Your API Shouldn't Redirect HTTP to HTTPS
Date: 6/11/2024 · Tags: #dev, #security@jviide wrote a blog post1 about why your API shouldn't redirect HTTP to HTTPS. He is right. It's probably a bad practice to simply redirect without any other notification. Your secrets could already be leaked while you're accessing the HTTP endpoint. So, what does the author suggest to do?
- Make the failure visible to the user or caller.
- Revoke API keys and tokens send over the unencrypted connection.