Issue metadata
Sign in to add a comment
|
Strict-Transport-Security does not suppress Mixed Content, leading to confusing DevTools experience
Reported by
potoms....@gmail.com,
Aug 8 2017
|
||||||||||||||||||||||
Issue descriptionUserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.115 Safari/537.36 Steps to reproduce the problem: 1. navigate to https://codecov.io/ 2. open devtools security tab 3. navigate to https://www.npmjs.com/package/url-pattern 4. check that it shows "insecure", look at "non-secure origins", click on "view requests in network panel" What is the expected behavior? there are requests in the filtered view What went wrong? there are no requests in the filtered view. STS took over on the non-https url http://codecov.io/github/snd/url-pattern/coverage.svg?branch=master Should the browser even mark this page as insecure if STS kicks in? Technically it's insecure but it was completely circumvented. Also, the reason why this is marked as insecure is hard to debug as the network panel shows nothing for "domain:codecov.io scheme:http". Did this work before? No Chrome version: 59.0.3071.115 Channel: n/a OS Version: OS X 10.12.6 Flash Version: This npm page is not mine, I just stumbled upon it and wondered why it was marked insecure.
,
Aug 8 2017
I get a 200.
,
Aug 8 2017
Yeah, you should see both, a HTTP request resulting in a 307 "Internal Redirect" and a 200 from the HTTPS endpoint. It's possible that the missing 307 was fixed on a later build.
,
Aug 8 2017
Checked in Canary and it works. Should have done that from the start, my apologies. This issue can be closed.
,
Aug 8 2017
Thanks for verifying! |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by elawrence@chromium.org
, Aug 8 2017Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Summary: Strict-Transport-Security does not suppress Mixed Content, leading to confusing DevTools experience (was: mixed content and strict-transport-security)
39.6 KB
39.6 KB View Download