New issue
Advanced search Search tips

Issue 834441 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: May 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Mac
Pri: 3
Type: Bug



Sign in to add a comment

Users can delete browser history even when the policy prevents it.

Project Member Reported by mheinsohn@chromium.org, Apr 18 2018

Issue description

Chrome Version: 66.0.3359.117
OS: Win10 / maybe all

What steps will reproduce the problem?
(1) Configure the AllowDeletingBrowserHistory policy to prevent deleting browser history.
(2) Go to Settings - Manage Other People. Delete the user profile (if only one, it has the name "You").
(3) All browser history is deleted.

What is the expected result?
Not being able to delete browser history, if policy prevents it.

What happens instead?
All browser history is deleted.

Reference this forum post https://productforums.google.com/forum/#!topic/chrome-admins/46nXDWDRPcY;context-place=forum/chrome-admins
 
Components: Enterprise
Owner: georgesak@chromium.org
Cc: jmukthavaram@chromium.org
Labels: M-66 Needs-Feedback
Thanks for filing the issue.
We are unable to reproduce the issue on Windows 10 Enterprise setup using chrome reported version-66.0.3359.117(stable) & latest dev-67.0.3396.10 as per the steps mentioned in C#0.

User unable to delete history when we Disable 'Enable delete history' policy.

Please find the attached screencast for reference & let us know if we anything to reproduce the issue.

Unable to delete history.mp4
2.0 MB View Download
Read the description again, specifically step (2).

(2) Go to Settings - Manage Other People. Delete the user profile (if only one, it has the name "You").

Yes, chrome://settings/clearBrowserData cannot be used if AllowDeletingBrowserHistory is set. That's not the issue. By deleting their profile, users CAN clear their browsing history.

More detailed steps:
chrome://settings
"People" section
Find and click the "Manage other people" line. (see pic settings.jpg)

That pops up a window showing all user profiles. If only one, it has the name "You". (see pic you.jpg)

Select the three vertical buttons on the upper right to present a popup window with the choice "Remove this person". (see pic delete1.jpg)

Removing the user allows deletion of browser history. (see pic delete2.jpg)

Thus, it is possible to delete browser history even when policy prevents it, by deleting the user profile.
settings.jpg
103 KB View Download
you.jpg
45.1 KB View Download
delete1.jpg
16.1 KB View Download
delete2.jpg
33.8 KB View Download
Cc: georgesak@chromium.org
Labels: -Needs-Feedback Enterprise-Triaged OS-Linux OS-Mac OS-Windows
Owner: ----
Status: Available (was: Untriaged)
Although this is true, we make no hard guarantees for that policy. After all, users can just delete their user profile manually as well, and there's nothing Chrome can do about it.

I will keep this open as P3.

Comment 6 by tozt...@gmail.com, May 1 2018

A non escalated user shouldn't have file system level access to remove their user profile manually so I have have no response to the previous comment.  However there is an expectation, however inaccurate that when AllowDeletingBrowserHistory is set a user shouldn't be able to delete their use profile in 2 clicks circumventing it.  At the very least it would be nice to have a AllowUserPorfileRemoval operating independent or as a dependency to the other,
Status: WontFix (was: Available)
Having a new policy to control profile removal makes sense to me, please open a new bug for that and assign it to me.

But I'll reiterate that determined users can still delete their data, unless there is something else explicitly blocking them from doing so. They don't need elevation, as Chrome is running in user mode, so the profile it's writing is fully owned by that user

I'm closing this as WontFix, feel free to open a new feature request for the other policy.

Sign in to add a comment