New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 623486 link

Starred by 2 users

Issue metadata

Status: Assigned
Owner:
Buried. Ping if important.
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 3
Type: Bug



Sign in to add a comment

Mixed content parent frame checking logic might be wrong

Project Member Reported by carlosk@chromium.org, Jun 27 2016

Issue description

While working on  issue 576270  I found out that when searching for the parent secure context for mixed content checking only the top level frame and the immediate parent are checked, in this order. See the implementation of MixedContentChecker::inWhichFrameIsContentMixed [1].

After discussing this with mkwst@ we think this might be wrong and we should instead check all levels in between. Note that there are layout tests that fail when the top one is not given priority.

Note: if  issue 576270  lands before this is addressed, the introduced browser side logic should also be updated.


[1] https://cs.chromium.org/chromium/src/third_party/WebKit/Source/core/loader/MixedContentChecker.cpp?type=cs&q=MixedContentChecker::inWhichFrameIsContentMixed+file:%5C.cpp&sq=package:chromium
 
Status: Available (was: Untriaged)
mkwst@, could you please help in finding the right owner for this issue. Thanks!
Cc: tyoshino@chromium.org hirosh...@chromium.org
Project Member

Comment 4 by sheriffbot@chromium.org, Mar 9 2018

Labels: Hotlist-Recharge-Cold
Status: Untriaged (was: Available)
This issue has been Available for over a year. If it's no longer important or seems unlikely to be fixed, please consider closing it out. If it is important, please re-triage the issue.

Sorry for the inconvenience if the bug really should have been left as Available. If you change it back, also remove the "Hotlist-Recharge-Cold" label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Cc: -tyoshino@chromium.org toyoshim@chromium.org
Components: Blink>SecurityFeature

Comment 6 by jochen@chromium.org, Mar 13 2018

Owner: mkwst@chromium.org
Status: Assigned (was: Untriaged)

Sign in to add a comment