4 ms·
super nifty and really useful, does it require https ?
by adalyz 10y ago
super nifty and really useful, does it require https ?
- shortstuffsushi 10y agoWhy would it require HTTPS? This is a javascript library that allows you to hook into a native browser function (showing desktop notifications). There are no web services involved.
- ludamad 10y agoPresumably grandparent post was paranoid that http websites have some lower status in terms of being able to send notifications. Not a likely scenario, but not an entirely unreasonable question.
- Nullabillity 10y agoThe browser push APIs do require HTTPS, since browsers refuse to install service workers otherwise (which is required for them to function...). That said, the demo is hosted over plain HTTP, and seems to work for me (Chrome 50, Linux).
- shortstuffsushi 10y agoThese are not actual "push" notifications, they are desktop notifications. Different functionality, and no service workers.
- adalyz 10y agohttps://developers.google.com/web/updates/2015/03/push-notifications-on-the-open-web?hl=en https://developers.google.com/web/updates/2015/03/push-notif... Why does this require HTTPS? How do I work around this during development? Service workers require secure origins to ensure that the service worker script is from the intended origin and hasn’t come about from a man-in-the-middle attack. Currently, that means using HTTPS on live sites, though localhost will work during development.
- shortstuffsushi 10y agoSo, I think there is some misunderstanding here. What you've linked here are Push notifications, which yes, go through GCM and do require web service calls. This JS library is doing Desktop notifications, which afaik, are an entirely different thing, and are strictly limited to "within the context of the active page."
- martijndwars 10y agoTo answer the "how do I work around this during development": non-HTTPS is permitted on localhost (this is at least the case in Chrome). The spec also hints at this (https://w3c.github.io/push-api/#security-and-privacy-considerations https://w3c.github.io/push-api/#security-and-privacy-conside...). But, as has already been mentioned, this is about desktop notifications and not web push.