://www.lifein19x19.com/viewtopic.p ... 84#p120684
https://www.lifein19x19.com/viewtopic.p ... 89#p120689
https://www.lifein19x19.com/viewtopic.p ... 91#p120691
https://www.lifein19x19.com/viewtopic.p ... 63#p120963
https://www.lifein19x19.com/viewtopic.p ... 72#p121372
https://www.lifein19x19.com/viewtopic.p ... 48#p122848
https://www.lifein19x19.com/viewtopic.p ... 05#p123005
https://www.lifein19x19.com/viewtopic.p ... 25#p123225
https://www.lifein19x19.com/viewtopic.p ... 26#p123226
https://www.lifein19x19.com/viewtopic.p ... 88#p123588
https://www.lifein19x19.com/viewtopic.p ... 58#p123958
https://www.lifein19x19.com/viewtopic.p ... 61#p123961
https://www.lifein19x19.com/viewtopic.p ... 62#p123962
https://www.lifein19x19.com/viewtopic.p ... 65#p123965
https://www.lifein19x19.com/viewtopic.p ... 69#p123969
https://www.lifein19x19.com/viewtopic.p ... 00#p124300
https://www.lifein19x19.com/viewtopic.p ... 98#p124698
https://www.lifein19x19.com/viewtopic.p ... 63#p125363
https://www.lifein19x19.com/viewtopic.p ... 81#p125481
https://www.lifein19x19.com/viewtopic.p ... 31#p125831
https://www.lifein19x19.com/viewtopic.p ... 88#p126088
https://www.lifein19x19.com/viewtopic.p ... 85#p126285
https://www.lifein19x19.com/viewtopic.p ... 99#p126499


I started updating a bunch of these manually, but then realized that I could modify the bb-code definition for sgf tags. I did this for now, so even when the post includes an L19 http URL, the string is substituted.

Hopefully this addresses at least the situation with sgf tags. Let me know if you find any problems with this.
be immersed
User avatar
apetresc
Lives with ko
Posts: 256
Joined: Wed Apr 21, 2010 3:42 pm
Rank: AGA 1k
GD Posts: 1190
KGS: apetresc
IGS: apetresc
OGS: apetresc
Universal go server handle: apetresc
Location: Waterloo, Ontario (Canada)
Has thanked: 110 times
Been thanked: 146 times
Contact:

Re: HTTPS now available on L19!

Post by apetresc »

Kirby wrote:I started updating a bunch of these manually, but then realized that I could modify the bb-code definition for sgf tags. I did this for now, so even when the post includes an L19 http URL, the string is substituted.

Hopefully this addresses at least the situation with sgf tags. Let me know if you find any problems with this.
That's... an infinitely better solution than fixing it in the database :) Great catch, Kirby! I think I hadn't consciously realized that BBCode is re-rendered every time a post is viewed, not just at posting time.
The road to wisdom? Well, it's plain, and simple to express: Err, and err, and err again; but less, and less, and less!
Image Image Image Image
Post Reply