Docs on enforcing HTTPS and avoiding mixed content #33017
Conversation
|
I dig it! While it is outside the scope of the docs, maybe we can at least refer folks to Cloudflare or something as a starting point? Do they have a getting started guide we could link? |
|
Thanks @mdo! Regarding a getting started guide, the thing is the range of potential hosts is so large that there wasn't a getting started guide that I felt good about referring to with confidence that it would cover a meaningful subset of users. If they're using GitHub Pages or Netlify they have totally different needs than Wordpress and different than AWS and so on. If anyone else has a reference they like I can link it but I think overall users will have to find their own for whatever host they're using, and that's ok! This is my first PR with Bootstrap, what is the process of getting it merged now that it's approved? |
|
I think further implementation details are outside of the scope of the guide. I mean, there are thousands of different services and software stacks. I'd say we can merge this as is and expand it later. |

Formed in 2009, the Archive Team (not to be confused with the archive.org Archive-It Team) is a rogue archivist collective dedicated to saving copies of rapidly dying or deleted websites for the sake of history and digital heritage. The group is 100% composed of volunteers and interested parties, and has expanded into a large amount of related projects for saving online and digital history.

The live documentation requested that someone fill in the section on "Always use https"
This PR includes a short reference on why to use HTTPS for all sites.
It also includes a more relevant warning about mixed active content.
Both paragraphs link to authoritative, neutral third-party sources.