New issue
Advanced search Search tips

Issue 794468 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 778974
Owner: ----
Closed: Dec 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Bug



Sign in to add a comment

HSTS Preload should not effect domains that resolve to localhost.

Reported by tom.faws...@gmail.com, Dec 13 2017

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.36

Steps to reproduce the problem:
Try and browse to a .dev domain hosted locally (ie in a development environment)

What is the expected behavior?
This should obey /etc/hosts before applying HSTS preload rules.

What went wrong?
.dev is now part of the HSTS preload list, now users have to type 

Did this work before? N/A 

Does this work in other browsers? Yes

Chrome version: 63.0.3239.84  Channel: stable
OS Version: OS X 10.12.6
Flash Version: N/A

I understand that the intent here is to improve user safety - but those that are editing their hosts files and using local domains generally know what they're doing.
 
Components: -Blink>Network Internals>Network>DomainSecurityPolicy
Mergedinto: 778974
Status: Duplicate (was: Unconfirmed)

Sign in to add a comment