New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 829235 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 829688
Owner:
Last visit > 30 days ago
Closed: Apr 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Chrome , Mac
Pri: 3
Type: Bug

Blocking:
issue 828697



Sign in to add a comment

desktop-pwas: Block mixed content in new OOPIF

Project Member Reported by ortuno@chromium.org, Apr 5 2018

Issue description

Chrome Version: (copy from chrome://version)
OS: (e.g. Win7, OSX 10.9.5, etc...)

What steps will reproduce the problem?
(1) Enable top-document-isolation
(2) Navigate to a PWA with a mixed content iframe e.g. https://marsh-band.glitch.me/
(3) Install PWA
(4) Open PWA

What is the expected result?
Mixed content inside the iframe should have been blocked

What happens instead?
Mixed content inside the iframe is not blocked

The good news is that we will show the location bar with the security indicator showing the site is not secure.

This is happening because we only set the Strict Mixed Content Checking preference for the main frame when the app is launched. We need to set it for all frames inside a Desktop PWA.
 
Labels: M-67
Blocking: 828697
Summary: desktop-pwas: Block mixed content in new OOPIF (was: desktop-pwas: Block mixed content in OOPIF)
Labels: Pri-3
Pushing back to P3 (this is less urgent than the other P2s).
Labels: -M-67 M-68
67 has branched, moving bugs over to 68.

Comment 6 by creis@chromium.org, Apr 26 2018

Cc: creis@chromium.org alex...@chromium.org
Components: Internals>Sandbox>SiteIsolation
Updating based on similarity to  issue 829688 , where a possible fix is being discussed.  Not sure if that will help with this or not.

Comment 7 by ortuno@chromium.org, Apr 26 2018

Mergedinto: 829688
Status: Duplicate (was: Assigned)
Merging since the fix in  issue 829688  will fix this as well.

Sign in to add a comment