diff --git a/lib/main.js b/lib/main.js index b25936ca..a75436e7 100644 --- a/lib/main.js +++ b/lib/main.js @@ -76,7 +76,7 @@ function SockJS(url, protocols, options) { var secure = parsedUrl.protocol === 'https:'; // Step 2 - don't allow secure origin with an insecure protocol - if (loc.protocol === 'https:' && !secure) { + if (loc.protocol === 'https:' && !secure && parsedUrl.host !== '127.0.0.1') { throw new Error('SecurityError: An insecure SockJS connection may not be initiated from a page loaded over HTTPS'); }