machawk1 / wail

:whale2: Web Archiving Integration Layer: One-Click User Instigated Preservation
https://matkelly.com/wail
MIT License
351 stars 35 forks source link

Initial launch of Heritrix Web interface loses credentials after certificate warning #63

Open machawk1 opened 10 years ago

machawk1 commented 10 years ago

...requiring the user to enter them. This process should be transparent. More investigation should be done to see if this is just in Safari or is present in other OS's.

Encountered in Safari (the default browser) for OS X 10.9.

machawk1 commented 9 years ago

screen shot 2015-12-01 at 7 51 11 am

machawk1 commented 8 years ago

Per https://webarchive.jira.com/wiki/display/Heritrix/Web-based+User+Interface :

if the parameter supplied to the -a -web-admin command line option is a string beginning with "@", the rest of the string is interpreted as a local file name containing the operator login and password. This adds an additional layer of protection to the admin username and password.

machawk1 commented 8 years ago

Specifying the credentials in a separate file might be better and more configurable than in-code but does not remedy the issue of Safari losing the credentials when http://lorem:ipsum@localhost:8443 is passed to it.

machawk1 commented 5 years ago

Still the case in 2019 with Safari:

Screen Shot 2019-08-09 at 4 47 30 PM

Show details > visit this website asks for confirmation to changing Certificate Trust Settings and system credentials. Adding these and hitting ok repeats the process, never advancing to the Heritrix interface.

macOS 10.14.6, Safari 12.1.2