New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 856137 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Nov 23
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug



Sign in to add a comment

Violating CSP / Network Reporting API privacy considerations.

Reported by witold.b...@gmail.com, Jun 25 2018

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.87 Safari/537.36

Steps to reproduce the problem:
http://wicg.github.io/reporting/#disable

Read section 11.6, Disabling Reporting, based on "Draft Community Group Report, 8 June 2018" of "Reporting API" of Web Platform Incubator Community Group.

What is the expected behavior?
Chrome respects a user settings, that are exposed in settings UI, to add ability to disable reporting.

PS. I think Reporting API is really pretty well designed, and a good thing, but please follow your own words.

What went wrong?
Violation of a draft standard.

http://wicg.github.io/reporting/#disable

"User agents MUST allow users to disable reporting with some reasonable amount of granularity in order to maintain the priority of constituencies espoused in [HTML-DESIGN-PRINCIPLES]."

See also:
https://tools.ietf.org/html/rfc7469
https://w3c.github.io/webappsec-csp/#cspro-header
https://w3c.github.io/webappsec-csp/#report-to

Did this work before? No 

Chrome version: 67.0.3396.87  Channel: stable
OS Version: 6.3
Flash Version:
 
Probably related to:

https://bugs.chromium.org/p/chromium/issues/detail?id=726634
https://crbug.com/676016

The use of Report-To is not wide spread yet. I checked few high profile sites like facebook.com ,  twitter.com , github.com and none of them is using it yet.

Comment 2 by mef@chromium.org, Jun 25 2018

Cc: dcreager@chromium.org
You can disable all Reporting API uploads for a particular origin (including CSP) via the Background Sync permission.

(Also note that the Reporting implementation has not yet shipped in Chrome stable, so no one is able to use the Report-To header yet.)
Labels: Needs-Triage-M67
Cc: vamshi.kommuri@chromium.org
Labels: Triaged-ET Needs-Feedback
Adding Needs-Feedback label as per comment#3 and requesting reporter to check as per that comment. Any further inputs from your end may be helpful.

Thanks!
Labels: Hotlist-DesktopUIChecked
Status: WontFix (was: Unconfirmed)
**UI mass Triage**
We were unable to find repro steps for this bug as per C#5 & no update for long from reporter . If you have more data to
reproduce this bug or have clear repro steps, please reopen or file a new issue.
Thanks!


Sign in to add a comment