New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 826553 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 527326
Owner: ----
Closed: Mar 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Mac
Pri: 3
Type: Bug



Sign in to add a comment

Chrome should allow redirects to data: URLs

Project Member Reported by domfarolino@gmail.com, Mar 27 2018

Issue description

Chrome Version       : 65.0.3325.162
URLs (if applicable) :
Other browsers tested:
  Add OK or FAIL, along with the version, after other browsers where you
have tested this issue:
     Safari: OK
    Firefox: OK
       Edge: ?

What steps will reproduce the problem?
(1) Navigate to https://hail-industry.glitch.me/

What is the expected result?
You should be redirected to the WHATWG SVG displayed (from a data URL)

What happens instead?
Chrome blocks the redirect saying it is an unsafe redirect, and does not follow-through with the redirect.

Currently, Safari and Firefox allow redirecting to data: URLs, and so do the HTML/Fetch specifications. If Chrome has decided to disallow this for security reasons, perhaps we should open up an issue on the HTML spec re-evaluating the process-a-navigate-fetch [1]

[1]: https://html.spec.whatwg.org/multipage/browsing-the-web.html#process-a-navigate-fetch
 
Description: Show this description
Labels: Needs-Triage-M65
Cc: kkaluri@chromium.org
Labels: Target-67 FoundIn-67 M-67 OS-Linux OS-Mac OS-Windows
Status: Untriaged (was: Unconfirmed)
Able to reproduce the issue on Windows 10, Debian Rodete and Mac 10.13.3 with chrome stable #65.0.3325.181, Beta #66.0.3359.45, Dev #67.0.3381.1, Canary #	67.0.3381.1 and also in earlier version M60-#60.0.3072.0
This is a non-regression issue, hence marking it as untriaged
826553.mp4
562 KB View Download

Comment 4 by ricea@chromium.org, Mar 29 2018

Components: -Blink>Network UI>Browser>Navigation

Comment 5 by creis@chromium.org, Mar 29 2018

Cc: tsepez@chromium.org nick@chromium.org
I think blocking redirects to data URLs was intentional.  nick@ or tsepez@, can you confirm?
I think there's some more context in  issue 272072 , but yes, AFAIK redirects to data URLs are blocked intentionally (see DataProtocolHandler::IsSafeRedirectTarget), and the only case I know of where it's allowed is with extensions via webRequest API.
Mergedinto: 527326
Status: Duplicate (was: Untriaged)
Marking this as a duplicate of Issue 527326. If we want, we can continue discussion there, I did not see this open issue. alexmos@ thanks for the other link too :)

Sign in to add a comment