http
Content-Security-Policy: upgrade-insecure-requests; block-all-mixed-content
<!-- HTTPS-Seite mit Legacy-HTTP-Ressourcen -->
<div class="dashboard">
<iframe src="http://widgets.example.com/chart"></iframe>
<!-- Upgraded zu HTTPS, blockiert falls HTTPS nicht verfügbar -->
</div>
<style>
.background {
background-image: url('http://cdn.example.com/bg.jpg');
/* Upgraded zu HTTPS automatisch */
}
</style>