"upgrade-insecure-requests works on localhost and breaks on every other device"
This story is from 2026-09-03. It is preserved in the archive; the latest stories are on the live feed.
The CSP allows no external host in any directive, so the page cannot contact anything even if a dependency tried. A build step drives a headless browser across the site and fails if any request leaves the origin. www.toolsholic.com
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-03 12:12 · DEV Community — AI
"upgrade-insecure-requests works on localhost and breaks on every other device"