New issue
Advanced search Search tips

Issue 614603 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Jan 8
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 3
Type: Feature
Team-Security-UX



Sign in to add a comment

Feature request: Indicate upgraded resources in security panel

Reported by tollm...@gmail.com, May 25 2016

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2747.0 Safari/537.36

Steps to reproduce the problem:
This is a feature request, so apologies for not following the "steps to reproduce" procedure.

The Security panel in Developer Tools is useful for identifying insecure domains used on secure pages; however, when using `upgrade-insecure-requests` and/or `strict-transport-security` Chrome may automatically upgrade requests to secure variants. While this is a good thing, it can lead a developer to think that all resources on a page are loaded securely when they actually aren't.

I would like to see the security panel indicator origins that have been upgraded so that it is clear to the developer that the HTML/JS/CSS in the page attempted to load an insecure request, but the browser upgraded it.

Perhaps this could be accomplished with another category, "Upgraded Origins". This category would list any origin that was upgraded via the browser even if it is listed in one of the other categories (because one origin could be used in multiple ways on one page).

What is the expected behavior?
N/A

What went wrong?
N/A

Did this work before? N/A 

Chrome version: 53.0.2747.0  Channel: canary
OS Version: OS X 10.11.4
Flash Version: Shockwave Flash 22.0 r0
 
Components: -Platform>DevTools Platform>DevTools>Security
Owner: caseq@chromium.org
Status: Assigned (was: Unconfirmed)

Comment 2 by caseq@chromium.org, May 25 2016

Owner: lgar...@chromium.org
Labels: -Type-Bug -OS-Mac OS-All Type-Feature
Labels: -Pri-2 Pri-3

Comment 5 by est...@chromium.org, Nov 10 2017

Labels: Hotlist-EnamelAndFriendsFixIt
Owner: est...@chromium.org

Comment 7 by est...@chromium.org, Feb 18 2018

Labels: -Hotlist-EnamelAndFriendsFixIt
Status: WontFix (was: Assigned)
Closing due to lack of action/resources. This would be a nice feature but developers can get this information with a report-only CSP policy as well.

Sign in to add a comment