How to enable SubtleCrypto in insecure context for testing?

Viewed 500

I have a few applications relying on hash functions, which were developed a while ago before browsers changed their policy to restrict Crypto.subtle to HTTPS connections.

Deploying the webapps on secure connection isn't a problem for me, but testing them locally is.

Is there a configuration in about:config that allows me to change the setting, for FireFox, Chrome, and Safari?

1 Answers

Probably too late to help you, but there's a config flag available on Chrome that allows you to specify insecure contexts that should be considered secure.

On Chrome, open chrome://flags and search for the flag "Insecure origins treated as secure". Add the insecure context domains you want to test on and relaunch the browser. Works for me.

I couldn't find a similar flag on Firefox. MDN says Safari allows SubtleCrypto usage on insecure contexts but I can't test it myself.

Related