New issue
Advanced search Search tips

Issue 723917 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 627968
Owner: ----
Closed: May 2017
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug-Security



Sign in to add a comment

Referrer-Policy using strict-origin recognized properly

Reported by stu...@anchev.net, May 18 2017

Issue description

UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.96 Safari/537.36

Steps to reproduce the problem:
1. In Apache's .htaccess set either:

Header always set Referrer-Policy "strict-origin-when-cross-origin"

or

Header always set Referrer-Policy "strict-origin"

2. Create an simple html file on the server and open it in the browser

What is the expected behavior?
The browser should recognize and respect the 'strict-origin' and 'strict-origin-when-cross-origin' referrer policies as outlined in the standard:

https://www.w3.org/TR/referrer-policy/#referrer-policy-strict-origin-when-cross-origin

What went wrong?
In console a red message appears:
---
Failed to set referrer policy: The value 'strict-origin-when-cross-origin' is not one of 'no-referrer', 'no-referrer-when-downgrade', 'origin', 'origin-when-cross-origin', or 'unsafe-url'. The referrer policy has been left unchanged.
---

IOW the set of recognized values does not include the full enum of values:

https://www.w3.org/TR/referrer-policy/#enumdef-referrerpolicy

Did this work before? N/A 

Chrome version: 58.0.3029.96  Channel: stable
OS Version: openSUSE Leap 42.2
Flash Version: Shockwave Flash 25.0 r0

Other policies like 'no-referrer' work as expected but not 'strict-origin-when-cross-origin' and 'strict-origin'
 

Comment 1 by est...@chromium.org, May 18 2017

Mergedinto: 627968
Status: Duplicate (was: Unconfirmed)
Thanks for the report. Chrome does not yet implement several referrer policies but hopefully will soon!

Comment 2 by stu...@anchev.net, May 18 2017

Thanks for the quick feedback. Looking forward to it!
Project Member

Comment 3 by sheriffbot@chromium.org, Aug 24 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment