在 HTTPS 承載的頁面上不允許出現 http 請求,一旦出現就是提示或報錯:
This request has been blocked; the content must be served over HTTPS
解決方案:
html:
<meta http-equiv="Content-Security-Policy" content="upgrade-insecure-requests"/>
php:
header("Content-Security-Policy: upgrade-insecure-requests");
nginx:在server模塊增加
add_header Content-Security-Policy "upgrade-insecure-requests;connect-src *";