Back to Previous Page
Forward to Previous Page

Portlets – Addressing Mixed Content Errors

Third-party Dashboard portlets, such as Facebook, Weather Channel, etc. may cause a mixed content scenario when secure (https) and insecure (http) content are both called into the same web page. This scenario is evident when the portlet added appears blank in the Dashboard screen.

Dashboard Portlets appear blank when both secure and insecure content is called into the same web page (mixed protocol content scenario).

Mixed Content

Sometimes, an SSL-secured website (denoted by 'https' in its web address) loads parts of its content from insecure sources. Content from insecure sources can be viewed by others as a web page is loading and information is transmitting. Malicious parties could potentially modify these insecure sources and change the look and behavior of the web page without your knowledge or consent.

Disclaimer:

Displaying mixed content requires changes to your browser settings that are not suggested for standard internet usage. These portlets have been provided by development for usage but they are publicly available widgets that use HTTP protocol. The user assumes the responsibility of doing their due diligence to ensure that they are able to use these safely as usage in OPERA Cloud causes a mixed protocol content scenario which is normally flagged on a publicly available website.

To Control the Display of Mixed Content on Secure Web pages

All browsers have some methodology that they use to manage this occurrence. We have outlined the mitigation steps for three of the major available browsers below.

Chrome

Firefox

Internet Explorer

Safari

Conclusion:

There are several reason why blank portlets may occur. This document, while dealing with the most frequent cause, does not address any other scenario. If users are experiencing blocked portlets they should go to console mode in the browser and try invoking the portlets individually. The blocked calls to the portlet URLs will look like the following:

e.g.

SEC7111: HTTPS security is compromised by

 

http://www.gmodules.com/ig/ifr?url=http%3A//igwidgets.com/lig/gw/f/islk/89/slkm/ik/s/1329844/87/charles447/google-maps-driving-directions.xml&
up_from=2640%20Goldengate%20Pkwy%2C%20Naples%2C%20FL%2C%2034105&up_to=&up_country=0&synd=open&
w=450&h=115&title=&lang=all&country=ALL&output=js

Oracle
Copyright © 2015, Oracle and/or its affiliates. All rights reserved.
Legal Notices

Version 9.0.1.20