Handshake Papers
Handshake Papers
@HandshakePapers

Why does my HTTPS page show "not fully secure"?

Why does my HTTPS page show "not fully secure"?

You installed a certificate, the page loads over HTTPS, yet the browser still complains. What is it objecting to? Almost always: mixed content — a secure page pulling sub-resources over plain HTTP.

Mixed content means an https:// page references http:// assets. Browsers split it into two classes with different treatment:

— Active mixed content: scripts, stylesheets, iframes, XHR/fetch. These can rewrite the entire page, so browsers block them outright. This is why "the page is broken" — your JavaScript over HTTP silently never loaded.
— Passive mixed content: images, audio, video. Historically only warned about, because they can't execute code — though modern browsers now auto-upgrade these to HTTPS where possible.

The security reasoning is concrete: a single HTTP-loaded script over an otherwise encrypted page hands a network attacker full DOM control, defeating the entire TLS session. So blocking active content isn't pedantry; it's closing the weakest link.

Two fixes worth knowing: serve every asset over HTTPS (the real fix), and add the upgrade-insecure-requests Content-Security-Policy directive, which tells the browser to rewrite http:// sub-resource URLs to https:// automatically.

Further reading: W3C Mixed Content specification; MDN's mixed-content reference.

Bottom line: one HTTP resource compromises a whole HTTPS page. Active content is blocked, passive is upgraded — serve everything over HTTPS to clear the warning.
Этот пост опубликован в Telegram-канале Handshake Papers. Подписаться можно по ссылке: @HandshakePapers.
tech

Свежие посты в категории «Tech Infrastructure»

Все каналы категории →

start

Готовы запустить рекламу через сеть public.tg?

Новый оффер, продукт, GEO, кейс, событие или партнёрский запуск — соберём маршрут под задачу и отдадим медиаплан.

Telegram для медиаплана: @AFFtop_connect. Быстрый тест: $20 за канал, $1000 за пакет по сети.