From a168dc915e35b7aa9313b2c1d876056f7ef9e4a0 Mon Sep 17 00:00:00 2001 From: Kirill Pimenov <kirill@pimenov.cc> Date: Fri, 1 Mar 2013 00:58:36 +0400 Subject: [PATCH] Secure gravatar --- app/models/user.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/models/user.rb b/app/models/user.rb index e6e1ce8a1..75b726061 100644 --- a/app/models/user.rb +++ b/app/models/user.rb @@ -315,7 +315,7 @@ class User < ActiveRecord::Base email_hash = self.email_hash(email) # robohash was possibly causing caching issues # robohash = CGI.escape("http://robohash.org/size_") << "{size}x{size}" << CGI.escape("/#{email_hash}.png") - "http://www.gravatar.com/avatar/#{email_hash}.png?s={size}&r=pg&d=identicon" + "https://www.gravatar.com/avatar/#{email_hash}.png?s={size}&r=pg&d=identicon" end # return null for local avatars, a template for gravatar