Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8404009
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 9, 20262026-06-09T22:29:09+00:00 2026-06-09T22:29:09+00:00

I am designing my first GAE app and obviously need to use HTTPS for

  • 0

I am designing my first GAE app and obviously need to use HTTPS for the login functionality (can’t be sending my User’s UIDs and passwords in cleartext!).

But I’m confused/nervous about how to handle requests after the initial login. The way I see it, I have 2 strategies:

  • Use HTTPS for everything
  • Switch back from HTTPS (for login) to plain ole’ HTTP

The first option is more secure, but might introduce performance overhead (?) and possibly send my service bill through the roof. The second option is quicker and easier, but less secure.

The other factor here is that this would be a “single-page app” (using GWT), and certain sections of the UI will be able to accept payment and will require the secure transmission of financial data. So some AJAX requests could be HTTP, but others must be HTTPS.

So I ask:

  • GAE has a nifty table explaining incoming/outgoing bandwidth resources, but never concretely defines how much I/O bandwidth can be dedicated for HTTPS. Does anybody know the restrictions here? I’m planning on using “Billing Enabled” and paying a little bit for the app (and for higher resource limits).
  • Is it possible to have a GWT/single-page app where some portions of the UI use HTTP while others utilize HTTPS? Or is it “all or nothing”?
  • Is there any real performance overheard to utilizing an all-HTTPS strategy?

Understanding these will help me decide between a HTTP/S hybrid solution, or a pure HTTPS solution. Thanks in advance!

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-09T22:29:11+00:00Added an answer on June 9, 2026 at 10:29 pm

    If you start mixing http and https request you are as secure as you would be using http, because any http request can be intercepted and can introduce possible XSS attacks.

    If you are serious about your security read up on it, assuming that you only require https for sensible data and transmitting the rest with http will bring you in a lot of trouble.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I'm stumbling my way through designing my first Flex app, using Flex Builder 4
My first post here – hoping you can help me with designing an algorithm
I have Finished Designing my first Crystal Report using ASP.NET, I am Providing user
I'm designing a programming language for my personal use and education. The first versions
I am designing my database using code first and I need a little help
I'm designing my first API for a web app based on a MongoDB datastore.
I'm currently designing my first website and I want to use a carousel style
When designing REST API is it common to authenticate a user first? The typical
I have just started designing for my first iOS app and I am confused
I am designing a mobile website and I first tried just to use a

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.