Intent to ship (in Nightly only): Mixed Content Level 2 upgrading of image, audio and video

42 views
Skip to first unread message

Lars Tomer Yavor

unread,
Nov 8, 2022, 4:15:02 AM11/8/22
to dev-platform, Firefox Dev

Summary: As part of increasing readiness to ship Mixed Content Level 2, we’re enabling the flag to upgrade some passive mixed content in Nightly only. Previously this would result in the mixed content indicator. Loads of type image, audio, and video will be upgraded by rewriting the URL from http: to secure transport using https:. As specified, there will be no fallback if the resource is not available over HTTPS.


We will keep this in Nightly for a couple of cycles, before we let it ride the trains.


Bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1672106 

Standard: https://www.w3.org/TR/mixed-content/ 

Platform coverage: All

Preference: security.mixed_content.upgrade_display_content

Our standards position: https://mozilla.github.io/standards-positions/#mixed-content 

Devtools bug: N/A. We already log to the console.


Other browsers: Chrome has been shipping that behavior since Chrome 81; no public signal from Apple.


web-platform-tests: Exist at mixed-content/tentative/autoupgrades



Intent to prototype was at https://groups.google.com/g/mozilla.dev.platform/c/F163Jz32oYY

Best regards,
Tomer, Freddy and Christoph
Reply all
Reply to author
Forward
0 new messages