Support Forum

Mixed content message due to Gravatar image

RM Roger Martin
Roger Martin
Member

I’m playing with a Simple:Press install on an SSL-secured site. It looks like all resources are being pulled down securely (i.e. with the https prefix) except for one – the gravatar image when you are logged on. For example, when I log in the following image is used in the top left corner:

http://www.gravatar.com/avatar/4c801adb87c3baafdb529622b64b68e6?d=404&size=50&rating=g

Since it’s not secure (http insted of https), Chrome gives a warning about mixed content being on the page. I flushed caches, checked the forum settings and Gravatar settings and don’t see a way to change it. I even tried the Gravatar cache plugin but then a new problem develops – a 404 error occurs presumably because a routing issue is preventing the IIS server from finding the resource. (FYI, if you change the cache file to use a file extension instead of being extensionless, this problem would disappear.)

You can see the issue for yourself at https://galleryserverpro.com/forum/.

Cheers!
Roger

19 Answers

New Answer

MP Mr Papa
Mr Papa
Member

interesting… not sure why the file extension would matter… and we have quite a few users with SSL and this has not been reported… in fact, we recently did an ssl sweep due to share this issue and this did not come up…

not saying, you are not correct, just odd that its not a global things…  or perhaps its specific to IIS…

and we will have to investigate further…

RM Roger Martin
Roger Martin
Member

The file extension issue is unrelated to SSL. To avoid confusion, I split that into another thread: Gravatar cache doesn’t work well on IIS

You don’t have to take my word for it on the mixed content warning. It is easy to repro the issue by going to https://galleryserverpro.com/forum and logging in (it supports several openauth providers so you can log in with your Google, Facebook, Twitter, or LinkedIn account). Once logged in and your gravatar image is shown, look at the source and notice the image is served as HTTP while the page is served as HTTPS.

RM Roger Martin
Roger Martin
Member

Any word on this? We are still having this issue on our site. Repro steps in the earlier posts still work.

Thanks!

Roger

MP Mr Papa
Mr Papa
Member

we have not been able to reproduce yet (doesnt happen on our ssl test setup)…  and still trying to understand how a file extension would make any difference…  of course, our test site is not on IIS…  and would like to understand why/how its specific to IIS… is it just your server set up or any IIS..  unfortunately, such as small number of IIS users so hard to get data…  not a good practice to ‘fix’ something for one instance without understanding any other implications…

CA Cherie Ve Ard
Cherie Ve Ard
Member

We’ve recently moved our site to use SSL, and everything is working fine except for the forums.

They work – but the browser flags the pages as insecure because SimplePress is loading the gravatar over http instead of https.

Here is the error in Chrome:

Mixed Content: The page at ‘https://www.rvmobileinternet.com/forum/’ was loaded over HTTPS, but requested an insecure image ‘http://www.gravatar.com/avatar/73c61c17d46e45ac2cd4a00b2bba5453?d=404&size=50&rating=g’. This content should also be served over HTTPS.

Any fix coming? Do I have to disable gravatars?

Thanks,

  – Chris

PS: This has nothing to do with IIS. Our web host is Dreamhost, running Apache. SimplePress just needs to request the https:// instead of http:// image from Gravatar to fix this, I think

YS Yellow Swordfish
Yellow Swordfish
Member

I thought we had a bug ticket open on this one but it appears to have fallen through the cracks somewhere. I will open one now and we will discuss tonight and let you know after that….

MP Mr Papa
Mr Papa
Member

we might be able to fix gravatars to always use https, but a bigger question would be why isnt it auto changing it to https??? 

It does for me on my test server…  makes me wonder if the server is properly configured to use https/ssl…

MP Mr Papa
Mr Papa
Member

have opened a ticket to just go ahead and force https in next version… should be no harm there…

BW Brandon Williams
Brandon Williams
Member

I’m having this issue as well. How can this be solved?

MP Mr Papa
Mr Papa
Member

upgrade to the latest version of gravatar cache that was released earlier this morning…

if not using that plugin, you will have to wait for the next release of core plugin in about a week…

will see if I can post a manual change you can make in the meantime…

MP Mr Papa
Mr Papa
Member

in wp-content/plugins/simple-press/forum/content/sp-common-view-functions.php, find this line around line 719

                        $avatarData->url = 'http://www.gravatar.com/avatar/'.md5(strtolower($avatarData->email))."?d=404&size=$avatarData->size&rating=$grating";

and change it to

                        $avatarData->url = 'https://www.gravatar.com/avatar/'.md5(strtolower($avatarData->email))."?d=404&size=$avatarData->size&rating=$grating";
BW Brandon Williams
Brandon Williams
Member

Ok, I’m not a developer, so if you don’t mind telling me exactly where to go to locate this? I’m assuming it’s in the Editor maybe? I can add the code, but don’t want to spend 30 minutes looking for where to find this 🙂 Thanks.

MP Mr Papa
Mr Papa
Member

you will have to pull up the file I specified in an editor… I gave you the path to the file, so not sure how to be more specific there…

normally you would pull it up via ftp (edit and save back to server)… you could also edit in a file manager type program your hosting company may provide via control panel such as cpanel…