New issue
Advanced search Search tips

Issue 895713 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 731104
Owner: ----
Closed: Oct 17
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

URLBlacklist policy not working as expected

Reported by ay...@coditas.com, Oct 16

Issue description

UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36

Steps to reproduce the problem:
1. Enforce URLBlacklist with url as chrome://extensions/?id=*
2. Navigate to chrome://extensions/?id=nihecfncajkmcfebflmfffpgmbgjnhdf the page is blocked
3. Navigate to chrome://extensions and now click on details of nihecfncajkmcfebflmfffpgmbgjnhdf extension
4. The details page is not opened

What is the expected behavior?
The details page should be blocked irrespective of where do I naviagte to the URLBlacklist url.

What went wrong?
The details page of extension is opened despite of the URLBlacklist as chrome://extensions/?id=*

Did this work before? N/A 

Does this work in other browsers? N/A

Chrome version: 69.0.3497.100  Channel: stable
OS Version: 
Flash Version:
 
Components: Platform>Extensions
 Issue 895706  has been merged into this issue.
Components: Enterprise
Cc: jam@chromium.org atwilson@chromium.org
[jam]:  One of the issues I mentioned.
[atwilson]:  Possible duplicate of  issue 876600 ?
this is not a duplicate of issue https://bugs.chromium.org/p/chromium/issues/detail?id=876600 as that issue talks about blacklisting of extensions and here we are talking about urlBlacklisting.
This is related to https://bugs.chromium.org/p/chromium/issues/detail?id=895702

These two issues talk about how the blocking is bypassed when visiting from internal pages and the blocking takes place only when someone tries to visit the blacklisted url directly.
Mergedinto: 731104
Status: Duplicate (was: Unconfirmed)
Polymer navigations within the same page aren't actually navigations - Javascript is spoofing navigation by modifying the DOM then pushing URLs on the history stack.

URLBlacklisting fundamentally cannot block these pseudo-navigations.

Sign in to add a comment