New issue
Advanced search Search tips

Issue 665001 link

Starred by 0 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Feb 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Bug



Sign in to add a comment

Mass RMV web site displays in Firefox but not in Chrome

Project Member Reported by rdsmith@chromium.org, Nov 14 2016

Issue description

Chrome Version       : 56.0.2914.3 (dev channel)
OS Version: OS X 10.11.6
URLs (if applicable) : https://secure.rmv.state.ma.us/PolicyBrowserPublic/PB/default.htm?turl=WordDocuments%2Fseizurelossofconsciousness.htm
Other browsers tested:
  Add OK or FAIL after other browsers where you have tested this issue:
     Safari 5:
  Firefox 4.x: OK
     IE 7/8/9:

What steps will reproduce the problem?
1. Visit the web site.  I've included screen captures of Chrome and Firefox when that is done.
2.
3.

What is the expected result?

Actually getting some textual information.

What happens instead of that?

A single vertical line down the screen.


Please provide any additional information below. Attach a screenshot if
possible.

UserAgentString: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2914.3 Safari/537.36



 
Chrome.png
85.9 KB View Download
Firefox.png
356 KB View Download
Components: -Blink Blink>SecurityFeature
Probably related to these console errors:

/PolicyBrowserPublic/PB/_d2h_theme_nav_left_top.htm:1 Multiple 'X-Frame-Options' headers with conflicting values ('SAMEORIGIN, "SAMEORIGIN"') encountered when loading 'https://secure.rmv.state.ma.us/PolicyBrowserPublic/PB/_d2h_theme_nav_left_top.htm'. Falling back to 'DENY'.
/PolicyBrowserPublic/PB/_d2h_theme_nav_left_top.htm:1 Refused to display 'https://secure.rmv.state.ma.us/PolicyBrowserPublic/PB/_d2h_theme_nav_left_top.htm' in a frame because it set 'X-Frame-Options' to 'SAMEORIGIN, "SAMEORIGIN"'.
/PolicyBrowserPublic/PB/_d2h_theme_nav_left_bottom.htm:1 Multiple 'X-Frame-Options' headers with conflicting values ('SAMEORIGIN, "SAMEORIGIN"') encountered when loading 'https://secure.rmv.state.ma.us/PolicyBrowserPublic/PB/_d2h_theme_nav_left_bottom.htm'. Falling back to 'DENY'.
/PolicyBrowserPublic/PB/_d2h_theme_nav_left_bottom.htm:1 Refused to display 'https://secure.rmv.state.ma.us/PolicyBrowserPublic/PB/_d2h_theme_nav_left_bottom.htm' in a frame because it set 'X-Frame-Options' to 'SAMEORIGIN, "SAMEORIGIN"'.
/PolicyBrowserPublic/PB/_d2hblank.htm:1 Multiple 'X-Frame-Options' headers with conflicting values ('SAMEORIGIN, "SAMEORIGIN"') encountered when loading 'https://secure.rmv.state.ma.us/PolicyBrowserPublic/PB/_d2hblank.htm'. Falling back to 'DENY'.
/PolicyBrowserPublic/PB/_d2hblank.htm:1 Refused to display 'https://secure.rmv.state.ma.us/PolicyBrowserPublic/PB/_d2hblank.htm' in a frame because it set 'X-Frame-Options' to 'SAMEORIGIN, "SAMEORIGIN"'.
/PolicyBrowserPublic/PB/Policy%20Browser-toc.htm:1 Multiple 'X-Frame-Options' headers with conflicting values ('SAMEORIGIN, "SAMEORIGIN"') encountered when loading 'https://secure.rmv.state.ma.us/PolicyBrowserPublic/PB/Policy%20Browser-toc.htm'. Falling back to 'DENY'.
/PolicyBrowserPublic/PB/Policy%20Browser-toc.htm:1 Refused to display 'https://secure.rmv.state.ma.us/PolicyBrowserPublic/PB/Policy%20Browser-toc.htm' in a frame because it set 'X-Frame-Options' to 'SAMEORIGIN, "SAMEORIGIN"'.
https://secure.rmv.state.ma.us/favicon.ico Failed to load resource: the server responded with a status of 404 (Not Found)
/PolicyBrowserPublic/PB/WordDocuments/seizurelossofconsciousness.htm:1 Multiple 'X-Frame-Options' headers with conflicting values ('SAMEORIGIN, "SAMEORIGIN"') encountered when loading 'https://secure.rmv.state.ma.us/PolicyBrowserPublic/PB/WordDocuments/seizurelossofconsciousness.htm'. Falling back to 'DENY'.
/PolicyBrowserPublic/PB/WordDocuments/seizurelossofconsciousness.htm:1 Refused to display 'https://secure.rmv.state.ma.us/PolicyBrowserPublic/PB/WordDocuments/seizurelossofconsciousness.htm' in a frame because it set 'X-Frame-Options' to 'SAMEORIGIN, "SAMEORIGIN"'.

Comment 2 by mkwst@chromium.org, Feb 23 2017

Status: WontFix (was: Untriaged)
It looks like they've changed the site to send only one `X-Frame-Options` header, which is excellent. Still, they're sending `"SAMEORIGIN"` rather than `SAMEORIGIN` (note the quotes). The console warnings accurately note that that's not a valid `X-Frame-Options` value.

I guess we could add support for quoted values, but no other browser does that, and this is the first time I've seen it reported. I'm closing this out as WAI, but I'm willing to be convinced otherwise if this is more widespread than I imagine it is.

Sign in to add a comment