New issue
Advanced search Search tips

Issue 603853 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Apr 2016
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

Mixed Content Shield not displaying correctly

Reported by dane.she...@gmail.com, Apr 15 2016

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.75 Safari/537.36

Steps to reproduce the problem:
1. Visit https://crix.xaxis.technology/creative/122961_LR%20Test.html
2. Checking the console we get the mixed content warning
3. The mixed content shield normally found on the right hand side within the address bar does not appear

What is the expected behavior?
1. Would expect the the mixed content shield to appear, alerting the user of the attempt to display mixed content.

For example. The mixed content shield shows correctly on this similar page...

https://crix.xaxis.technology/creative/378997_Sizmek.html

What went wrong?
.

Did this work before? N/A 

Chrome version: 50.0.2661.75  Channel: stable
OS Version: 10.0
Flash Version: Shockwave Flash 21.0 r0
 

Comment 1 by tsepez@chromium.org, Apr 15 2016

Status: WontFix (was: Unconfirmed)
Visiting the abouve URL (step 1), I didn't see any mixed content being requested in the network tab, nor were there any console messages, thus the lack of a shield seems correct.

Do you have any extensions installed?  If so, you can try again after disabling them?
No i don't have any extensions installed.

Please view screenshot
Capture.JPG
121 KB View Download
It seems the issue is when the mixed content is loaded within an iframe on the page.

This is the iframe that is loaded...

https://secure-ds.serving-sys.com/BurstingRes/Site-76373/WSFolders/5955244//index.html?v=_2_57_1_0&n=1

And the shield is appearing there. View attachment.
Capture.JPG
69.5 KB View Download

Comment 4 by est...@chromium.org, Apr 17 2016

This is by design; we intentionally disabled the mixed content shield for active mixed content loaded inside iframes because it's too hard to properly explain to the user what's going on. See issues  536925  and  582603 .
Project Member

Comment 5 by sheriffbot@chromium.org, Jul 23 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 6 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 7 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment