Facebook Canvas Pages to Require SSL Certificates

Posted 8th August 2011

On the first of Octo­ber, Face­book will make another change which could have a sig­nif­i­cant — and poten­tially costly — impact to your appli­ca­tions and pages. As part of its lat­est moves to increase secu­rity across the plat­form, in addi­tion to OAuth adop­tion they will expect that your can­vas appli­ca­tions to be hosted at a secure address (https). If a user browses to your page via https — and mil­lions are begin­ning to change their set­tings so that they are — instead of your lov­ingly crafted con­tent, they’ll see the fol­low­ing warning:

Facebook warning: We can't display this content while you're viewing Facebook over a secure connection (https)
When view­ing a page with a Can­vas appli­ca­tion hosted at a non-​secure address, but when the user uses https for Face­book, they will see this message.