Handshake Papers
Handshake Papers
@HandshakePapers

upgrade-insecure-requests or block-all-mixed-content: which CSP directive fits a migration?

upgrade-insecure-requests or block-all-mixed-content: which CSP directive fits a migration?

When you move a site to HTTPS but legacy resources still reference http://, which Content Security Policy tool should you reach for? They solve adjacent but distinct problems.

upgrade-insecure-requests rewrites in-document HTTP subresource URLs to HTTPS before the request is made. It is forgiving: if the resource exists over TLS, it loads; the user sees no breakage. This is the migration aid — it papers over hardcoded http:// references during transition.

block-all-mixed-content does the opposite: it refuses to load any mixed content, optionally including the passive kind browsers normally allow. It is the enforcement tool — useful once you believe the site is clean and want a hard guarantee against regression.

Note that browsers now auto-upgrade many mixed requests regardless, and block passive mixed content in stricter modes, so these directives increasingly codify behavior the browser trends toward anyway.

— Use upgrade-insecure-requests during and shortly after migration.
— Switch to block-all-mixed-content once you want regression protection.
— Audit with the browser console's mixed-content warnings before flipping to block mode.

Further reading: W3C Mixed Content specification; CSP Level 3.

Bottom line: upgrade is the gentle migration crutch; block is the strict post-migration guardrail — sequence them, do not pick one forever.
Этот пост опубликован в Telegram-канале Handshake Papers. Подписаться можно по ссылке: @HandshakePapers.
tech

Свежие посты в категории «Tech Infrastructure»

Все каналы категории →

start

Готовы запустить рекламу через сеть public.tg?

Новый оффер, продукт, GEO, кейс, событие или партнёрский запуск — соберём маршрут под задачу и отдадим медиаплан.

Telegram для медиаплана: @AFFtop_connect. Быстрый тест: $20 за канал, $1000 за пакет по сети.