New issue
Advanced search Search tips

Issue 749421 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Jul 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug



Sign in to add a comment

HTTP Feature-Policy header is ignored

Reported by sime.vi...@gmail.com, Jul 27 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0

Steps to reproduce the problem:
1. Open https://output.jsbin.com/wubaric/quiet
2. Press the "Go fullscreen" button

What is the expected behavior?
The page should not go into fullscreen, since the Fullscreen API has been disabled via this header:

feature-policy: { "fullscreen": [] }

According to Chrome Platform Status [1], Feature Policy is now enabled in Chrome.

[1]: https://www.chromestatus.com/feature/5694225681219584

What went wrong?
The page went into fullscreen.

Did this work before? No 

Does this work in other browsers? N/A

Chrome version: Version 60.0.3112.78 (Official Build) (64-bit)  Channel: stable
OS Version: 10.0
Flash Version:
 
Cc: iclell...@chromium.org
Components: Blink>FeaturePolicy
ian: Any thoughts? 
The header is disabled (we elected not to ship that part) in M60; we had several long discussions about the syntax and eventually decided that to avoid burning in the JSON format if we were not going to standardize on it, we would not parse that.

We're actually moving very quickly to a csp-inspired format which will apply to both the header and the <iframe allow> attribute. We're aiming for M62 support for that.

I'll update chromestatus.com with the actual state-of-the-world.
Thanks for the update. This bug can be closed.

Comment 4 by hdodda@chromium.org, Jul 28 2017

Status: WontFix (was: Unconfirmed)
As per comment #3, closing this issue . Please feel free to raise a new issue if any issues faced in latest chrome channels.

Thanks!

Sign in to add a comment