mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-08-06 08:58:05 +00:00
50df5b3c02
Helmet 8 merges custom directives with its built-in defaults, which include upgrade-insecure-requests. Simply omitting the directive from the custom object (PR #59) was insufficient — Helmet silently re-adds it from defaults. Setting upgradeInsecureRequests: null is the correct Helmet 8 API to remove a default directive. This was the root cause of the persistent blank page on plain-HTTP self-hosted deployments: the directive tells browsers to upgrade all HTTP sub-resource fetches to HTTPS, producing ERR_SSL_PROTOCOL_ERROR on every JS/CSS asset.