New issue
Advanced search Search tips

Issue 689301 link

Starred by 1 user

Issue metadata

Status: Available
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug


Participants' hotlists:
PossibleTriciumChecks


Sign in to add a comment

Encourage or enforce HTTPS URLs in documentation

Project Member Reported by lgar...@chromium.org, Feb 7 2017

Issue description

Our documentation contains a lot of HTTP links, and even a lot of Chromium-related domains don't use HSTS: crbug.com/624163#c11

Anyone visiting those links is at risk of making development decisions or copying information from an untrusted source, especially when they are not on the corp network.

I'mma start by updating the conspicuous links at https://cs.chromium.org/chromium/src/docs/useful_urls.md to use HTTPS.

A presubmit like _CheckHardcodedGoogleHostsInLowerLayers [1] could catch future HTTP links, but that would be friction against submitting documentation, and probably futile in the face of all the existing documentation in the repo. Ideas welcome.

[1] https://bugs.chromium.org/p/chromium/issues/detail?id=624163#c11
 
Project Member

Comment 1 by bugdroid1@chromium.org, Feb 7 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/90c8bc34ef2ae379749a4c0c5a8a4fc55fe02056

commit 90c8bc34ef2ae379749a4c0c5a8a4fc55fe02056
Author: lgarron <lgarron@chromium.org>
Date: Tue Feb 07 03:27:18 2017

Update useful_urls.md links to HTTPS.

BUG=689301
TBR=elawrence@chromium.org

Review-Url: https://codereview.chromium.org/2680483003
Cr-Commit-Position: refs/heads/master@{#448535}

[modify] https://crrev.com/90c8bc34ef2ae379749a4c0c5a8a4fc55fe02056/docs/useful_urls.md

Project Member

Comment 2 by sheriffbot@chromium.org, Feb 12 2018

Labels: Hotlist-Recharge-Cold
Status: Untriaged (was: Available)
This issue has been Available for over a year. If it's no longer important or seems unlikely to be fixed, please consider closing it out. If it is important, please re-triage the issue.

Sorry for the inconvenience if the bug really should have been left as Available. If you change it back, also remove the "Hotlist-Recharge-Cold" label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Cc: cthomp@chromium.org
Status: Available (was: Untriaged)
Maybe we could do this with a Tricium check? It seems like it would be feasible to detect HTTP URLs/links, so I'll add it to a hotlist to think about when I have a chance to play with Tricium.

Sign in to add a comment