No http:// resources on HTTPS pages
On this page
Reject HTML / Svelte / Astro pages that reference http:// resources via src= or href= attributes. On HTTPS pages, browsers block these as mixed content - images don’t load, scripts don’t execute, analytics doesn’t fire, and the console errors are too vague for non-devtools users to make sense of.
What this catches#
Every src="http://..." and href="http://..." value, with these exemptions:
- XML namespaces -
xmlnsURLs are identifiers, not fetch targets (e.g.http://www.w3.org/2000/svg) - Schemas -
schema.org,schemas.example.com - Localhost / RFC1918 ranges (
127.0.0.1,192.168.x.x,10.x.x.x,172.16-31.x.x) example.com/example.org/example.net- documentation examples- IETF / purl reference URLs
For everything else: BLOCK.
Fix#
<!-- WRONG - fails on https pages -->
<img src="http://cdn.example.com/logo.png" />
<link rel="stylesheet" href="http://fonts.googleapis.com/css?family=Roboto" />
<!-- RIGHT - explicit https -->
<img src="https://cdn.example.com/logo.png" />
<link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Roboto" />
<!-- ALSO OK - protocol-relative (matches the page's protocol) -->
<img src="//cdn.example.com/logo.png" />
If the resource is HTTPS-capable, the swap is mechanical. If it’s HTTP-only, you have three options:
- Host a copy yourself behind your own HTTPS endpoint
- Proxy through a CF Worker / similar reverse proxy
- Reach out to the upstream maintainer - most “HTTP-only” claims are out of date
Suppressing intentional cases#
Per-line for explicit demos / docs:
<!-- appframes:disable-next-line security/no-mixed-content-urls -->
<a href="http://internal-only.lan/admin">Admin (LAN only)</a>
Per-file for entire pages that legitimately serve HTTP-internal contexts:
<!-- appframes:disable security/no-mixed-content-urls -->
Why BLOCK (tier 2)#
The failure mode is silent: the page loads, but resources are missing. Users see broken images, missing fonts, layout shift, and unexplained errors in features that depend on the blocked resources. Catching it at commit time costs nothing; catching it via “the site looks weird in prod” costs hours of debugging.
WARN lets the push through and records the finding. Turn frames on per repo on the dashboard's Policy page - see choosing what the gate checks.
Source on GitHub Live demo How it works Questions: contact@nimblegate.com