New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 684231 link

Starred by 5 users

Issue metadata

Status: Assigned
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 3
Type: Bug



Sign in to add a comment

Remove data: from the list of secure schemes

Project Member Reported by mea...@chromium.org, Jan 24 2017

Issue description

data: URLs aren't secure except for being isolated origins. We don't know if the data URL originated from an http page, as opposed to https. We should consider removing data from kSecureSchemes in url_util.cc. 

The good news is that doing this seems to only break two tests:
http://build.chromium.org/p/tryserver.chromium.linux/builders/linux_chromium_rel_ng/builds/376516
 

Sign in to add a comment