3 ms·
CSP is not supported by IE, unfortuantely. But you an do 2 things around HTTPS: * set up a report-only policy saying taht all assets must be loaded over HTTPS.
by jusob 10y ago
CSP is not supported by IE, unfortuantely. But you an do 2 things around HTTPS:
* set up a report-only policy saying taht all assets must be loaded over HTTPS. You can receive a report when this is not the case.
* use upgrade-insecure-requests to upgrade HTTP requests to HTTPS automatically. Obviously, this can break stuff if the 3rd party server does not supprot HTTPS or has invalid SS certificates (CDN, for example).
Most browsers load images over HTTP from a HTTPS site but they will not for active content (Javascript, IFRAMES, etc.) unless the user explicitly acknowledge the mixed-content issue.