chrome-error:// URLs are marked insecure |
||
Issue descriptionNote: only works with marking http as insecure. What steps will reproduce the problem? 1. Visit a nonexistent URL in an incognito browser (http://nonexistent.example.com will work) 2. Look at the omnibox What is the expected result? Since chrome-error:// pages are internal to chrome, I'd expect them to be secure. What happens instead of that? The omnibox reads "Not Secure" in the omnibox, which is a bit disconcerting. Alex, assigning this to you for now, since you added the chrome-error:// scheme. Feel free to reassign as appropriate.
,
Sep 29 2017
Yeah, this is kinda weird. Fixing it on iOS is going to be annoying, but https://chromium-review.googlesource.com/#/c/chromium/src/+/691237 at least fixes it on desktop/Android.
,
Sep 30 2017
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/a04c72aaf1051817f76d2f41bf0ef1ee1777ddf8 commit a04c72aaf1051817f76d2f41bf0ef1ee1777ddf8 Author: Emily Stark <estark@google.com> Date: Sat Sep 30 23:28:32 2017 Do not show Not Secure chip on incognito error pages It's confusing/unnecessary to show Not Secure on http://nonexistent.test in Incognito mode, so this CL gives GetSecurityInfo() a way to distinguish error pages and not mark them as Not Secure. The fix isn't implemented on iOS yet because it's a bit tricky to tell if we're on an error page (have to set up a WebStateObserver and track navigations). Bug: 760647 Change-Id: Ifdfdf7bd2546f79efcb354437b829fdeb4323d53 Reviewed-on: https://chromium-review.googlesource.com/691237 Commit-Queue: Emily Stark <estark@chromium.org> Reviewed-by: Eric Lawrence <elawrence@chromium.org> Cr-Commit-Position: refs/heads/master@{#505474} [modify] https://crrev.com/a04c72aaf1051817f76d2f41bf0ef1ee1777ddf8/chrome/browser/ssl/security_state_tab_helper_browser_tests.cc [modify] https://crrev.com/a04c72aaf1051817f76d2f41bf0ef1ee1777ddf8/chrome/browser/ssl/ssl_browser_tests.cc [modify] https://crrev.com/a04c72aaf1051817f76d2f41bf0ef1ee1777ddf8/components/security_state/content/content_utils.cc [modify] https://crrev.com/a04c72aaf1051817f76d2f41bf0ef1ee1777ddf8/components/security_state/core/security_state.cc [modify] https://crrev.com/a04c72aaf1051817f76d2f41bf0ef1ee1777ddf8/components/security_state/core/security_state.h [modify] https://crrev.com/a04c72aaf1051817f76d2f41bf0ef1ee1777ddf8/components/security_state/core/security_state_unittest.cc |
||
►
Sign in to add a comment |
||
Comment 1 by alex...@chromium.org
, Sep 27 2017Owner: est...@chromium.org