Tweakers home page https Mixed Content (error)

Pagina: 1
Acties:

Vraag


  • ddexp67
  • Registratie: Februari 2008
  • Laatst online: 19-01 15:09
Mijn vraag
Bij mij bezoek aan Tweakers home page krijg ik een fout melding van zowel chrome (51.0.2704.84 m) als FF (47) dat mijn verbinding niet 100% veilig is.

Fout melding word veroorzaakt door Mixed Content.

Volgens mij is dit niet de bedoeling want ik zie het voor het eerst dus ga er van uit dat er iets fout gaat.

gr
Dejan
Dit is wat ik terug krijg in de console van Chrome.

VM164:1 [Report Only] Refused to load the image 'http://ic.tweakimg.net/ext/i/2001095807.jpeg' because it violates the following Content Security Policy directive: "default-src https: data: 'unsafe-inline' 'unsafe-eval'". Note that 'img-src' was not explicitly set, so 'default-src' is used as a fallback.

VM164:1 Mixed Content: The page at 'https://tweakers.net/' was loaded over HTTPS, but requested an insecure image 'http://ic.tweakimg.net/ext/i/2001095807.jpeg'. This content should also be served over HTTPS.
VM164:1 [Report Only] Refused to load the image 'http://ic.tweakimg.net/ext/i/2001122093.png' because it violates the following Content Security Policy directive: "default-src https: data: 'unsafe-inline' 'unsafe-eval'". Note that 'img-src' was not explicitly set, so 'default-src' is used as a fallback.

VM164:1 Mixed Content: The page at 'https://tweakers.net/' was loaded over HTTPS, but requested an insecure image 'http://ic.tweakimg.net/ext/i/2001122093.png'. This content should also be served over HTTPS.
VM164:1 [Report Only] Refused to load the image 'http://ic.tweakimg.net/ext/i/2001104387.jpeg' because it violates the following Content Security Policy directive: "default-src https: data: 'unsafe-inline' 'unsafe-eval'". Note that 'img-src' was not explicitly set, so 'default-src' is used as a fallback.

VM164:1 Mixed Content: The page at 'https://tweakers.net/' was loaded over HTTPS, but requested an insecure image 'http://ic.tweakimg.net/ext/i/2001104387.jpeg'. This content should also be served over HTTPS.
VM164:214 Mixed Content: The page at 'https://tweakers.net/' was loaded over a secure connection, but contains a form which targets an insecure endpoint 'http://www.itbanen.nl/vacature/zoeken?utm_source=tweakers.net&utm_medium=widget&utm_campaign=tweakers_home'. This endpoint should be made available over a secure connection.
VM164:1 [Report Only] Refused to load the image 'http://ic.tweakimg.net/vacature/logo/1583566/small' because it violates the following Content Security Policy directive: "default-src https: data: 'unsafe-inline' 'unsafe-eval'". Note that 'img-src' was not explicitly set, so 'default-src' is used as a fallback.

VM164:1 Mixed Content: The page at 'https://tweakers.net/' was loaded over HTTPS, but requested an insecure image 'http://ic.tweakimg.net/vacature/logo/1583566/small'. This content should also be served over HTTPS.
VM164:1 [Report Only] Refused to load the image 'http://ic.tweakimg.net/vacature/logo/1467397/small' because it violates the following Content Security Policy directive: "default-src https: data: 'unsafe-inline' 'unsafe-eval'". Note that 'img-src' was not explicitly set, so 'default-src' is used as a fallback.

VM164:1 Mixed Content: The page at 'https://tweakers.net/' was loaded over HTTPS, but requested an insecure image 'http://ic.tweakimg.net/vacature/logo/1467397/small'. This content should also be served over HTTPS.
VM164:1 [Report Only] Refused to load the image 'http://ic.tweakimg.net/vacature/logo/1195003/small' because it violates the following Content Security Policy directive: "default-src https: data: 'unsafe-inline' 'unsafe-eval'". Note that 'img-src' was not explicitly set, so 'default-src' is used as a fallback.

VM164:1 Mixed Content: The page at 'https://tweakers.net/' was loaded over HTTPS, but requested an insecure image 'http://ic.tweakimg.net/vacature/logo/1195003/small'. This content should also be served over HTTPS.
VM164:1 [Report Only] Refused to load the image 'http://ic.tweakimg.net/vacature/logo/1433309/small' because it violates the following Content Security Policy directive: "default-src https: data: 'unsafe-inline' 'unsafe-eval'". Note that 'img-src' was not explicitly set, so 'default-src' is used as a fallback.

VM164:1 Mixed Content: The page at 'https://tweakers.net/' was loaded over HTTPS, but requested an insecure image 'http://ic.tweakimg.net/vacature/logo/1433309/small'. This content should also be served over HTTPS.
VM164:1 [Report Only] Refused to load the image 'http://ic.tweakimg.net/vacature/logo/4942/small' because it violates the following Content Security Policy directive: "default-src https: data: 'unsafe-inline' 'unsafe-eval'". Note that 'img-src' was not explicitly set, so 'default-src' is used as a fallback.

VM164:1 Mixed Content: The page at 'https://tweakers.net/' was loaded over HTTPS, but requested an insecure image 'http://ic.tweakimg.net/vacature/logo/4942/small'. This content should also be served over HTTPS.
VM164:1 [Report Only] Refused to load the image 'http://ic.tweakimg.net/ext/i/2001105265.jpeg' because it violates the following Content Security Policy directive: "default-src https: data: 'unsafe-inline' 'unsafe-eval'". Note that 'img-src' was not explicitly set, so 'default-src' is used as a fallback.

VM164:1 Mixed Content: The page at 'https://tweakers.net/' was loaded over HTTPS, but requested an insecure image 'http://ic.tweakimg.net/ext/i/2001105265.jpeg'. This content should also be served over HTTPS.
VM164:1 [Report Only] Refused to load the image 'http://ic.tweakimg.net/ext/i/2001116743.png' because it violates the following Content Security Policy directive: "default-src https: data: 'unsafe-inline' 'unsafe-eval'". Note that 'img-src' was not explicitly set, so 'default-src' is used as a fallback.

VM164:1 Mixed Content: The page at 'https://tweakers.net/' was loaded over HTTPS, but requested an insecure image 'http://ic.tweakimg.net/ext/i/2001116743.png'. This content should also be served over HTTPS.
content.scripts.c.js:11 TableManager::findTables()
XHR finished loading: GET "https://tweakers.net/xmlhttp/xmlHttp.php?application=frontpage&type=refresh…%5D=20&types%5B%5D=21&display=aggregated&output=json&nocache=1465891111810".
XHR finished loading: GET "https://tweakers.net/xmlhttp/xmlHttp.php?application=frontpage&type=refresh…%5D=20&types%5B%5D=21&display=aggregated&output=json&nocache=1465891233087".
XHR finished loading: GET "https://tweakers.net/xmlhttp/xmlHttp.php?application=frontpage&type=refresh…%5D=20&types%5B%5D=21&display=aggregated&output=json&nocache=1465891354317".


Relevante software en hardware die ik gebruik
...

Wat ik al gevonden of geprobeerd heb
...

Alle reacties


  • crisp
  • Registratie: Februari 2000
  • Laatst online: 23:34

crisp

Devver

Pixelated

Daar wordt nog aan gewerkt, momenteel worden de script om alle http-gelinkte content om te zetten naar https nog gedraaid ;)

Intentionally left blank


  • ddexp67
  • Registratie: Februari 2008
  • Laatst online: 19-01 15:09
Aha dus de overstap voor de hele site wordt nu gedaan. Excuses ik had het gemist... ik dacht dat jullie al lang over waren :)

  • crisp
  • Registratie: Februari 2000
  • Laatst online: 23:34

crisp

Devver

Pixelated

Als het goed is zou dit nu niet meer voor mogen komen. Indien wel horen we het uiteraard graag :)

Intentionally left blank