New issue
Advanced search Search tips

Issue 809823 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Feb 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Windows , Chrome , Mac
Pri: 1
Type: Bug-Security

Blocking:
issue 776896



Sign in to add a comment

Make chrome://view-http-cache use WebUI bindings

Project Member Reported by dpa...@chromium.org, Feb 7 2018

Issue description

Context https://bugs.chromium.org/p/chromium/issues/detail?id=776896 (see comment 12).

CC'ing OWNERs.
 
Blocking: 776896
The context bug is access restricted.
Thanks for the heads up. Working on getting the right permissions, will ping this thread soon, to try again.
Project Member

Comment 4 by sheriffbot@chromium.org, Feb 7 2018

Labels: M-64
Project Member

Comment 5 by sheriffbot@chromium.org, Feb 7 2018

Labels: -Pri-2 Pri-1
Components: UI>Browser>WebUI
Owner: eroman@chromium.org
Status: Assigned (was: Available)
Eric, can you please take a look or help with an owner.
Without access to the original bug, I don't think we can adequately approach this, or write regression tests.
Added you mmenke@, please add others as needed.
Summary: Make chrome://view-http-cache use WebUI bindings (was: Convert chrome://view-http-cache to a proper WebUI page.)
And, for the record "a proper WebUI page" is defined as one with WebUI bindings.  Not sure if we have to use WebUI to deliver the response body - if so, that requires either modifying the WebUI interface itself, or completely reworking the cache pages to load data via scripts, since WebUI only manages static HTML/JS/CSS, I believe (They can load data via WebUI calls, but the HTML itself is static).
Please add me to the context bug.

(I would request that the cc list for this bug be pruned to people who have access to the context bug; otherwise you're spamming for no purpose.)

Pruning...
Cc: -davidben@chromium.org -zhongyi@chromium.org -xunji...@chromium.org -jkarlin@chromium.org -pauljensen@chromium.org -mef@chromium.org -juliatut...@chromium.org -rch@chromium.org -jri@chromium.org -gavinp@chromium.org -b...@chromium.org -asanka@chromium.org -rsleevi@chromium.org -mattm@chromium.org -agl@chromium.org -cbentzel@chromium.org morlovich@chromium.org
[+morlovich], [-everyone not on the other bug]
Cc: -rdsmith@chromium.org
Project Member

Comment 14 by sheriffbot@chromium.org, Feb 21 2018

eroman: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: Disable-Nags
Project Member

Comment 16 by bugdroid1@chromium.org, Feb 21 2018

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/6ebc11f6f6d112e4cca5251d4c0203e18cd79adc

commit 6ebc11f6f6d112e4cca5251d4c0203e18cd79adc
Author: Eric Roman <eroman@chromium.org>
Date: Wed Feb 21 19:32:24 2018

Remove chrome://view-http-cache.

This was also aliased by chrome://cache.

TBR=palmer@chromium.org,hubbe@chromium.org

Bug:  811956 ,  809823 
Cq-Include-Trybots: master.tryserver.chromium.linux:closure_compilation;master.tryserver.chromium.linux:linux_mojo
Change-Id: I2187a3956d913f8f110b0f7b5296e84beb2a82ac
Reviewed-on: https://chromium-review.googlesource.com/917303
Commit-Queue: Eric Roman <eroman@chromium.org>
Reviewed-by: Eric Roman <eroman@chromium.org>
Reviewed-by: John Abd-El-Malek <jam@chromium.org>
Reviewed-by: Matt Menke <mmenke@chromium.org>
Cr-Commit-Position: refs/heads/master@{#538186}
[modify] https://crrev.com/6ebc11f6f6d112e4cca5251d4c0203e18cd79adc/chrome/browser/browser_about_handler.cc
[modify] https://crrev.com/6ebc11f6f6d112e4cca5251d4c0203e18cd79adc/chrome/browser/browser_about_handler_unittest.cc
[modify] https://crrev.com/6ebc11f6f6d112e4cca5251d4c0203e18cd79adc/chrome/browser/net/network_context_configuration_browsertest.cc
[modify] https://crrev.com/6ebc11f6f6d112e4cca5251d4c0203e18cd79adc/chrome/browser/resources/net_internals/http_cache_view.html
[modify] https://crrev.com/6ebc11f6f6d112e4cca5251d4c0203e18cd79adc/chrome/common/webui_url_constants.cc
[modify] https://crrev.com/6ebc11f6f6d112e4cca5251d4c0203e18cd79adc/chrome/common/webui_url_constants.h
[modify] https://crrev.com/6ebc11f6f6d112e4cca5251d4c0203e18cd79adc/content/browser/BUILD.gn
[delete] https://crrev.com/421a0bb636d7fe67e4712a71c85c92c101c42268/content/browser/net/view_http_cache_job_factory.cc
[delete] https://crrev.com/421a0bb636d7fe67e4712a71c85c92c101c42268/content/browser/net/view_http_cache_job_factory.h
[modify] https://crrev.com/6ebc11f6f6d112e4cca5251d4c0203e18cd79adc/content/browser/webui/url_data_manager_backend.cc
[delete] https://crrev.com/421a0bb636d7fe67e4712a71c85c92c101c42268/content/browser/webui/web_ui_browsertest.cc
[modify] https://crrev.com/6ebc11f6f6d112e4cca5251d4c0203e18cd79adc/content/browser/webui/web_ui_url_loader_factory.cc
[modify] https://crrev.com/6ebc11f6f6d112e4cca5251d4c0203e18cd79adc/content/public/common/url_constants.cc
[modify] https://crrev.com/6ebc11f6f6d112e4cca5251d4c0203e18cd79adc/content/public/common/url_constants.h
[modify] https://crrev.com/6ebc11f6f6d112e4cca5251d4c0203e18cd79adc/content/test/BUILD.gn
[modify] https://crrev.com/6ebc11f6f6d112e4cca5251d4c0203e18cd79adc/media/cast/net/udp_socket_client_unittest.cc
[modify] https://crrev.com/6ebc11f6f6d112e4cca5251d4c0203e18cd79adc/services/network/BUILD.gn
[delete] https://crrev.com/421a0bb636d7fe67e4712a71c85c92c101c42268/services/network/cache_url_loader.cc
[delete] https://crrev.com/421a0bb636d7fe67e4712a71c85c92c101c42268/services/network/cache_url_loader.h
[modify] https://crrev.com/6ebc11f6f6d112e4cca5251d4c0203e18cd79adc/services/network/network_context.cc
[modify] https://crrev.com/6ebc11f6f6d112e4cca5251d4c0203e18cd79adc/services/network/network_context.h
[modify] https://crrev.com/6ebc11f6f6d112e4cca5251d4c0203e18cd79adc/services/network/public/mojom/network_service.mojom

Status: Fixed (was: Assigned)
Project Member

Comment 18 by sheriffbot@chromium.org, Feb 22 2018

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Labels: -M-64 M-66
Project Member

Comment 20 by sheriffbot@chromium.org, May 31 2018

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment