Skip to content

Conversation

@gkesaev
Copy link

@gkesaev gkesaev commented Sep 22, 2020

No description provided.

Copy link

@idanmel idanmel left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the pull request.
We allow http requests to our API.

Can you please change the schema back to http?

@gkesaev
Copy link
Author

gkesaev commented Oct 4, 2020

No worries.
To be clear the only reason for this pull request is http schema.
If you like I can change it so the user would have the option to choose http/s but truly I think that this is a bad idea.
One might use this library for the first time without checking exactly what the code does and use it to search for some very sensitive information over say cyber API.
What do you think?

@idanmel
Copy link

idanmel commented Oct 4, 2020

Hi Nescobar,
That's a good idea.
Maybe have HTTPS as the default, and give the user the option of using HTTP?

@gkesaev
Copy link
Author

gkesaev commented Feb 24, 2021

@idanmel I've thought about it and I think that there is no point in leaving the HTTP schema.
With the provided services your customers may search for very sensitive data, and some of them are probably doing it right now over the clear web.
I think it should be the other way around: you should help your users by enforcing them to use a more secure connection and if someone wants they'll be able to downgrade to HTTP after changing one line of code.

@gkesaev gkesaev mentioned this pull request May 2, 2021
@sonarqubecloud
Copy link

sonarqubecloud bot commented Oct 7, 2022

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
No Duplication information No Duplication information

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants