New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 717934 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: May 2017
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Mac
Pri: 2
Type: Bug



Sign in to add a comment

Chrome allows you to insert html code into windows with about:blank protocol

Reported by jm.acun...@gmail.com, May 3 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.81 Safari/537.36

Example URL:

Steps to reproduce the problem:
1- go to http://createcharts.esy.es/about-blank.html
2- click button Test

What is the expected behavior?

What went wrong?
Chrome allows you to insert html code into windows with about:blank protocol

Does it occur on multiple sites: N/A

Is it a problem with a plugin? N/A 

Did this work before? N/A 

Does this work in other browsers? N/A

Chrome version: 58.0.3029.81  Channel: n/a
OS Version: 6.3
Flash Version:
 
Tested in

- Google Chrome Version 58.0.3029.96 (64-bit)
- Google Chrome Version 60.0.3087.0 (Build oficial) canary (64 bits)
Labels: Needs-Triage-M58 Needs-Bisect
Cc: hdodda@chromium.org
Labels: Needs-Feedback
Tested the issue on Windows 7 using M58 #58.0.3029.81 and #58.0.3029.96 and #60.0.3088.3 and followed below steps :

1. Launched chrome and navigated to "http://createcharts.esy.es/about-blank.html" and clicked on test 
2. Observed that page redirected to chrome downloads page with about: blank url..

Attached screencast for reference.

@jm.acuna73-- COuld you please check attached screencast and confirm us if we have missed out any steps in reproducing the issue and please provide us the expected and actual issue screenshots for better traiging.

Thanks!
717934.mp4
1.1 MB View Download
Standardization: in 2010, and onwards, there are efforts to standardize the about URI scheme, and define the processing requirements for some specific URIs, in the IETF Applications Area Working Group (APPSAWG)

URI -> about:blank
Purpose -> Returns a blank HTML document with the media type text/html and character encoding UTF-8

(https://en.wikipedia.org/wiki/About_URI_scheme)

A more basic example:

<script>
function go(){
	var win = open('about:blank','_blank');
	win.document.open();
	win.document.write('<h1>test</h1>');
	win.document.close();	
}
</script>
<input type="button" onclick="go()" value="test"/>

Testing in Mozilla Firefox, I think it has a correct browsing behavior.
Project Member

Comment 5 by sheriffbot@chromium.org, May 4 2017

Labels: -Needs-Feedback
Thank you for providing more feedback. Adding requester "hdodda@chromium.org" to the cc list and removing "Needs-Feedback" label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Go to http://createcharts.esy.es/about-blank-basic.html

(please try Mozilla Firefox and Google Chrome to see the differences)
Labels: -Type-Compat -Needs-Bisect -Needs-Triage-M58 M-60 OS-Linux OS-Mac Type-Bug
Status: Untriaged (was: Unconfirmed)
Able to reproduce this issue on Mac 10.12.4, Win-10 and Ubuntu 14.04 using chrome reported version #58.0.3029.81 and latest canary #60.0.3089.0.

This is a non-regression issue as it is observed from M30 old builds. 

Hence, marking it as untriaged to get more inputs from dev team.

Thanks...!!
Labels: Needs-triage-Mobile

Comment 9 by ajha@chromium.org, May 18 2017

Labels: -Needs-triage-Mobile
Status: WontFix (was: Untriaged)
It's an expected feature of the web platform that a window navigated to about:blank can be written into by the context that opened it.

There's discussion about whether or not the omnibox should display something more informative in this case (e.g. "about:blank under the control of whatever.com") but the issue described here is absolutely by design.

Sign in to add a comment