If your web app is being hosted over HTTPs as you’ve indicated, then all external resources it is consuming (CDN, scripts, CSS files, API calls) should also use SSL and be secured through HTTPs. Think about it. It would defeat the purpose of your app being secure, if your app was in turn making insecure requests to an API.
You can either therefore:
- As Chrome suggests, change your API calls to use HTTPs (recommended)
- Use HTTP instead of HTTPs
- Add the following
meta
tag to your<head>
element in your HTML:<meta http-equiv="Content-Security-Policy" content="upgrade-insecure-requests">
More information about this can be found here: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/upgrade-insecure-requests.
Related Posts:
- How can I convert MP3 file to a Base64 encoded string? [closed]
- How is the AND/OR operator represented as in Regular Expressions?
- TCP vs UDP – What is a TCP connection? [duplicate]
- Google Calendar API event insert always return 404 “not found” error
- did you specify the right host or port? error on Kubernetes
- What is archive mode in rsync?
- 403 Forbidden vs 401 Unauthorized HTTP responses
- Turn off pager for psql’s interactive output
- How do I get my C# program to sleep for 50 msec?
- How can I sort a dictionary by key?
- How to align iframe always in the center
- How to turn IDENTITY_INSERT on and off using SQL Server 2008?sql-server-2008
- XPath contains(text(),’some string’) doesn’t work when used with node with more than one Text subnode
- What does enctype=’multipart/form-data’ mean?
- How do I remove version tracking from a project cloned from git?
- What is the difference between == and equals() in Java?
- Error in .External.graphics R
- Time Complexity of Prims Algorithm?
- Does != have meaning in OCaml?
- Assembly’s manifest definition does not match assembly reference
- Java – No enclosing instance of type Foo is accessible
- How does createOrReplaceTempView work in Spark?
- “package XXX is not in GOROOT” when building a Go project
- what is the difference between OLE DB and ODBC data sources?
- How do I get a list of built-in data sets in R?
- How to terminate the script in JavaScript?
- Git push won’t do anything (everything up-to-date)
- spring @sqlgroup with multiple datasource
- Spyder does not autocomplete local variables
- What is the definition of a “disparity map”?
- Git error on git pull (unable to update local ref)
- git status shows modifications, git checkout —
doesn’t remove them - Tool for drawing parse trees?
- Resource interpreted as stylesheet but transferred with MIME type text/html (seems not related with web server)
- how to uninstall MinGW and make cygwin ‘make’ as deafult make program with gcc 3.8.1
- Clearing localStorage in javascript?
- How to sign-extend a number in Verilog
- “docker build” requires exactly 1 argument(s)
- ORA-01461: can bind a LONG value only for insert into a LONG column-Occurs when querying
- Optional Parameters in Go?
- Python FileNotFound
- Android java.lang.IllegalStateException: Could not execute method of the activity
- How do I get monitor resolution in Python?
- How do I get monitor resolution in Python?
- SonarQube Runner vs Scanner
- How to set the authorization header using cURL
- R error which says “Models were not all fitted to the same size of dataset”
- Error in glm() in R
- OCaml: Match expression inside another one?
- Create new tmux session from inside a tmux session
- Swift protocols: method does not override any method from its superclass
- Disable Chrome pinch zoom for use in kiosk
- jQuery onclick not firing on dynamically inserted HTML elements?
- JavaScript: IIF like statement
- What is the relationship between PyTorch and Torch?
- What is the relationship between PyTorch and Torch?
- Receiving “message”:”CB-ACCESS-KEY header is required” when attempting to connect to coinbase pro api
- How to implement OnFragmentInteractionListener
- What is the `data-target` attribute in Bootstrap 3?
- simple IPython example raises exception on sys.exit()
- PostgreSQL: Query has no destination for result data
- if-not condition fails (jQuery)
- RGBA code for red color
- Arithmetic Overflow in mips
- error: unknown type name ‘bool’
- How to draw lines in Java
- NoClassDefFoundError in Java: com/google/common/base/Function
- While running the script throws cannot find module ‘dotenv’
- Brackets : how to make autocomplete / autoindent works ?
- Python: What OS am I running on?
- Import error No module named skimage
- In Java, what is a shallow copy?
- Why define PI = 4*ATAN(1.d0)
- Android marshmallow : Galaxy Note 4 Screen Overlay Detected
- Passing a hexadecimal value into a module in Verilog
- Visual Studio 2019 – error MSB8020: The build tools for Visual Studio 2013 cannot be found
- mport win32ui in python 3.6
- How to print a int64_t type in C
- textarea’s rows, and cols attribute in CSS
- Contact Form 7 – Execute code AFTER mail send [closed]
- wp_localize_script with mce_external_plugins in wordpress
- Forbid contributors viewing drafts
- Contact Form 7: Redirecting on a condition? [closed]
- show taxonomy meta field in template
- Multiple og:image for Facebook
- Reset counter with jQuery [closed]
- show just own posts of custom-post-type to wordpress user
- Symlink not updating as expected when using an absolute with relative path
- What are the different widely used RAID levels and when should I consider them?
- What is a glue record?
- Getting “Cannot ioctl TUNSETIFF tun: Operation not permitted” when trying to connect to OpenVPN
- Run Oracle SQL script and exit from sqlplus.exe via command prompt
- Windows Server restart / shutdown history
- Cooling Server Closet – No A/C Is Possible
- nmap find all alive hostnames and IPs in LAN
- How to filter http traffic in Wireshark?
- How to inspect remote SMTP server’s TLS certificate?
- Dealing with HTTP w00tw00t attacks
- Do SPF Records For Primary Domain apply to subdomains?
- Why is the response on localhost so slow?