Immediately after switching the page, it will work with CSR.
Please reload your browser to see how it works.
If an attacker has your phone and your password, it's game over anyway, who cares if some random app could allow MITM connections over HTTP.