New issue
Advanced search Search tips

Issue 816189 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Feb 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Compat



Sign in to add a comment

CORS problem when source is same, but with or without leading www

Reported by keikl...@gmail.com, Feb 25 2018

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.186 Safari/537.36

Example URL:
Bespoke mapping app (we can discuss access)

Steps to reproduce the problem:
1. KML file with icon url as https://www.xxx.com/icon.png
2. User starts app with https://xxx.com/yyy.php
3. Blocked access to icons due to CORS (app has * access)

What is the expected behavior?
Icons should show.

What went wrong?
Icons are now shown, and the console shows CORS issues.

Does it occur on multiple sites: N/A

Is it a problem with a plugin? No 

Did this work before? Yes Unclear, probably Chrome <v54.

Does this work in other browsers? Yes

Chrome version: 64.0.3282.186  Channel: stable
OS Version: 10.0
Flash Version: 

The mapping app is Cesium, loading a KML file.
 
Components: Blink>SecurityFeature>CORS
Labels: Needs-Triage-M64
Cc: vamshi.kommuri@chromium.org
Labels: Triaged-ET Needs-Feedback
Thanks for filing the issue!

Checked the issue on reported chrome version 64.0.3282.186 using Windows 10 with the below mentioned steps.
1. Launched chrome
2. Navigated to https://www.xxx.com/icon.png
We are unable to navigate to the given URL, attaching the screen shot of the same.

@Reporter: Could you please have a look at the screen shot and let us know if any additional tasks to be done in order to check/reproduce the issue.
816189.png
7.8 KB View Download

Comment 4 by jochen@chromium.org, Feb 27 2018

Status: WontFix (was: Unconfirmed)
xxx.com and www.xxx.com are different origins.

If you want users to be able to start at xxx.com but all your resources point to www.xxx.com. configure your server to redirect users from xxx.com to www.xxx.com

Please feel free to reopen if you have repro steps, and another browser (e.g. Firefox) allows access.

Comment 5 by keikl...@gmail.com, Feb 27 2018

Ok. New to me, but some logic in spite of its user-unfriendliness..  Now see that Firefox complains too, and the code will be changed. 

Kjell 

 

 

From: joc… via monorail [mailto:monorail+v2.113376574@chromium.org] 
Sent: Tuesday, 27 February, 2018 10:00
To: keikland@gmail.com
Subject:  Issue 816189  in chromium: CORS problem when source is same, but with or without leading www

Sign in to add a comment