https://mybbc.files.bbci.co.uk/s/id/account-idcta/1.23.4/modules/idcta-v2/statusbar.js

Category: Uncategorized

Keywords: resource requested


Last fetched: 2019-11-28T14:11:57.937561+00:00

HTTP status: 5 Sub-resource URL


TLS/SSL configuration report

TLS score
F
Grade capped at F
Certificate path cannot be verified to a known root certificate

See full SSL/TLS security report for mybbc.files.bbci.co.uk

Security-related HTTP headers

  • Server: AmazonS3

    Announces web server software and optionally version details.

    Read more...

  • NEL: {"report_to":"default","max_age": 604800,"include_subdomains":true,"failure_fraction":0.01}

    Network Error Logging (NEL) defines a mechanism enabling web applications to declare a reporting policy that can be used by an user agent to report network errors for a given origin.

    Read more...

  • Report-To: {"group":"default","max_age":3600,"endpoints":[ {"url":"https://europe-west1-bbc-otg-traf-mgr-bq-prod-4591.cloudfunctions.net/report-endpoint","priority":1} ],"include_subdomains":true}

    The header defines a generic reporting framework which allows web developers to associate a set of named reporting endpoints with an origin. Various platform features (like Content Security Policy, Network Error Reporting, and others) may use these endpoints to deliver feature-specific reports in a consistent manner.

    Read more...

  • Access-Control-Allow-Origin: *

    Controls origins (websites) that are allowed to load data from this web service over JavaScript-based APIs as part of Cross-Origin Resource Sharing (CORS) standard. By default, a web browser will refuse to load data over XmlHttpRequest from a website that is not in the same origin, which is a precaution against various types of data stealing attacks. The target server has to explicitly allow the origin domain using the Access-Control-Allow-Origin (ACAO) header, or it may allow all origins to access it using a wildcard *. The latter however creates a potential security issue if the website in question is transactional and processing sensitive data, so the wildcard should be only used on websites consciously offering public APIs.

    Read more...

Pages loading this URL

Fully automated RESTful API is now available. Subscribe for your free trial today!