class ActionDispatch::ContentSecurityPolicy
def block_all_mixed_content(enabled = true)
policy.block_all_mixed_content false
Pass +false+ to allow it again:
policy.block_all_mixed_content
HTTP when the page uses HTTPS:
Specify whether to prevent the user agent from loading any assets over
def block_all_mixed_content(enabled = true) if enabled @directives["block-all-mixed-content"] = true else @directives.delete("block-all-mixed-content") end end