Protocol-Relative URLs to Fix Mixed-Content Warnings
autoref.com
autoref.com
If you then change your feed to hard-code "http://example.com/... in IMGs and such, you've just created the mixed-content hole when someone reads your feed over https. So, then you really have to have a second instance of the feed with nearly-identical URLs but with https protocols.
Why not serve https to everyone? Some places block it. They tend to be oppressive regimes, but that's the way it is. They can get to you on port 80 but not port 443.
I had to go to a hybrid scheme. Web pages get //host/path, http fetches of my Atom feed get http://host/path, and https fetches of the Atom feed get https://host/path.
Even then, some browsers still don't quite work with the web site, but I'm okay with ignoring them, since they didn't send User-Agent strings and are obviously broken. Besides, there have only been two of them so far this entire week.
( Mostly recycled from a post about this not too long ago: http://rachelbythebay.com/w/2012/08/28/feed/ )
Full disclosure (bizdev at autoref)
I've got a project that addresses this by converting any URL to SSL:
http://www.fixweb.co/
Just take whatever URL you want to access, like http://example.com/test.gif
add the FixWeb.co address in front of it like this: https://fixweb.co/example.com/test.gif
^^^^^^^^^^^^^^^^^^
and it will return the file over SSL.It's not designed for high security file delivery, obviously, but it will get you around a normal Mixed-Content warning.
Or do you see this as more of an end user fix via a MITM proxy or something? Even then that sounds contrived.
What am I missing?
Yes, this means you probably need to re-evaluate whether your "like/share/connect/plusone this" really needs to be on every page, or even any page.
You also need to re-evaluate whether you really need statistics via third parties, or if you can track them yourselves. The answer is almost always that you can do it yourself, though it might not be as convenient as, say, copy/pasting google analytics code into your template.
If you're using a content engine, take a close look at it. Turn off and remove features you don't use, don't merely hide them. You might also be surprised which plugins may be phoning home in some form, or pulling content from places you didn't expect.
> If you're constantly pulling content from 4-5 different
> domains, perhaps you should re-think your sites
> architecture to minimize that.
And if you are not you may be interested in doing that — browsers have limited number of connections per domain so splitting your assets across 2-4 domains allows to download more resources in parallel.Finally, we went back to two separate tags (one for http, one for https).
I hope this becomes more widely understood, it make a lot of sense.
Thank you for finally acknowledging and serving this important niche.