New issue
Advanced search Search tips

Issue 695363 link

Starred by 3 users

Issue metadata

Status: Available
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Windows , Chrome , Mac
Pri: 2
Type: Bug
csp



Sign in to add a comment

Deprecate insecure violation reports.

Project Member Reported by mkwst@chromium.org, Feb 23 2017

Issue description

CSP sends reports from HTTPS pages to HTTP endpoints. That seemed like a good idea at some point, but it obviously isn't one. Let's remove that misfeature.
 

Comment 1 Deleted

Comment 2 by mkwst@chromium.org, Feb 24 2017

Labels: csp

Comment 3 by mkwst@chromium.org, Mar 6 2017

Components: Blink>SecurityFeature>ContentSecurityPolicy
Am I correct in noting that these reports are currently blocked as Mixed Content?

I see the shield and the notification in the DevTools console:

Mixed Content: The page at 'https://docs.google.com/document/d/10REOGnhM/edit#' was loaded over HTTPS, but requested an insecure Content Security Policy reporting endpoint ''. This request has been blocked; the content must be served over HTTPS.

Interestingly, in this particular repro the report URI is empty; not sure what's up with that.

Comment 5 by mkwst@chromium.org, Mar 8 2017

Oh, well, that'd be great if we're already blocking mixed reporting endpoints! :)

Is this something easy to reproduce? We should write a test, but it turns out to be a little difficult to verify that a report _wasn't_ sent, given the fact that PingLoader explicitly decouples the reporting request from the page's lifetime. :/

Comment 6 by est...@chromium.org, Nov 10 2017

Labels: Hotlist-EnamelAndFriendsFixIt

Comment 7 by est...@chromium.org, Feb 18 2018

Labels: -Hotlist-EnamelAndFriendsFixIt
Labels: Hotlist-Interop

Sign in to add a comment