New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 877897 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Sep 14
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug



Sign in to add a comment

Captcha is not visible when referrer - no-referrer

Reported by mveer.ja...@gmail.com, Aug 27

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36

Steps to reproduce the problem:
1. Apply referrer - no referrer in web.config of a web project
2. Get the ASP.net captch from Package
Package details - id="CaptchaMvc.Mvc4" version="1.5.0" targetFramework="net45"

What is the expected behavior?
Captcha should visible 

What went wrong?
Captcha is not visible

Did this work before? N/A 

Chrome version: 68.0.3440.106  Channel: stable
OS Version: 10.0
Flash Version: 

visible on IE/EDGE/Safari. We are having a forgot password page with captcha information on it.
 
Captach Network requrest.PNG
56.2 KB View Download
Captcha.PNG
31.9 KB View Download
Labels: Needs-Triage-M68
Components: -Platform>DevTools Internals>Network
Looks like a network bug, not a devtools bug.
Labels: Needs-Feedback
I suspect this is an issue with the ASP.net captcha server, however if you can attach a net-internals as described at https://dev.chromium.org/for-testers/providing-network-details, we can check and see if there's an issue in the network stack.
Please find the chrome network statck.
chrome-net-export-log.json
77.1 KB View Download
this issue is not network bug as issue is only produciable on chrome. It is working on IE/Edge
Project Member

Comment 6 by sheriffbot@chromium.org, Aug 28

Cc: svaldez@chromium.org
Labels: -Needs-Feedback
Thank you for providing more feedback. Adding the requester to the cc list.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: Needs-Feedback
I don't think there's any actionable information here - there are no network errors.  We aren't sending referrer headers, as desired.  Think you're going to need to figure out why your script isn't working when we're not sending referrers, and only then can we determine if it's a Chrome issue.
our ASP.net code is sending the captcha if browser is IE/Edge it does means our script is working fine but in case of chrome, captcha is not visible. If i keep the referrer-policy other than no-referrer, it works in chrome.
Project Member

Comment 9 by sheriffbot@chromium.org, Aug 30

Cc: mmenke@chromium.org
Labels: -Needs-Feedback
Thank you for providing more feedback. Adding the requester to the cc list.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Team Please find the attached POC.
Captcha.7z
22.5 MB Download
Unfortunately, I can't download, build, and run code from untrusted sources (Particularly ones that contain pre-compiled binaries, like that project does).  Digging into a large third party project for something that may or may not be a Chrome issue also isn't something we can reasonably spend time on - one thing to look at a repro, quite another to download and build code.
Labels: Needs-Feedback
To echo what Matt said, that is a giant amount of code there. The NetLog shows a successful request to /DefaultCaptcha/Generate?t=900d77534de644b2b8f0674ab9723a61. And indeed your screenshots from DevTools show something similar.

That suggests the issue is elsewhere. Perhaps the server is not giving back a valid image, perhaps it's not being incorporated into the site properly, etc.

If you can give us a URL to look at, that might make more progress. If not, I would suggest looking into your server logs or inspecting the DOM in DevTools to figure out what's wrong with the image in question.
Status: WontFix (was: Unconfirmed)
It sounds like a server-side failure.

It is my understanding that IE/Edge don't support the Referrer-Policy response header. So it is not surprising that they would behave as when the header is omitted.

My suggestion is to continue debugging the client/server interaction and try to reduce this to a single request.

Unfortunately there isn't much else we can do on the Chrome side with the information we have.

Sign in to add a comment