New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 642101 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jun 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 3
Type: Feature



Sign in to add a comment

HPKP errors/reports are not displayed in the console or devtools anywhere

Reported by scott.he...@gmail.com, Aug 29 2016

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36

Steps to reproduce the problem:
1. Generate a HPKP error and note that nothing is shown in the console.

To demonstrate this you can visit https://scotthelme.co.uk to get my policy and then https://hpkp.scotthelme.co.uk which violates it to generate the warning page. 

What is the expected behavior?
An error message in the console with details would be handy.

What went wrong?
There is no error shown in the console. 

Did this work before? No 

Chrome version: 52.0.2743.116  Channel: stable
OS Version: 10.0
Flash Version: Shockwave Flash 22.0 r0
 
Also see  Issue 505550 , which is about Security panel support for anything HSTS/HPKP-related.

Comment 2 by est...@chromium.org, Aug 29 2016

Components: Security>UX
Labels: -Type-Bug-Security -OS-Windows -Pri-2 -Restrict-View-SecurityTeam OS-All Pri-3 Type-Feature
Status: Available (was: Unconfirmed)
Removing view restriction and marking this as a feature request. Also related to  issue 469471  which explains why the plumbing is kinda tricky for this.

I don't think it would be all that useful to just display when a violation occurs (after all, the interstitial should make it clear that a violation occurred). But, it might be useful to somehow show in devtools when a report is sent, for developers debugging their reporting setups.
Yeah, I was thinking how in CSP you can get some basic info from the console on what went wrong without having reporting enabled. Something similar for HPKP might be useful. 

Comment 4 by est...@chromium.org, Aug 29 2016

Cc: lgar...@chromium.org est...@chromium.org
 Issue 642105  has been merged into this issue.

Comment 5 by est...@chromium.org, Aug 29 2016

Summary: HPKP errors/reports are not displayed in the console or devtools anywhere (was: HPKP errors are not displayed in the console)

Comment 6 by raymes@chromium.org, Nov 30 2016

Components: -Security>UX Internals>Network>DomainSecurityPolicy
Labels: Team-Security-UX
Status: WontFix (was: Available)
Unfortunately, I think we should close this out for now. I definitely see the value, but it would be a fairly large plumbing job to make this happen, and I don't think usage is high enough to justify the effort. HPKP reports can be seen in chrome://net-internals at least.

Sign in to add a comment