Will I just have to deal with the yellow "mixed content! insecure!" warning? Will I have to proxy requests?
There’s many forums like that in the web.
Will I just have to deal with the yellow "mixed content! insecure!" warning? Will I have to proxy requests?
There’s many forums like that in the web.
[1] https://developers.google.com/web/fundamentals/security/prev...
In the long term you'd have to "hope" the whole web transitions to https and just rewrite the url's to https, or cache them locally or proxy serve them locally. HTH.
Something like:
At worst the users see the grey "i" in circle icon: https://googlesamples.github.io/web-fundamentals/fundamental...
Imagine you have a website with a payment form on an HTTPS page, but you embed some external analytics script over HTTP. If your visitor's request is MITMed (e.g. they're in a coffee shop or some other insecure WiFi access point, etc), then an attacker can modify the script (that's over HTTP) to send these credit card details to the attacker's server. Once there's a single HTTP resource on the page, HTTPS means a whole lot less, hence the scary warnings.
More like if there is a single line of 3rd party code.
That's quite concerning as far as warning signs go.
And I don't want to have to compromise the users safety by switching entirely back to HTTP, which would just give no warning.