New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 859595 link

Starred by 3 users

Issue metadata

Status: Untriaged
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug
Team-Security-UX



Sign in to add a comment

Repeated notification permission requests from subdomains in same tab

Project Member Reported by johnidel@chromium.org, Jul 2

Issue description

Chrome Version: 	67.0.3396.99 
OS: Linux/Android/...

What steps will reproduce the problem?
(1) Clear notification permissions for *.kungfoo.net in content settings.
(2) Navigate to https://cr.kungfoo.net/click_jacking/permissions/loop.html
(3) Click block permissions

Some sites are requesting notification permissions in the browser. When the request is denied, They navigate to a new subdomain running the same script, asking for permissions once again, which is a relatively abusive behavior.





Please use labels and text to provide additional information.

If this is a regression (i.e., worked before), please consider using the
bisect tool (https://www.chromium.org/developers/bisect-builds-py) to help
us identify the root cause and more rapidly triage the issue.

For graphics-related bugs, please copy/paste the contents of the about:gpu
page at the end of this report.


 
Issue 859627 has been merged into this issue.
Cc: raymes@chromium.org
Labels: Needs-Feedback
This just pops up two prompts for me. Is that the PoC WAI? Could you attach a screencast of what you're seeing?

Nevertheless, from the sounds of it, I'm not sure there's much we could do about it. Chrome can't tell the difference between multiple domains colluding to the annoy the user and independent domains legitimately asking for permissions.
Cc: dominickn@chromium.org
I think Dom was looking at this on Android.
Cc: peter@chromium.org awdf@chromium.org
Sadly, there's not that much we can do within the browser for this. Our Crowd Consent project was designed to tackle this sort of bad behaviour, but we haven't been able to advance it due to being reorg'd.

+notifications team - this is another report on the case we discussed earlier this year of a site redirecting to multiple subdomains when permission isn't granted.

Sign in to add a comment