lips.scheme.org implementation subdomain Lassi Kortela 28 Dec 2020 22:28 UTC

> And as side topic I would like to ask if I can grab lips.scheme.org domain
> for my implementation.

Yes, absolutely! It would be great to have more implementations.

> I can setup on old domain redirect (it need to be like
> this) https://node.js.org/ and setup GitHub pages with scheme.org domain. I
> can setup CNAME on GitHub pages (right now it say lips.js.org) I'm not sure
> what need to be done in order to make this proper mapping. I would prefer
> proper name and not redirect like with other implementations.

The proper name, non-redirect solution, requires adding a
lips.scheme.org virtual host to your web server software and getting a
TLS/SSL certificate for it. The cert can be completely different from
your existing cert, or you can add lips.scheme.org as an alias hostname
onto the existing cert. Let's Encrypt and certbot make this easy but any
cert provider ought to be able to do it.

We have a policy that scheme.org subdomains should not track users. This
precludes tracking cookies, analytics JavaScript, etc. I wonder whether
GitHub pages does tracking; can we find out? Doing a HTTP HEAD request
for the current lips.js.org shows that it goes through Fastly,
Cloudflare, a Varnish server, then onto GitHub pages. Cloudflare, sets a
cookie like this:

Set-Cookie: __cfduid=<...hex digits...>; expires=<date>; path=/;
domain=.js.org; HttpOnly; SameSite=Lax

Their blog says that it's not for user tracking, and they plan to remove
it in May: <https://blog.cloudflare.com/deprecating-cfduid-cookie/>.

There was prior discussion that web fonts embedded from Google's servers
apparently introduce some kind of tracking, but I forget the details.

Sorry about all the hassle in case you are from the web 2.0 generation.
Many Schemers feel quite strongly about privacy on the web.