infoCSP12 — upgrade-insecure-requests not set
Optional. If your app may load from a mix of http:// and https:// origins, this directive auto-upgrades requests, blocking mixed content.
fix: Add upgrade-insecure-requests if you serve over HTTPS and may have legacy http:// references.