Issue metadata
Sign in to add a comment
|
Wrong security state when redirecting to HTTP
Reported by
jleedev@gmail.com,
Sep 1 2016
|
||||||||||||||||||||||
Issue descriptionUserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2845.0 Safari/537.36 Steps to reproduce the problem: Visit https://www.google.com/#newwindow=1&q=%22http.badssl.com%22 and click on the first result. What is the expected behavior? What went wrong? Lock icon is shown. Devtools Security Panel says this page is secure. Did this work before? Yes Chrome version: 55.0.2845.0 Channel: canary OS Version: 6.1 (Windows 7, Windows Server 2008 R2) Flash Version: Correct behavior in 414731 Bad behavior in 415292
,
Sep 1 2016
Regression on Windows and OS X. Looks okay in 55.0.2844, bad in 2845 and 2846, so this is a very recent regression.
,
Sep 1 2016
Suspect this'll be fixed by https://codereview.chromium.org/2299843002/?
,
Sep 1 2016
(I can't reproduce on 55.0.2846.0 on OS X though.)
,
Sep 1 2016
I can repro it on: 55.0.2845.0 canary (64-bit) on OSX. Seems like a duplicate of Issue 642838 (SSL state not updated on restoring tab).
,
Sep 2 2016
re-opening since the fix for issue 642838 did not fix this. jam@ -- do you want to take on this one also?
,
Sep 2 2016
,
Sep 2 2016
doh, looking. I didn't test this case.
,
Sep 3 2016
Issue 643905 has been merged into this issue.
,
Sep 3 2016
When you add Type-Bug-Security, make sure to add Restrict-View-SecurityTeam.
,
Sep 4 2016
Issue 643963 has been merged into this issue.
,
Sep 6 2016
Issue 644120 has been merged into this issue.
,
Sep 6 2016
,
Sep 7 2016
,
Sep 7 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/0576b13b74ef273fe311a95cbbb9e1a3bc8045c5 commit 0576b13b74ef273fe311a95cbbb9e1a3bc8045c5 Author: jam <jam@chromium.org> Date: Wed Sep 07 05:13:10 2016 Fix incorrect SSL state being shown for client redirects. BUG= 643173 CQ_INCLUDE_TRYBOTS=master.tryserver.chromium.linux:linux_site_isolation Review-Url: https://codereview.chromium.org/2305093002 Cr-Commit-Position: refs/heads/master@{#416849} [modify] https://crrev.com/0576b13b74ef273fe311a95cbbb9e1a3bc8045c5/chrome/browser/ssl/ssl_browser_tests.cc [add] https://crrev.com/0576b13b74ef273fe311a95cbbb9e1a3bc8045c5/chrome/test/data/ssl/in_page_navigation_during_load.html [add] https://crrev.com/0576b13b74ef273fe311a95cbbb9e1a3bc8045c5/chrome/test/data/ssl/redirect.html [add] https://crrev.com/0576b13b74ef273fe311a95cbbb9e1a3bc8045c5/chrome/test/data/ssl/redirect_with_mixed_content.html [modify] https://crrev.com/0576b13b74ef273fe311a95cbbb9e1a3bc8045c5/content/browser/frame_host/navigation_controller_impl.cc [modify] https://crrev.com/0576b13b74ef273fe311a95cbbb9e1a3bc8045c5/content/browser/frame_host/navigation_controller_impl.h
,
Sep 7 2016
,
Sep 8 2016
,
Sep 9 2016
Issue 645434 has been merged into this issue.
,
Sep 9 2016
,
Dec 9 2016
Security>UX component is deprecated in favor of the Team-Security-UX label
,
Dec 15 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 14 2017
,
Nov 20 2017
Reproduced with 55.0.2845.0 (used example.com to confirm I could interact with the page, follow links etc, which I could)
,
Dec 1 2017
*** Boilerplate reminders! *** Please do NOT publicly disclose details until a fix has been released to all our users. Early public disclosure may cancel the provisional reward. Also, please be considerate about disclosure when the bug affects a core library that may be used by other products. Please do NOT share this information with third parties who are not directly involved in fixing the bug. Doing so may cancel the provisional reward. Please be honest if you have already disclosed anything publicly or to third parties. Lastly, we understand that some of you are not interested in money. We offer the option to donate your reward to an eligible charity. If you prefer this option, let us know and we will also match your donation - subject to our discretion. Any rewards that are unclaimed after 12 months will be donated to a charity of our choosing. *********************************
,
Dec 1 2017
Hi jleedev@ - the Chrome VRP (after a rather long delay, sorry about that!) looked at this issue and decided to reward $2,000! A member of our finance team will be in touch to arrange details. Also, how would you like to be credited?
,
Dec 1 2017
,
Dec 1 2017
Yay! Josh Lee. |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by elawrence@chromium.org
, Sep 1 2016Status: Available (was: Unconfirmed)