Issue metadata
Sign in to add a comment
|
Wrong security state when going back/forward after HTML5 history push
Reported by
jleedev@gmail.com,
Sep 16 2016
|
||||||||||||||||||||
Issue descriptionUserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2860.0 Safari/537.36 Steps to reproduce the problem: Either: 1. Visit https://github.com/rust-lang/rust 2. Click on README.md 3. Go back Or (minimal): 1. Visit https://www.example.com 2. history.pushState({}, '', ''); 3. Go back What is the expected behavior? Security state should remain secure. What went wrong? Security state switches to "not secure". Did this work before? Yes 53 and 54 are ok. Chrome version: 55.0.2860.0 Channel: canary OS Version: 6.1 (Windows 7, Windows Server 2008 R2) Flash Version: This looks like another edge case of Issue 643173 .
,
Sep 19 2016
De-restricting and taking out of the security sheriff queue, since we are failing to show the lock icon when we should be. (Instead of, for example, showing it when we shouldn't be, which would be a security bug.) Still, I think we should fix this ASAP.
,
Sep 19 2016
doh, looking.
,
Sep 20 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/9edf16001930c58297ae6790c74c5b36050906e8 commit 9edf16001930c58297ae6790c74c5b36050906e8 Author: jam <jam@chromium.org> Date: Tue Sep 20 01:40:58 2016 Fix navigations after HTML5 history push losing their SSL status. BUG= 647683 CQ_INCLUDE_TRYBOTS=master.tryserver.chromium.linux:linux_site_isolation Review-Url: https://codereview.chromium.org/2348203003 Cr-Commit-Position: refs/heads/master@{#419633} [modify] https://crrev.com/9edf16001930c58297ae6790c74c5b36050906e8/chrome/browser/ssl/ssl_browser_tests.cc [modify] https://crrev.com/9edf16001930c58297ae6790c74c5b36050906e8/content/browser/frame_host/navigation_controller_impl.cc
,
Sep 20 2016
,
Sep 20 2016
,
Sep 28 2016
,
Oct 1 2016
,
Dec 9 2016
Security>UX component is deprecated in favor of the Team-Security-UX label
,
Dec 27 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 12
,
Dec 3
|
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by est...@chromium.org
, Sep 16 2016Components: Security>UX
Labels: -OS-Windows OS-All
Owner: jam@chromium.org
Status: Assigned (was: Unconfirmed)