New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 881948 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 881694
Owner: ----
Closed: Sep 7
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: ----
Type: Bug
Team-Security-UX



Sign in to add a comment

URL bar hides `www` and `m` in the middle of a subdomain hierarchy.

Project Member Reported by lgar...@chromium.org, Sep 7

Issue description

Chrome 71.0.3544.2
macOS 10.13.6

What steps will reproduce the problem?
(1) Visit http://a.www.b.m.example.com

What is the expected result?
The URL bar shows a.www.b.m.example.com or example.com

What happens instead?
The URL bar shows a.b.example.com, even after you highlight it the first time.

I understand the goal is to simplify how subdomains are displayed, but anything other than left truncation attaches the domain to the wrong hierarchy.

I'm initially filing this as a security bug, since a site like m.appspot.com could spoof any other appspot.com subdomain: site.m.appspot.com currently shows as site.appspot.com
(This is not unique to appspot.com .)

Reported by Feross:
https://twitter.com/feross/status/1037818967987912704
 
Screen Shot 2018-09-07 at 11.52.39.png
446 KB View Download
Cc: fer...@gmail.com
It seems that test.m.appspot.com doesn't actually exhibit this on Canary anymore, but test.ww.appspot.com does.
Screen Shot 2018-09-07 at 11.54.27.png
214 KB View Download
Components: -Services>Safebrowsing>VRP -Services>Safebrowsing
Removing SafeBrowsing labels since this is outside of SafeBrowsing's realm.
(Also, hi lgarron@! :)
👋😊
Mergedinto: 881694
Status: Duplicate (was: Unconfirmed)
Thanks!  This is being tracked in  issue 881694 .
Project Member

Comment 6 by sheriffbot@chromium.org, Dec 15

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment