Add a new flag for HTTP-bad development work |
|||
Issue descriptionWe should extend the #mark-non-secure-as flag to include an option for HTTP Bad Phase 1. All user-visible changes for HTTP-bad should happen behind the flag.
,
Sep 15 2016
,
Sep 15 2016
If I want to direct engineers to this flag, is there a specific hashtag? Would I sent them to this Bug?
,
Sep 15 2016
Re #3: #mark-non-secure-as with the non-secure-passwords-cc switch
,
Sep 15 2016
also point them to this bug so they can see where the switch is to work with it
,
Sep 15 2016
felt@: What should "Always mark non-secure origins as neutral" do for expired.badssl.com? It currently shows as bad.
,
Sep 15 2016
Re #6: "non-secure" = HTTP and equivalent. It doesn't do anything to HTTPS sites, validated or otherwise.
,
Sep 16 2016
That sounds wrong to me. Broken HTTPS is also non-secure by definition of the word "secure". And the flag choices are "Mark non-secure origins as *non-secure*" vs. "Mark non-secure origins as neutral." I think we should avoid using "non-secure" to mean "HTTP or downgraded [e.g. mixed content] HTTPS" to avoid any potential for confusion.
,
Sep 16 2016
This is how they've always been named; I didn't introduce any new naming scheme here, just continued with it for consistency. But I can update the strings in the dropdown.
,
Sep 23 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/ddc621c75ee7aba48a886d48201052047212b780 commit ddc621c75ee7aba48a886d48201052047212b780 Author: felt <felt@chromium.org> Date: Fri Sep 23 23:23:00 2016 Rename HTTP bad-related flags to be more clear The previous names used "non-secure", which is precise and correct (anything that is not a secure context) but confusing (does that include a supposedly secure context that is invalid?). This renames them to say "Http", but leaves the actual name of the flag the same because it's already widely documented. BUG= 646221 Review-Url: https://codereview.chromium.org/2344043003 Cr-Commit-Position: refs/heads/master@{#420780} [modify] https://crrev.com/ddc621c75ee7aba48a886d48201052047212b780/chrome/app/generated_resources.grd [modify] https://crrev.com/ddc621c75ee7aba48a886d48201052047212b780/chrome/browser/about_flags.cc [modify] https://crrev.com/ddc621c75ee7aba48a886d48201052047212b780/chrome/browser/ssl/ssl_browser_tests.cc [modify] https://crrev.com/ddc621c75ee7aba48a886d48201052047212b780/components/security_state/security_state_model.cc [modify] https://crrev.com/ddc621c75ee7aba48a886d48201052047212b780/components/security_state/security_state_model_unittest.cc [modify] https://crrev.com/ddc621c75ee7aba48a886d48201052047212b780/components/security_state/switches.cc [modify] https://crrev.com/ddc621c75ee7aba48a886d48201052047212b780/components/security_state/switches.h
,
Dec 9 2016
Security>UX component is deprecated in favor of the Team-Security-UX label |
|||
►
Sign in to add a comment |
|||
Comment 1 by bugdroid1@chromium.org
, Sep 15 2016