<p>The server URL is used to generate links in password recovery e-mails.<br>
This should happen via HTTPS not plain HTTP to prevent<br>
man-in-the-middle attacks.</p>

<p>There are a lot of other places that hardcode http:// instead of https:// for several URLs. If you do not mind changing the links to https, I can create a follow-up patch to address the other instances. Also I guess that the actual config file in production needs to be adjusted to actually use this change.</p>

<hr>

<h4>You can view, comment on, or merge this pull request online at:</h4>
<p>  <a href='https://github.com/openstreetmap/openstreetmap-website/pull/1340'>https://github.com/openstreetmap/openstreetmap-website/pull/1340</a></p>

<h4>Commit Summary</h4>
<ul>
  <li>Use https:// for server_url</li>
</ul>

<h4>File Changes</h4>
<ul>
  <li>
    <strong>M</strong>
    <a href="https://github.com/openstreetmap/openstreetmap-website/pull/1340/files#diff-0">config/example.application.yml</a>
    (2)
  </li>
</ul>

<h4>Patch Links:</h4>
<ul>
  <li><a href='https://github.com/openstreetmap/openstreetmap-website/pull/1340.patch'>https://github.com/openstreetmap/openstreetmap-website/pull/1340.patch</a></li>
  <li><a href='https://github.com/openstreetmap/openstreetmap-website/pull/1340.diff'>https://github.com/openstreetmap/openstreetmap-website/pull/1340.diff</a></li>
</ul>

<p style="font-size:small;-webkit-text-size-adjust:none;color:#666;">—<br />You are receiving this because you are subscribed to this thread.<br />Reply to this email directly, <a href="https://github.com/openstreetmap/openstreetmap-website/pull/1340">view it on GitHub</a>, or <a href="https://github.com/notifications/unsubscribe-auth/ABWnLWO66hBiRxbpGkpmB-i0rcpK69Jfks5q30v1gaJpZM4KhIJN">mute the thread</a>.<img alt="" height="1" src="https://github.com/notifications/beacon/ABWnLZETBkfrZSt6atQAXwAmK-pRBJeUks5q30v1gaJpZM4KhIJN.gif" width="1" /></p>
<div itemscope itemtype="http://schema.org/EmailMessage">
<div itemprop="action" itemscope itemtype="http://schema.org/ViewAction">
  <link itemprop="url" href="https://github.com/openstreetmap/openstreetmap-website/pull/1340"></link>
  <meta itemprop="name" content="View Pull Request"></meta>
</div>
<meta itemprop="description" content="View this Pull Request on GitHub"></meta>
</div>

<script type="application/json" data-scope="inboxmarkup">{"api_version":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"GitHub"},"entity":{"external_key":"github/openstreetmap/openstreetmap-website","title":"openstreetmap/openstreetmap-website","subtitle":"GitHub repository","main_image_url":"https://cloud.githubusercontent.com/assets/143418/17495839/a5054eac-5d88-11e6-95fc-7290892c7bb5.png","avatar_image_url":"https://cloud.githubusercontent.com/assets/143418/15842166/7c72db34-2c0b-11e6-9aed-b52498112777.png","action":{"name":"Open in GitHub","url":"https://github.com/openstreetmap/openstreetmap-website"}},"updates":{"snippets":[{"icon":"DESCRIPTION","message":"Use https:// for server_url (#1340)"}],"action":{"name":"View Pull Request","url":"https://github.com/openstreetmap/openstreetmap-website/pull/1340"}}}</script>