New issue
Advanced search Search tips

Issue 795678 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 766091
Owner: ----
Closed: Dec 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug-Security



Sign in to add a comment

.dev domain force to https and cann't exckuded in hsts

Reported by toor...@gmail.com, Dec 18 2017

Issue description

UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/63.0.3239.84 Chrome/63.0.3239.84 Safari/537.36

Steps to reproduce the problem:
1. set any *.dev dumain local to local ip
2. put it domain in chrome

What is the expected behavior?
It SHOULD make request to 80 port

What went wrong?
It redirecting to https!

Did this work before? N/A 

Chrome version: 63.0.3239.84  Channel: n/a
OS Version: 16.04
Flash Version: -

deleting dev domain from hsts here:
chrome://net-internals/#hsts
doesn't help.
So, if it stupid protection rule it should way to exclude from this rule. I want make self decision about my personal protection without any fishen pushes.
 
Components: Internals>Network>DomainSecurityPolicy
Mergedinto: 793994
Status: Duplicate (was: Unconfirmed)
Mergedinto: -793994 766091
Project Member

Comment 4 by sheriffbot@chromium.org, Mar 28 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment