New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 817549 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 811440
Owner: ----
Closed: Mar 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Windows , Chrome , Mac , Fuchsia
Pri: 2
Type: Bug-Regression



Sign in to add a comment

XSS Auditor violation reports are no longer sent cross-origin

Reported by scott.he...@gmail.com, Feb 28 2018

Issue description

Chrome Version: 64.0.3282.186
OS Version: All

As a result of https://bugs.chromium.org/p/chromium/issues/detail?id=807304 any XSS auditor report that is sent cross-origin will be blocked. 

The fix was for a bug raised over 3 years ago, I'm not entirely sure it's valid, but has resulted in a useful feature being disabled: https://bugs.chromium.org/p/chromium/issues/detail?id=441275

We were in the process of testing a new capability on https://report-uri.com to collect XSS auditor reports for our customers and this change broke that and introduced errors in the consoles on websites using it. It's also worth nothing that youtube.com and t.co use cross-origin XSS auditor reporting along with other sites.

It'd be great if we could enable cross-origin reports again!
 
Cc: andypaicu@chromium.org mkwst@chromium.org
Components: Blink>SecurityFeature>XSSAuditor
Labels: -Type-Bug -Pri-3 FoundIn-64 OS-Android OS-Chrome OS-Fuchsia OS-Linux OS-Windows Pri-2 Type-Bug-Regression
Status: Untriaged (was: Unconfirmed)
Summary: XSS Auditor violation reports are no longer sent cross-origin (was: XSS auditor reports are not sent cross-origin)
Indeed, I'm unconvinced that disabling of cross origin reporting meaningfully impacted  issue 441275 . 

At the time we landed the cross-origin lockdown, I don't think we had metrics on the usage of cross-origin reporting attributes (e.g. Youtube and Twitter numbers are likely huge) that would have allowed us to notice the real-world impact such a lockdown would create.
Mergedinto: 811440
Status: Duplicate (was: Untriaged)
Hey, please could you give me view/access permission to the linked bug?

Cheers. 

Sign in to add a comment