New issue
Advanced search Search tips

Issue 812339 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Feb 2018
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

Chrome will not let me download file using file:// but exact link in DevTools console works

Reported by nshill...@dovetailsoftware.com, Feb 14 2018

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36

Steps to reproduce the problem:
1. click hyperlink on a web page with URL of: file://servername/folder1/folder2/file.docx - Chrome does not download the file
2. Manually enter the above URL into address bar - Chrome downloads the file
3. Open DevTools and click hyperlink to same URL (from the "not allowed to load local resource" error - Chrome downloads the file

What is the expected behavior?
Any file download would be blocked for security reasons

What went wrong?
I was unable to download the file by clicking hyperlink on a web page, but was able to copy link address and paste into address bar and download, as well as open DevTools and click the URL in the error message and download it.

SO, where is the protection for this?

Did this work before? N/A 

Chrome version: 64.0.3282.167  Channel: n/a
OS Version: 7
Flash Version:
 
Components: UI>Browser>Navigation
Status: WontFix (was: Unconfirmed)
This is working as expected.

The browser restricts navigation to file:// URIs (and chrome:// uris, etc) from web content, but does not restrict navigations that are initiated by the user from a browser context (e.g. using the omnibox).
Project Member

Comment 2 by sheriffbot@chromium.org, May 24 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment