New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 695260 link

Starred by 1 user

Issue metadata

Status: Assigned
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Mac
Pri: 3
Type: Bug



Sign in to add a comment

extensions: scripts blocked in sandboxed frame

Reported by huglovef...@gmail.com, Feb 23 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3020.0 Safari/537.36

Steps to reproduce the problem:
1. select "do not allow any site to run javascript" in chrome://settings/content
2. install the provided extension
3. open its options page

What is the expected behavior?
the text in the sandboxed frame should be "scripts allowed" (inserted via document.write() in javascript)

What went wrong?
the sandboxed frame says "scripts blocked" (the text is in a noscript element) and the "javascript was blocked on this page" badge appears in the omnibox

WebStore page: 

Did this work before? N/A 

Chrome version: 58.0.3020.0  Channel: canary
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: Shockwave Flash 24.0 r0

the feature i'm referring to: https://developer.chrome.com/extensions/sandboxingEval

scripts are otherwise allowed in extensions regardless of the content setting so i think allowing them in sandboxed frames too would be the correct behavior

i could reproduce the issue with chrome versions 56.0.2924.87 (stable) and 58.0.3020.0 (canary)

 
sandbox breakage testcase.zip
726 bytes Download
scriptsAllowed.png
5.3 KB View Download
scriptsBlocked.png
7.1 KB View Download

Comment 1 by ajha@chromium.org, Feb 23 2017

Labels: Needs-Triage-M58
Cc: kkaluri@chromium.org
Labels: -Needs-Triage-M58 M-58 OS-Linux OS-Mac
Status: Untriaged (was: Unconfirmed)
Able to reproduce this issue on windows 10, Ubuntu 14.04 and Mac OS 10.12.3 using chrome stable M56-56.0.2924.87 
and earlier version of chrome M30-30.0.1595.0. This is a non-regression issue and marking it as untriaged.

Attaching screen-cast for reference.

Thank You...
Issue 695260.mp4
474 KB View Download

Comment 3 Deleted

Sign in to add a comment