http restAPI calls on a https webiste












0















I have a https webiste. There is a rest call with POST method on a http target. Ideally http access over https should give errors but it gives response without any error. The http rest call responds with an excel file which gets downloaded.



Do restAPI calls bypass SAME ORIGIN POlICY ( since in my case there is difference of protocol ) ?



****Edited****
I converted a subdomain of my website to https ( for testing purpose) . So earlier there was a dropdown which on select would trigger a rest call to another URL ( same domain but different subdomain ( both http) ). This rest call would result in an excel file download.



Now one subdomain is https. Still that dropdown works and rest call is success and results in downloads ( now protocols of both subdomains are different). Shouldn't browser block rest call from executing ?



rest call from one subdomain ( https) to another subdomain ( http and using POST method)










share|improve this question

























  • where are you making the http request from and where does it connect to?

    – mihai
    Nov 26 '18 at 12:47











  • @mihai I have edited to make it clear

    – nits
    Nov 26 '18 at 13:39
















0















I have a https webiste. There is a rest call with POST method on a http target. Ideally http access over https should give errors but it gives response without any error. The http rest call responds with an excel file which gets downloaded.



Do restAPI calls bypass SAME ORIGIN POlICY ( since in my case there is difference of protocol ) ?



****Edited****
I converted a subdomain of my website to https ( for testing purpose) . So earlier there was a dropdown which on select would trigger a rest call to another URL ( same domain but different subdomain ( both http) ). This rest call would result in an excel file download.



Now one subdomain is https. Still that dropdown works and rest call is success and results in downloads ( now protocols of both subdomains are different). Shouldn't browser block rest call from executing ?



rest call from one subdomain ( https) to another subdomain ( http and using POST method)










share|improve this question

























  • where are you making the http request from and where does it connect to?

    – mihai
    Nov 26 '18 at 12:47











  • @mihai I have edited to make it clear

    – nits
    Nov 26 '18 at 13:39














0












0








0








I have a https webiste. There is a rest call with POST method on a http target. Ideally http access over https should give errors but it gives response without any error. The http rest call responds with an excel file which gets downloaded.



Do restAPI calls bypass SAME ORIGIN POlICY ( since in my case there is difference of protocol ) ?



****Edited****
I converted a subdomain of my website to https ( for testing purpose) . So earlier there was a dropdown which on select would trigger a rest call to another URL ( same domain but different subdomain ( both http) ). This rest call would result in an excel file download.



Now one subdomain is https. Still that dropdown works and rest call is success and results in downloads ( now protocols of both subdomains are different). Shouldn't browser block rest call from executing ?



rest call from one subdomain ( https) to another subdomain ( http and using POST method)










share|improve this question
















I have a https webiste. There is a rest call with POST method on a http target. Ideally http access over https should give errors but it gives response without any error. The http rest call responds with an excel file which gets downloaded.



Do restAPI calls bypass SAME ORIGIN POlICY ( since in my case there is difference of protocol ) ?



****Edited****
I converted a subdomain of my website to https ( for testing purpose) . So earlier there was a dropdown which on select would trigger a rest call to another URL ( same domain but different subdomain ( both http) ). This rest call would result in an excel file download.



Now one subdomain is https. Still that dropdown works and rest call is success and results in downloads ( now protocols of both subdomains are different). Shouldn't browser block rest call from executing ?



rest call from one subdomain ( https) to another subdomain ( http and using POST method)







node.js rest http ssl https






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Nov 26 '18 at 13:36







nits

















asked Nov 26 '18 at 11:13









nitsnits

345




345













  • where are you making the http request from and where does it connect to?

    – mihai
    Nov 26 '18 at 12:47











  • @mihai I have edited to make it clear

    – nits
    Nov 26 '18 at 13:39



















  • where are you making the http request from and where does it connect to?

    – mihai
    Nov 26 '18 at 12:47











  • @mihai I have edited to make it clear

    – nits
    Nov 26 '18 at 13:39

















where are you making the http request from and where does it connect to?

– mihai
Nov 26 '18 at 12:47





where are you making the http request from and where does it connect to?

– mihai
Nov 26 '18 at 12:47













@mihai I have edited to make it clear

– nits
Nov 26 '18 at 13:39





@mihai I have edited to make it clear

– nits
Nov 26 '18 at 13:39












0






active

oldest

votes











Your Answer






StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");

StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "1"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});














draft saved

draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53479910%2fhttp-restapi-calls-on-a-https-webiste%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown

























0






active

oldest

votes








0






active

oldest

votes









active

oldest

votes






active

oldest

votes
















draft saved

draft discarded




















































Thanks for contributing an answer to Stack Overflow!


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53479910%2fhttp-restapi-calls-on-a-https-webiste%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Contact image not getting when fetch all contact list from iPhone by CNContact

count number of partitions of a set with n elements into k subsets

A CLEAN and SIMPLE way to add appendices to Table of Contents and bookmarks