struts-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Stefaan Dutry (JIRA)" <>
Subject [jira] [Commented] (WW-4774) Upgrding Struts 2.3.1 to - Redirect issues HTTPS to HTTP
Date Sun, 26 Mar 2017 20:40:41 GMT


Stefaan Dutry commented on WW-4774:

What i've found so far:

*Is this issue caused by struts?*
No, it's not exactly caused by struts. The problem is caused by the fact that the {{sendRedirect}}
method from {{HttpServletResponse}} doesn't take https offloading into account.
*Can this issue be prevented by a change inside struts?*
It probably can be fixed by a change in struts.
*Can this issue be fixed on your side?*
Unfortunately i don't know the capabilities of {{ELB}}. Chances are that it's powerful enough
to do this. It would require to change the {{Location}} response header when there is one.
This is not the correct location for this fix.
*How is this working with version {{2.3.1}}?*
No idea, i don't see any notable change concerning how the redirect is performed.

Currently i'm still looking into finding a fix for this.

> Upgrding Struts 2.3.1 to - Redirect issues  HTTPS to HTTP
> ------------------------------------------------------------------
>                 Key: WW-4774
>                 URL:
>             Project: Struts 2
>          Issue Type: Bug
>    Affects Versions: 2.5.10
>            Reporter: upendar
>            Priority: Critical
>             Fix For:
> We are upgrading Struts2 from 2.3.1 to ; redirect  making https:// to http://
. The following errors in chrome and IE are seen while redirecting  from the popup to main
> redirecting  popup (create user) --- main window (viewdashboard)  - the URL shows https://
to http://
> We are blocked completely due to this issue and need support ASAP. We also reviewed the
apache server configurations and looks good. Please share the fix in detail.
> Error Issue in chrome :
> Mixed Content: The page at 'https://XXXXX/XX/XX/viewdashboard?clear&Id=1&uar=44'
was loaded over HTTPS, but requested an insecure XMLHttpRequest endpoint 'http://XXX/XX/XX/viewdashboard?uar=44&Id=1'.
This request has been blocked; the content must be served over HTTPS.
> Issue in IE
> SEC7127: Redirect was blocked for CORS request.
> File: account
> SCRIPT7002: XMLHttpRequest: Network Error 0x2ef1, Could not complete the operation due
to error 00002ef1.

This message was sent by Atlassian JIRA

View raw message