The social media login features provided in the shop section by LoginRadius will result in a user attempting to login via the .onion being redirected back to
https://www.bentasker.co.uk
The cookie set on landing will be issued by the www-front so won't be valid if the user then switches back to the onion.
So there are essentially two issues here
- User can get redirected to the clearnet without warning
- Social media login doesn't work on the .onion
As a precaution against the former (my bigger concern) I'm going to temporarily block the shop section (with an appropriate message) for the .onion.
Activity
2015-05-22 16:34:40
2015-05-22 16:44:07
I suppose I should probably think about returning an appropriate response code as well though.
2015-05-22 16:50:52
I don't want to leave the shop section blocked indefinitely, but would unblocking it and disabling social media logins for the .onion be a better option? Not sure of the mechanism to do so yet, but if I could disable loginradius solely for the .onion it's probably a good improvement for privacy.
How many people are likely to visit the site via the .onion and yet be willing to let a 3rd party link their Twitter (or whatever) account to a visit to my site (onion or otherwise)?
On the other hand, though, disabling loginradius on the .onion means another difference between the onion and www-front that I'll need to maintain.
Needs thought.....
2015-10-19 16:19:11
The shop section has been read-only since the VAT MOSS changes earlier this year, so currently noone can log in, with social media or otherwise.
On the other hand, if the planned changes come into effect in January, I'll have to do MOSS stuff for offline sales/contracts anyway, so may look at re-opening the shop (as the extra MOSS overhead will be present and inavoidable at that point).
I'll leave this issue open for the time being, but can probably start to think about removing the block as the reason for it's implementation is no longer present. Just need to remember come January so that it can either be re-blocked, or the issue with LoginRadius resolved.
2017-07-06 10:17:24
I closed the shop section down quite some time ago, so have now moved it to being a collection of static pages, so loginradius isn't present on the site at all.
The archives can be accessed via Tor - http://6zdgh5a5e6zpchdz.onion/shoparchives
2017-07-06 10:17:24
2017-07-06 10:17:24
2017-07-06 10:17:28