Is there some workaround I can use to avoid mixed-content errors?

Viewed 559

I am working on a .Net core web app which is using esri services /resources. The app will eventually be hosted on the client's server. We have esri resources hosted on our servers and other esri resources hosted on their servers. For whatever reason, they refuse to use SSL and we do use SSL so I now have an

Mixed content: The page at https://app.smt.smt was loaded over HTTPS but requests and insecure XMLHttpRequest endpoint. This request has been blocked; the content must be served over HTTPS.

I tried migrating our resources on their servers, they refused. Is there some workaround I can do to avoid this mixed content error?

2 Answers

There is no way just from your frontend code to work around mixed-content blocking.

The only alternative is to make the requests to the http resources from your backend code rather than your frontend code, or else to create a proxy of some kind that exposes the resources to your frontend code at https URLs rather than http URLs.

No frontend way to avoid this error. The server I had that caused this issue was an nginx ingress server for a kubernetes cluster.

I found that if I made my requests over https and to port 443 that the error was resolved. (even though the nginx server had no HTTPs cert to speak of).

So it appears this can be resolved on the backend by allowing https requests on port 443 even if the backend server isn't configured with a valid https cert.


Very possible security restrictions get tighter in the future but this works as of June 2022.

Related