4 ms·
If it's a HTTPS page, wouldn't that be blocked due to mixed content though? Or is HTTP requests from a HTTPS-loaded script allowed?
by CraftThatBlock 8y ago
If it's a HTTPS page, wouldn't that be blocked due to mixed content though? Or is HTTP requests from a HTTPS-loaded script allowed?
- djsumdog 8y agoModern browsers should block all backend/javascript http communication if the main request is made over HTTPS, unless you specifically disable it with a Content Security Policies.
- inetknght 8y agoBetter to just disable javascript altogether. Sure, there's no dynamic loading of garbage, but I didn't want that anyway. If your back-end server can't render HTML then you need to build an app. At least with native desktop apps I can put that garbage into a VM or container. Load whatever you want. I can then apply my own firewall/containerization/VM rules.