New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 899559 link

Starred by 2 users

Issue metadata

Status: Assigned
Owner:
Last visit > 30 days ago
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Mac
Pri: 2
Type: Bug



Sign in to add a comment

Iframe load event fires when blocked by CSP

Reported by signupsa...@gmail.com, Oct 28

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36

Steps to reproduce the problem:
1. Set a CSP that blocks iframe loading (frame-src 'none')
2. Create an iframe and set a load event handler
3. Load the page

What is the expected behavior?
The iframe should use an error event instead of a load event when blocked.

What went wrong?
The iframe uses the load event instead of the error event when blocked.

Did this work before? N/A 

Chrome version: 70.0.3538.77  Channel: stable
OS Version: OS X 10.13.6
Flash Version: 

I'm LITERALLY shaking with anger and may write in my blog and make 3 tweets about this if it's not fixed immediately!  😡

P.S. thank you for your hard work! xoxo
 
iframe_csp_onload.html
326 bytes View Download
Labels: Needs-Triage-M70
Components: -Blink Blink>SecurityFeature>ContentSecurityPolicy
Cc: swarnasree.mukkala@chromium.org
Labels: Triaged-ET Target-72 M-72 FoundIn-71 FoundIn-70 FoundIn-72 OS-Linux OS-Windows
Status: Untriaged (was: Unconfirmed)
Able to reproduce the issue on reported chrome #70.3538.77 and latest chrome #72.0.3596.0 using Windows 10, Ubuntu 17.10 and Mac OS 10.13.6 by following steps as per comment #9.


The behavior is seen from old M-60 builds(#60.0.3112.113). This is a non-regression issue, hence marking it as Untriaged and requesting someone from the dev team to look into the issue.
Thanks.!
Owner: andypaicu@chromium.org
Status: Assigned (was: Untriaged)

Sign in to add a comment