Content-Security-Policy: block-all-mixed-content directive

Deprecated: This feature is no longer recommended. Though some browsers might still support it, it may have already been removed from the relevant web standards, may be in the process of being dropped, or may only be kept for compatibility purposes. Avoid using it, and update existing code if possible; see the compatibility table at the bottom of this page to guide your decision. Be aware that this feature may cease to work at any time.

Warning: This directive is marked as obsolete in the specification. This directive was previously used to prevent "optionally blockable" mixed content from being fetched insecurely and displayed. Content that isn't blocked is now always upgraded to a secure connection, so this directive is not needed.

The HTTP Content-Security-Policy (CSP) block-all-mixed-content directive prevents loading any assets over HTTP when the page uses HTTPS.

All mixed content resource requests are blocked, including both blockable and upgradable mixed content. This also applies to <iframe> documents, ensuring the entire page is mixed content-free.

Note: The upgrade-insecure-requests directive is evaluated before block-all-mixed-content. If the former is set, the latter does nothing, so set one directive or the other – not both, unless you want to force HTTPS on older browsers that do not force it after a redirect to HTTP.

Syntax

http
Content-Security-Policy: block-all-mixed-content;

Examples

http
Content-Security-Policy: block-all-mixed-content;

<meta http-equiv="Content-Security-Policy" content="block-all-mixed-content">

To disallow http assets on a more granular level, you can also set individual directives to https:. For example, to disallow insecure HTTP images:

http
Content-Security-Policy: img-src https:

Specifications

Not part of any current specification. Used to be defined in the outdated Mixed Content Level 1 specification.

Browser compatibility

desktop mobile
Chrome
Edge
Firefox
Opera
Safari
Chrome Android
Firefox for Android
Opera Android
Safari on iOS
Samsung Internet
WebView Android
WebView on iOS
block-all-mixed-content
Deprecated
Chrome – Full support
Chrome 44 (Release date: 2015-07-21)
footnote
footnote Will be removed, see bug 40260100.
Edge – Full support
Edge 79 (Release date: 2020-01-15)
footnote
footnote Will be removed, see bug 40260100.
Firefox – No support
Firefox 48 – 121 (Release date: 2016-08-02)
footnote Removed in 122 and later
Opera – Full support
Opera 31 (Release date: 2015-08-04)
footnote
footnote Will be removed, see bug 40260100.
Safari – Full support
Safari 10 (Release date: 2016-09-20)
footnote Full support
Chrome Android – Full support
Chrome Android 44 (Release date: 2015-07-29)
footnote
footnote Will be removed, see bug 40260100.
Firefox for Android – No support
Firefox for Android 48 – 121 (Release date: 2016-08-02)
footnote Removed in 122 and later
Opera Android – Full support
Opera Android 32 (Release date: 2015-09-23)
footnote
footnote Will be removed, see bug 40260100.
Safari on iOS – Full support
Safari on iOS 10 (Release date: 2016-09-13)
footnote Full support
Samsung Internet – Full support
Samsung Internet 4 (Release date: 2016-03-11)
footnote
footnote Will be removed, see bug 40260100.
WebView Android – Full support
WebView Android 44 (Release date: 2015-07-29)
footnote
footnote Will be removed, see bug 40260100.
WebView on iOS – Full support
WebView on iOS 10 (Release date: 2016-09-13)
footnote Full support

Legend

Tip: you can click/tap on a cell for more information.

Full support
Full support
Deprecated. Not for use in new websites.
See implementation notes.

See also