New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 687537 link

Starred by 3 users

Issue metadata

Status: WontFix
Owner:
Closed: Oct 9
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Windows , Chrome , Mac
Pri: 2
Type: Bug



Sign in to add a comment

Clearing cookies from URL bar doesn't work on HTTPS pages with cert errors

Reported by andreych...@gmail.com, Feb 1 2017

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.95 Safari/537.36

Steps to reproduce the problem:
1. Navigate to a server with an expired/invalid SSL certificate that is known to set a cookie (a secure one, only to be sent on HTTPS).
2. Click on the "Secure" word in the URL bar, open the cookies list.
3. Delete the cookies.
4. Reload the page.

What is the expected behavior?
The secure cookie should have been deleted and not resent to the server.

What went wrong?
A non-secure cookie may be deleted, but the secure one stays and is resent to the server.

Did this work before? N/A 

Chrome version: 55.0.2883.95  Channel: stable
OS Version: OS X 10.12.2
Flash Version: Shockwave Flash 24.0 r0

Deleting the cookie through Settings -> advanced -> Content Settings -> All cookies and site data does work.

 
Labels: Needs-Milestone

Comment 2 by b...@chromium.org, Feb 2 2017

Components: Internals>Network>Cookies

Comment 3 by ajha@chromium.org, Feb 2 2017

Cc: ajha@chromium.org
Labels: Needs-Feedback
Somehow I didn't observed the behavior as updated above on Mac OS 10.12.2 using the reported version(55.0.2883.95). Tested this on https://expired.badssl.com/ and observed '0 Cookies in Use'. Attached is the screenshot of the same.

andreychirikba@: Could you please take a look at the attached screenshot and confirm if anything being missed here. Please check the same on the latest stable(56.0.2924.87) as well and provide any such URL if the issue is still seen.
687537.png
108 KB View Download
Components: -Platform>DevTools
Re Comment 3: I think https://expired.badssl.com/ doesn't set any cookie in the first place. The problem actually manifests itself when a server sets a cookie and I then delete it (it doesn't actually get deleted). I am experiencing this on our company dev server. I can provide you with a temporary login to verify this if you give me your contact details (don't want to publish company data).
Cc: jww@chromium.org mkwst@chromium.org
Components: Blink>SecurityFeature
Project Member

Comment 7 by sheriffbot@chromium.org, Feb 13 2017

Labels: -Needs-Feedback Needs-Review
Owner: ajha@chromium.org
Thank you for providing more feedback. Adding requester "ajha@chromium.org" for another review and adding "Needs-Review" label for tracking.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 8 by mkwst@chromium.org, Feb 14 2017

Labels: -Needs-Milestone M-58 OS-Android OS-Chrome OS-Linux OS-Windows
Owner: mkwst@chromium.org
Status: Assigned (was: Unconfirmed)
Looks like the strict secure cookie bits and pieces have broken the UI here (we should be displaying/removing all cookies).

Comment 9 by cda...@chromium.org, Mar 13 2017

Labels: -Needs-Review
Cleaning up sheriffbot label "Needs-Review" label as a part of modified "Needs-Feedback" sheriffbot rule. [ref bug for cleanup 684919]
Labels: Hotlist-EnamelAndFriendsFixIt
Labels: -Hotlist-EnamelAndFriendsFixIt
Cc: chlily@chromium.org mef@chromium.org mmenke@chromium.org morlovich@chromium.org
Labels: Hotlist-Cookies
Owner: ----
Status: Untriaged (was: Assigned)
(Unassigning myself, marking untriaged in preparation to retriage with folks who will do a better job taking care of cookies than I've been able to)
Owner: dullweber@chromium.org
Status: Assigned (was: Untriaged)
Status: WontFix (was: Assigned)
I wasn't able to reproduce the issue. I disabled the ssl warning for https://expired.badssl.com, manually created a cookie in devtools and reenabled the ssl warning in the pageinfo dialog. The cookie is listed in pageinfo and it can be deleted from there as well. Maybe the issue was fixed?

Also note that the cookie wouldn't be send to the server if Chrome can't establish a secure connection.

Sign in to add a comment