diff options
author | Peter Zhang <peter@innocraft.com> | 2022-05-18 01:12:21 +0300 |
---|---|---|
committer | GitHub <noreply@github.com> | 2022-05-18 01:12:21 +0300 |
commit | 35957fc5aeecf9f6f795e4e8e005f9d37fab7a2d (patch) | |
tree | ea88e41c8643d469bdb0352e492d401ae5bdc09a /config | |
parent | 3860159eaa190561896dcade11268193b4b4630b (diff) |
[security] Force matomo.org related requests to use ssl as default (#19098)
* Update dataTable.js
update database table
* Update dataTable.js
update table bug
* Update dataTable.js
shorter the query
* update screenshot
update screenshot
* Update dataTable.js
make table size stable
* Revert "Update dataTable.js"
This reverts commit 1a72e1d9580172414fb147cda9e66f4927f4b2ae.
* Update dataTable.js
update columns
* Revert "update screenshot"
This reverts commit c11aec88af44668171d2ee14e7a502b5fb04126f.
* force ssl to api and plug
force ssl to api and plug
* force request to ssl
force request to ssl
* Update Http.php
update tests
* update tests
update condition only on matomo.org
* update checks
update checks
* update default to https
update default to https
* update phpcs check
update phpcs check
* Update plugins/Marketplace/config/config.php
* add config force ssl on market place
add config force ssl on market place
* Update plugins/Marketplace/config/config.php
Co-authored-by: Justin Velluppillai <justin@innocraft.com>
* update config
update config
* update config
update config
* built vue files
* remove double diagnostic
remove double diagnostic
* force api using https
force api using https
* update tests
update tests
* update feed back
update feed back
* Remove unused use
* update failed display message
update failed display message
* Update plugins/CoreUpdater/Diagnostic/HttpsUpdateCheck.php
Co-authored-by: Justin Velluppillai <justin@innocraft.com>
* Minor text tweak
* update hardcode to translation
update hardcode to translation
* update translation
update translation
* update language and some logic
update language and some logic
* run test
run test
* trigger test
trigger test
* update screenshot
update screenshot
Co-authored-by: sgiehl <stefan@matomo.org>
Co-authored-by: Justin Velluppillai <justin@innocraft.com>
Co-authored-by: peterhashair <peterhashair@users.noreply.github.com>
Co-authored-by: Ben Burgess <88810029+bx80@users.noreply.github.com>
Diffstat (limited to 'config')
-rw-r--r-- | config/global.ini.php | 6 |
1 files changed, 5 insertions, 1 deletions
diff --git a/config/global.ini.php b/config/global.ini.php index 14276efcd7..ffe327416e 100644 --- a/config/global.ini.php +++ b/config/global.ini.php @@ -706,7 +706,7 @@ enable_trusted_host_check = 1 ; The API server is an essential part of the Matomo infrastructure/ecosystem to ; provide services to Matomo installations, e.g., getLatestVersion and ; subscribeNewsletter. -api_service_url = http://api.matomo.org +api_service_url = https://api.matomo.org ; When the ImageGraph plugin is activated, report metadata have an additional entry : 'imageGraphUrl'. ; This entry can be used to request a static graph for the requested report. @@ -800,6 +800,10 @@ enable_update_communication = 1 ; If you may need to download GeoIP updates or other stuff using other protocols like ftp you may need to extend this list. allowed_outgoing_protocols = 'http,https' +; This option forces matomo marketplace and matomo api requests to use Https for improved security +; If you have a problem loading the marketplace, please disable this config option +force_matomo_ssl_request = 1 + ; Comma separated list of plugin names for which console commands should be loaded (applies when Matomo is not installed yet) always_load_commands_from_plugin= |