New issue
Advanced search Search tips

Issue 894818 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Oct 30
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug
Team-Security-UX



Sign in to add a comment

Cannot undo mixed content exception

Project Member Reported by stelter@google.com, Oct 12

Issue description

Chrome Version: 69.0.3497.100 (Official Build) (64-bit)
OS: Linux

What steps will reproduce the problem?
(1) Open site with mixed content
(2) Warning appears about unsafe scripts (even if violation is caused by a dynamically loaded favicon.ico)
(3) Press "Load unsafe scripts"
(4) Page remembers this setting, no obvious way to block mixed content again.

What is the expected result?
I can revoke this exception from the UI and go back to blocking mixed content.

What happens instead?
I'm stuck with active mixed content on a website forever.
 
Cc: carlosil@chromium.org
Are mixed content settings remembered permanently? I thought they were session based, meaning restarting the browser should clear them. +CC carlosil to confirm.
Yeah, they are session based. I double checked 70 and 72 in case there was a bug with it, but opening https://mixed-script.badssl.com, allowing the script, and then opening it in a new tab results in the scripts being blocked.

stelter: Do you have an example site where the behavior persists across sessions?
Indeed I cant reproduce this on https://mixed-script.badssl.com/ and unfortunately don't remember the website I found this on.

I'll ping/reopen this bug if I run into the issue again. Thanks for looking into it!
Status: WontFix (was: Untriaged)
I'll go ahead and close this one for now, but please do reopen it if you find a site that reproduces. Thanks!

Sign in to add a comment