New issue
Advanced search Search tips

Issue 868365 link

Starred by 1 user

Issue metadata

Status: Assigned
Owner:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Bug



Sign in to add a comment

When A CSP policy blocks a form redirect, dev tools show the request as pending

Reported by gabe.cas...@uphabit.com, Jul 27

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.99 Safari/537.36

Steps to reproduce the problem:
1. Visit a website with a form that is a get to the same origin, and a CSP policy of form-action 'self'

2. Have the response to that form be a 302 Found to a different origin

What is the expected behavior?
The network tab of the dev tools should show 2 requests

1. The form request completed as with a status 302, and all the relevant data
2. A request to the redirected origin with a status of (blocked:csp)

There is a console error showing
Refused to send form data to '<OTHER ORIGIN>' because it violates the following Content Security Policy directive: "form-action 'self'".

What went wrong?
Instead it shows the form request as being stuck pending, and dose show the console error

Did this work before? N/A 

Chrome version: 67.0.3396.99  Channel: n/a
OS Version: OS X 10.13.6
Flash Version:
 
Screen Shot 2018-07-27 at 10.11.42 AM.png
350 KB View Download
Owner: caseq@chromium.org
Status: Assigned (was: Unconfirmed)
Components: -Platform>DevTools Platform>DevTools>Network
Owner: jarhar@chromium.org

Sign in to add a comment