HbbTV and HTTPS content mixing rules
Reference: ETSI TS 102 796 v2.x.x, Mixed Content (A.3.13) and W3C Candidate Recommendation – Mixed Content.
Overview
To protect users and maintain platform integrity, many HbbTV devices follows strict rules on how secure (HTTPS) and non-secure (HTTP) content can be combined. These rules are aligned with modern web security practices and enforced by both browsers and HbbTV terminals.
No mixed content allowed
HbbTV applications should not mix HTTP and HTTPS resources within the same page or application context.
- If your application is loaded over HTTPS, then all resources — including scripts, images, stylesheets, media files, and XHR/fetch requests — must also use HTTPS.
- Any attempt to load an http:// resource into an https:// application is considered mixed content and will violate both browser-level and HbbTV security policies.
- Conversely, if your application is delivered over HTTP, it may not access HTTPS resources that require a secure origin or certificate validation. These requests will typically fail or be blocked.
Broadcast vs broadband content
Broadcast resources (e.g., A/V streams received via DVB broadcast transport) are not affected by these rules because they are not delivered over HTTP or HTTPS.
The HTTPS content mixing restrictions apply only to broadband content — that is, any asset fetched over a network connection (e.g., via URL, XMLHttpRequest, fetch, or embedded <img>, <video>, or <script> tags).
Practical effect for developers
When building or testing an HbbTV application:
- Ensure your base URL and all referenced resources (scripts, stylesheets, images, videos, data files, etc.) use the same scheme — either all https:// or all http://.
- If you serve your application over https://, even a single http:// reference may cause the application to fail to load or be blocked entirely on TVs that enforce mixed content rules.
- Pay particular attention to third-party assets, analytics scripts, and CDN-hosted libraries — these must also be served securely if your application is HTTPS.
- When testing locally, use a consistent development environment (e.g., local HTTPS via self-signed certificates) to mirror your production setup.
Summary
| App Base URL | Allowed Resource Scheme | Mixed Content? | Result |
|---|---|---|---|
| https:// | https:// only | No | ✅ Works |
| https:// | http:// | Yes | 🚫 Blocked |
| http:// | http:// only | No | ✅ Works |
| http:// | https:// (secure-only APIs) | Yes | 🚫 Blocked |
Maintaining consistent URL schemes ensures that your application will load reliably on HbbTV devices.