testing, please ignore

What's Hot
The images should display (maybe).


0reaction image LOL 1reaction image Wow! 0reaction image Wisdom

Comments

  • NiteflyNitefly Frets: 4916
    That's a wow from me, @Tannin - looks like a kestrel, but knowing you're in Tasmania I guess it's something else?

    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • TanninTannin Frets: 5431
    Cheers @Nitefly. Yes, it is indeed a kestrel, but taken in Western Victoria, about 700 kilometres north-west of here. This one is a Nankeen Kestrel, a species both widespread and common in most parts of Australia, New Guinea, and islands nearby. 

    The main thing is that you can see the picture, which means I have my web server configuration right. :)

    0reaction image LOL 0reaction image Wow! 1reaction image Wisdom
  • prowlaprowla Frets: 4919
    Ignored...
    (...even though the box says "Sorry, you have a browser configuration error.)
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • TanninTannin Frets: 5431
    Thankyou Prowla. Do you have aggressive "security" settings on your browser or anti-virus program? 

    (That error message is supposed to appear when people  try to access the picture from an unauthorised source, as demonstrated by the lack of an appropriate referrer in the requesting HTTP header (e.g., thefretboard.co.uk). It also appears when the user has excessive browser "security" settings. Typically these come about without the user's knowledge via badly-written anti-virus programs. Norton used to do it, for example, but I believe that was fixed years ago. If it is appearing on lots of people's screens, then I need to look at the other end. Some time back my provider added HTTPS functionality without bothering to tell me first. That caused some issues like the one above. I believe I have them sorted, but I'm testing to be sure.)


    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • droflufdrofluf Frets: 3691
    I’m seeing the same as prowla, using an iPad with default settings
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • TanninTannin Frets: 5431
    Ahh, thankyou Drofluf. I can't duplicate the issue on any of my systems, so now I'm stuck. :(
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • droflufdrofluf Frets: 3691
    Tannin said:
    Ahh, thankyou Drofluf. I can't duplicate the issue on any of my systems, so now I'm stuck. :(
    Also tried on a new Mac - out of the box setup. I also get the same message if I try to browse directly to the image. But, I can see the image on my work laptop that's very locked down/protected.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • TanninTannin Frets: 5431
    Thanks mate. I think I've worked out the problem now. Alas, if I'm right, I can't fix it at my end.

    Browsing directly to the image should fail. The normal way to handle image read permissions on a website is to allow free access to any browser with the correct referrer. So the server at example.net would hand out the picture at example.net/myimage.jpg to any browser that requests it with the referrer "example.net". Everything works as expected. However, when some scumbag tries to steal the image and embed it in his page at scumbags.net, the example.net webserver refuses access, usually with an error message or an alternative picture (like the one you are seeing in this thread). This too is desired behaviour. 

    What if you (the webmaster) want to allow embedding of an image on another site (e.g., The Fretboard)?  You provide the web server with an exceptions list. This, of course, I have done - thefretboard.co.uk is whitelisted on my webserver.

    Unfortunately, if my reading of the server logs is correct, the Fretboard web server is stripping the referrer tag out of the HTTP header it sends to my image hosting site. My server, very properly, says "this could be any random scumbag trying to access my files" and refuses access. 

    I'll return to this issue and double check my assumptions a bit later, but that is what seems to be happening. 
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • RolandRoland Frets: 8704
    I tried going directly to the image using http://tannin.net.au/upload/07/070902-104618-5fac.jpg but got the same browser configuration error message. However http://tannin.net.au does get me to your website from which I can find and view the image.
    Tree recycler, and guitarist with  https://www.undercoversband.com/.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • I was taught not to trust the http referrer for anything important as it can so easily be removed/spoofed.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • TanninTannin Frets: 5431
    edited December 2021
    Thanks Roland. That is correct and as it should be for a bare image link. The problem (so far as I can see) is that the Fretboard server is stripping the referrer from the link. I have no idea why oit would be set to do that - it makes no sense. Here is an example entry from the server logs: 
    2.29.84.xxx
    12/8/21, 4:22 PM
    683
    Mozilla/5.0 (iPhone; CPU iPhone OS 15_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.1 Mobile/15E148 Safari/604.1



    Note the missing referrer. Compare with a normal entry, which the referrer intact:

    110.147.203.xxx
    12/8/21, 9:52 PM
    199956
    Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:91.0) Gecko/20100101 Firefox/91.0

    Cheer4s Idiotwind. Of course it can be spoofed. However, in the real world any leakage from spoofing is trivially small and  this can in practice be ignored.  The alternative is leaving yourself without any hotlink protection, and that is unacceptable. It only takes one scumbag on a very popular site hotlinking your stuff to blow your bandwidth out of the water. You are left to get through the rest of the month with all your sites down and no email either. 
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • MellishMellish Frets: 945
    Same browser configuration here. I'm on mobile with android. I can mostly see images on the forum, though :) 
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • MellishMellish Frets: 945
    :+1:
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
Sign In or Register to comment.