Sites must not utilize the unsafe-url policy, as this will likely induce HTTPS URLs to become exposed about the wire around an HTTP connection, which defeats one of several vital privacy and security ensures of HTTPS. This can be a disincentive to migrate to HTTPS, since it deprives joined HTTP http://XXX