Skip to content

Always fetch upstream content through HTTPS

Tasks

  • Consider to always fetch upstream content through HTTPS, regardless of the force_https setting. This means Onionspray can accept both HTTPS and non-HTTPS connections to onionsites, but backend connections should always go upstream through validated HTTPS connections.

Time estimation

  • Complexity: very small (0.5 day)
  • Uncertainty: low (x1.1)
  • Reference (adapted)