New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 733675 link

Starred by 1 user

Issue metadata

Status: Assigned
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug



Sign in to add a comment

Add a group policy to override auto-open / danger level

Project Member Reported by mad@chromium.org, Jun 15 2017

Issue description

As suggested in the conversation of  issue 683797   #9 :

One of the feature requests that we've considered for downloads in the past:

* Override auto-open / danger level -- possibly per origin.

  We disallow opening some file types automatically. Folks have asked for overrides for enterprises in the past for file types like .jnlp and even .exes.

  Enterprise would like to control the danger level of files downloaded from private networks as a policy. Once SB is disabled for a download, it automatically falls back on the dangerous file list for deciding when to prompt users for dangerous downloads. Admins want to be able to disable prompting for executables and other files that are deployed via their intranets.

This (and related  issue 723658 ) will likely rely on some concept of a 'private' or 'safe' network with additional restrictions. E.g. foo.example.com is safe iff when talking over https. 

On Windows we could potentially derive this concept from IE's 'Intranet' zone settings. Doing so has the advantage that the mark-of-the-web annotation for executables and other file types would be consistent with Chrome's dangerous file handling. Without this, we could end up in situations where Chrome doesn't prompt for a whitelisted download, but Windows does. Thus forcing admins to keep two sets of settings in sync.

[note that the * Disable SB pings for downloads from private networks. also suggested in the original comment, is taken care of in  issue 723658 ].

I think that preventing the warning for dangerous file types should be easy to add, but allowing auto-open for these file types would be trickier, since we wouldn't want to auto-open files of these types unless they come from a trusted network so the UI becomes confusing. Right?

 
Project Member

Comment 1 by sheriffbot@chromium.org, Jun 15 2018

Labels: Hotlist-Recharge-Cold
Status: Untriaged (was: Available)
This issue has been Available for over a year. If it's no longer important or seems unlikely to be fixed, please consider closing it out. If it is important, please re-triage the issue.

Sorry for the inconvenience if the bug really should have been left as Available.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Status: Assigned (was: Untriaged)
mad@ marking this as assigned since it looks like you're the owner.  If you need the downloads team to do work here instead let me know!  Thanks :).
Owner: georgesak@chromium.org

Sign in to add a comment