New issue
Advanced search Search tips

Issue 778198 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 766091
Owner: ----
Closed: Oct 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Bug-Regression



Sign in to add a comment

Unexpected HSTS redirect for domain with different TLD

Reported by m...@skotty.io, Oct 25 2017

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.9 Safari/537.36

Example URL:
http://skotty.dev:1703/

Steps to reproduce the problem:
1. Set up hosts-file record for "127.0.0.1" to "skotty.dev"
2. Set up basic HTTP-server listening on port 1703
3. Try to access http://skotty.dev:1703

What is the expected behavior?
Chrome should open the requested URL with its specific port.

What went wrong?
HSTS is triggered, page can't be loaded because the server does not support HTTPS.

I tried this on a second system and the same thing happened.

Did this work before? Yes Version 61.0.3163.100 (Official Build) (64-bit)

Chrome version: 63.0.3239.9  Channel: dev
OS Version: OS X 10.13.1
Flash Version: 

The "skotty.io"-domain is on the preload HSTS-list, which might cause HSTS to be triggered.
 
chrome-net-export-log.json
88.2 KB View Download

Comment 1 by mmenke@chromium.org, Oct 25 2017

Components: -Internals>Network Internals>Network>DomainSecurityPolicy
Mergedinto: 766091
Status: Duplicate (was: Unconfirmed)
.dev is a real TLD that was recently added to the HSTS preload list, all domains under .dev now use HSTS. You should use a reserved TLD (see RFC 2606) for local development/testing (e.g. .test or .localhost).

The HSTS redirect for skotty.dev is intended behaviour because of the HSTS preload for the .dev TLD.

Comment 3 by m...@skotty.io, Oct 25 2017

Thanks!

Sign in to add a comment