Hi,

In addition to HTTP the Google SVN repository plain viewer is also served 
over HTTPS. There exists a bug where https:// URIs to directories missing 
the trailing slash are redirected to a HTTP destination rather than a HTTPS 
destination.

For example:

https://postscriptbarcode.googlecode.com/svn/trunk

incorrectly redirects to:

http://postscriptbarcode.googlecode.com/svn/trunk/

rather than the proper destination:

https://postscriptbarcode.googlecode.com/svn/trunk/

This makes it trivial to slip out of the secure viewer.


All the best,

Terry

-- 
You received this message because you are subscribed to the Google Groups 
"Project Hosting on Google Code" group.
To view this discussion on the web visit 
https://groups.google.com/d/msg/google-code-hosting/-/ok1zuxF_XX8J.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/google-code-hosting?hl=en.

Reply via email to