Hi guys,
I've installed an SSL cert on a website but whenever I try to load it via https, it throws out a 'The page at "..." was loaded over HTTPS, but requested an insecure "..."'.
I have no idea why it's doing this, I've changed the link scheme in the config to https but it's had no effect, am I missing something obvious here?
Thanks!
Any images or JS scripts included on the page would also have to be https.
I can't think of anything safe. You may have links to off-site URLs that need to be http.
A plugin could change everything to https. It would slow down page loads slightly and might change too many links.
It would look something like this attached to OnDocFormRender (untested):
if (strpos($modx->resource->_content, 'http:') !== false) {
$modx->resource->_content = str_replace('http:', 'https:', $modx->resource->_content);
}
return;
I'm not sure if this suggestion applies to you or not, but if the files you are including in your webpage are also resources in your resource tree in MODX then when using a placeholder reference like [[~[[+resource_id]]]], where [[+resource_id]] is the resource number of the file you are linking to, you could change it to [[~[[+resource_id]]?&scheme=`https`]]
You can also change the default scheme in your system settings by going to the `link-tag-scheme` setting, and setting it of course to `https`
As a footnote, I will say that personally I like to setup all images, CSS files, and javascript files as static resources in my sites, but that's just me - with proper Content Types of course! This is in part due to the fact that I manage many many contexts (one for each client website) and linking between contexts means that I have to have fine-grained control over how each link url is generated. Having each file as a resource helps me to enforce proper link_tag_schemes on all files so that I personally don't get those nasty insecure request notifications.
Hope this helps!