diff --git a/www/checkup/main.js b/www/checkup/main.js index 93ead1bbc..90c16a29a 100644 --- a/www/checkup/main.js +++ b/www/checkup/main.js @@ -705,9 +705,13 @@ define([ var isOnion = function (host) { return /\.onion$/.test(host); }; + var isLocalhost = function (host) { + return /^http:\/\/localhost/.test(host); + }; + assert(function (cb, msg) { // provide an exception for development instances - if (/http:\/\/localhost/.test(trimmedUnsafe)) { return void cb(true); } + if (isLocalhost(trimmedUnsafe) && isLocalhost(window.location.href)) { return void cb(true); } // if both the main and sandbox domains are onion addresses // then the HTTPS requirement is unnecessary