New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 864690 link

Starred by 2 users

Issue metadata

Status: Assigned
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Chrome , Mac
Pri: 3
Type: Feature



Sign in to add a comment

In DevTools Network panel, HSTS "internal redirect" may be confusing

Project Member Reported by cthomp@chromium.org, Jul 17

Issue description

Currently, Dev Tools exposes the internal implementation detail of how Chrome handles HSTS and lists a request to the http:// site with a "307 Internal Redirect" entry. (In  Issue 863617 , this caused confusion about possible plaintext requests to google.com.) For users who don't understand the internal implementation in Chrome, this may be unnecessarily confusing when setting up HSTS on their sites.

I know in the full network event log these are annotated with "Non-Authoritative-Reason: HSTS". While we might not want to completely gloss over that this internal redirect occurs, would there be a good way to expose that this is expected as part of HSTS in Dev Tools at least?

I've attached a screenshot of what this currently looks like, and steps for reproducing it.

Chrome Version: 69.0.3491.0 (Developer Build) (64-bit)
What steps will reproduce the problem?
(1) Open Dev Tools Network panel
(2) Navigate to http://preloaded-hsts.badssl.com
(3) See a request to "http://preloaded-hsts.badssl.com" with a "307 Internal Redirect" status.
 
devtools-hsts-redirect.png
135 KB View Download
Issue 829132 suggests changing the internal implementation of HSTS to a URL rewrite (although it seems more of a "what if" suggestions), which, if implemented, might also resolve this concern.

 Issue 820304  discusses a related confusion around time taken for redirects (particular 307 Internal Redirect like for HSTS).

Also, cc'ing the reporter of  Issue 863617 .
Cc: masonda...@gmail.com
Components: Platform>DevTools>Network
Owner: eostroukhov@chromium.org
Status: Assigned (was: Untriaged)
Owner: jarhar@chromium.org

Sign in to add a comment