為了改善您的使用體驗,本網站正在進行維護,部分功能暫時無法使用。若本站的文件無法解決您的問題,想要向社群發問的話,請到 Twitter 上的 @FirefoxSupport 或 Reddit 上的 /r/firefox 發問,我們的社群成員將很快會回覆您的疑問。

搜尋 Mozilla 技術支援網站

防止技術支援詐騙。我們絕對不會要求您撥打電話或發送簡訊,或是提供個人資訊。請用「回報濫用」功能回報可疑的行為。

了解更多

HTTPS mode in all windows only failure

more options

When going to a site with FF, 90 which has partial secure information FF still allows access even though the site is not completely https. this should not be allowed HTTPS only should work if the site is completely compliant with HTTPS.

The example site is https://www.brampton.ca//en/online-services/pages/bramcams.aspx

If you click on one of the camera images with "https mode in all windows only" set, no image is displayed and the icon suggest HTTPS but the site is only partial https.

With "https mode in all windows" no configured you get the secure lock icon with the exclamation. see enclosed.

When going to a site with FF, 90 which has partial secure information FF still allows access even though the site is not completely https. this should not be allowed HTTPS only should work if the site is completely compliant with HTTPS. The example site is https://www.brampton.ca//en/online-services/pages/bramcams.aspx If you click on one of the camera images with "https mode in all windows only" set, no image is displayed and the icon suggest HTTPS but the site is only partial https. With "https mode in all windows" no configured you get the secure lock icon with the exclamation. see enclosed.
附加的畫面擷圖

所有回覆 (6)

more options

Note that clicking the padlock and selecting "HTTPS-Only Mode: Off temporarily" is sufficient to load the camera images (they are accessed via http://192.82.150.11:xxxx).

more options

For me, HTTPS Only mode blocks insecure embedded images.

For confirmation, I have this old test page (third image is insecure and can't be upgraded to HTTPS): https://www.jeffersonscher.com/res/mixed-display.html

more options

I see what you mean but I think FF should refuse to display the page if it is mixed https as the configuration setting is ""https-only mode in all windows"

more options

The mixed content is blocked. You would prefer to see nothing at all than only the secure content?

more options

Correct. Like Co-rel says I can override it if I wish.

more options

Seems like a lot of extra work. Definitely would not want it to default to that behavior.