Vgutierrez added a comment.

  In T330906#8657917 <https://phabricator.wikimedia.org/T330906#8657917>, 
@Ennomeijers wrote:
  
  > Thanks for the replies! Advising to use HTTPS over HTTP makes sense.
  >
  > But not supporting redirection from HTTP to HTTPS will in my opinion 
introduce a fundamental problem for using Wikidata as a source for Linked Data. 
When querying Wikidata through the sparql endpoint the entities of the result 
set are all HTTP URIs. The RDF description of WD entities (accessed as 
described on https://www.wikidata.org/wiki/Wikidata:Data_access) contain many 
HTTP URIs for related entities and other resources.
  >
  > Using the HTTP as identifier for the entity is not problematic as long as 
the redirection from HTTP to HTTPS can deliver access to the data itself.
  
  IMHO that's a gap that needs to be closed  on the sparql endpoint as 
including HTTP resources from a https resource is considered insecure: 
https://developer.mozilla.org/en-US/docs/Web/Security/Mixed_content.
  
  That being said, on almost any recent browser 
<https://caniuse.com/stricttransportsecurity> traffic against wikidata.org or 
any other Wikimedia canonical domain 
<https://wikitech.wikimedia.org/wiki/HTTPS#For_the_Foundation%27s_canonical_domain_names>
 will target port 443 (HTTPS) due to HTTP Strict Transport Security, a 
mechanism that allows us to ask the browsers to contact any of our domains via 
https even if the link or the user tries to reach the site via http

TASK DETAIL
  https://phabricator.wikimedia.org/T330906

EMAIL PREFERENCES
  https://phabricator.wikimedia.org/settings/panel/emailpreferences/

To: Vgutierrez
Cc: Nikki, Vgutierrez, BBlack, Ennomeijers, Aklapper, Astuthiodit_1, KOfori, 
karapayneWMDE, joanna_borun, Invadibot, Devnull, maantietaja, Muchiri124, 
ItamarWMDE, Akuckartz, Legado_Shulgin, ReaperDawn, Nandana, Davinaclare77, 
Techguru.pc, Lahi, Gq86, GoranSMilovanovic, Hfbn0, QZanden, LawExplorer, Zppix, 
_jensen, rosalieper, Scott_WUaS, Wong128hk, Wikidata-bugs, aude, faidon, 
Mbch331, Jay8g, fgiunchedi
_______________________________________________
Wikidata-bugs mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to