New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 649686 link

Starred by 6 users

Issue metadata

Status: Assigned
Owner:
Buried. Ping if important.
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Compat



Sign in to add a comment

non-secure context https iframe can open secure context window

Reported by olli.pet...@gmail.com, Sep 23 2016

Issue description

UserAgent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0

Example URL:

Steps to reproduce the problem:
Do what example 9 in https://w3c.github.io/webappsec-secure-contexts/ explains. The newly opened window object has 
window.isSecureContext true, but the opener has window.w.isSecureContext false.

What is the expected behavior?
Both should be false

What went wrong?
opened window has isSecureContext true.

Does it occur on multiple sites: N/A

Is it a problem with a plugin? N/A 

Did this work before? N/A 

Does this work in other browsers? N/A 

Chrome version:   Channel: n/a
OS Version: 
Flash Version:
 
I was using Version 55.0.2859.0 dev (64-bit)

Firefox Nightly does not have this issue.
s/opener has window.w.isSecureContext/opener has window.isSecureContext/
Hmm, it is not example 9, since this isn't about worker, but opening a new window.
So, the testcase is to have http top level page from origin A, it has iframe which has page from https domain B, and then in that iframe one does var w = window.open(location.href);
The window object inside iframe has isSecureContext == false, but the newly opened window has isSecureContext == true. And the newly opened window and iframe window can access each others.

Comment 4 by foolip@chromium.org, Nov 16 2016

Cc: mkwst@chromium.org
Mike, can you help triage this?
Components: Blink>HTML>IFrame
Labels: M-55

Comment 6 by mkwst@chromium.org, Nov 17 2016

Cc: -mkwst@chromium.org
Components: Blink>SecurityFeature
Owner: mkwst@chromium.org
Status: Assigned (was: Unconfirmed)
Sounds like a bug. I'll take a look.
Components: -Blink>SecurityFeature Blink>SecurityFeature>SecureContexts

Comment 8 by vakh@chromium.org, Jul 25 2017

Issue 748523 has been merged into this issue.

Comment 9 by est...@chromium.org, Nov 10 2017

Labels: Hotlist-EnamelAndFriendsFixIt
Labels: -Hotlist-EnamelAndFriendsFixIt

Sign in to add a comment