New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 618437 link

Starred by 1 user

Issue metadata

Status: Assigned
Owner:
Buried. Ping if important.
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 2
Type: Bug



Sign in to add a comment

upgrade-insecure-requests: dragging and "Open Image in New Tab" do not take upgrade into account

Project Member Reported by lgar...@chromium.org, Jun 8 2016

Issue description

Chrome 53.0.2756.0 
OSX 10.11.5

What steps will reproduce the problem?
(1) Visit https://upgrade.badssl.com/
(2) Drag the footer image to your desktop.
(3) Drag the footer image into the tab bar.

What is the expected output?
In step 2, the version of the resource with the green checkmark should be added to the file system.
In step 3, the URL of the actual resource should be visited.

What do you see instead?
Step 2 is as expected.
Step 3, however, visits the HTTP URL (with a red X rather than a green checkmark).
See the attached file for a screencast.

It seems confusing (dangerous?) that the URL attached to the drag is not for the image attached to the drag.

I haven't looked into intra-page and inter-tab/inter-browser drag/drop, but I imagine it's just as confusing.

Is it possible to either rewrite the DOM `src` of an upgraded resource, or else attach the correct URL for dragging?
 
upgrade-inconsistency.mov
9.4 MB Download
Summary: upgrade-insecure-requests: dragging and "Open Image in New Tab" do not take upgrade into account (was: upgrade-insecure-requests: drag of an upgraded resource has insecure URL attached)
Actually, it's even more confusing if you select "Open Image in New Tab" from the context menu. It literally doesn't open the image you clicked on.
open-image-in-new-tab.mov
3.4 MB Download

Comment 2 by rbyers@chromium.org, Nov 18 2016

Components: Blink>SecurityFeature

Comment 3 by est...@chromium.org, Nov 10 2017

Labels: Hotlist-EnamelAndFriendsFixIt

Comment 4 by est...@chromium.org, Feb 18 2018

Labels: -Hotlist-EnamelAndFriendsFixIt

Sign in to add a comment