New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 709748 link

Starred by 3 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Nov 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug


Show other hotlists

Hotlists containing this issue:
EnamelAndFriendsFixIt


Sign in to add a comment

ERR_BLOCKED_BY_XSS_AUDITOR

Reported by safaks...@gmail.com, Apr 8 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 Safari/537.36

Steps to reproduce the problem:
1. I get this error when youtube.com is sent to iframe in CKEditor form.

What is the expected behavior?

What went wrong?
I get this error when youtube.com is sent to iframe in CKEditor form.

Did this work before? No 

Chrome version: 57.0.2987.133  Channel: stable
OS Version: 10.0
Flash Version: 

I get such an error while creating the record.
 
Cc: mikew@chromium.org
Components: -Platform>DevTools
Labels: TE-NeedsTriageHelp
This issue seems to be out of TE-scope. Hence, adding label TE-NeedsTriageHelp for further investigation.

Thanks...!!

Comment 3 by mmenke@chromium.org, Apr 19 2017

Cc: mkwst@chromium.org
Components: Blink>SecurityFeature>XSSAuditor
[mkwst]:  Looks like you added this error code?

Comment 4 by mkwst@chromium.org, Apr 20 2017

Cc: -mikew@chromium.org tsepez@chromium.org
Status: Available (was: Unconfirmed)
I don't really understand the bug report. Are you posting something to YouTube.com? Or are you posting something to your own origin that contains HTML?

Comment 5 by est...@chromium.org, Nov 10 2017

Labels: Hotlist-EnamelAndFriendsFixIt
Status: WontFix (was: Available)
Closing due to lack of feedback.

Sites that post HTML content to themselves need to opt out of XSS filtration using X-XSS-Protection: 0.

Sign in to add a comment