New issue
Advanced search Search tips

Issue 908506 link

Starred by 3 users

Issue metadata

Status: Assigned
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug
Team-Security-UX



Sign in to add a comment

Download links pasted into NTP page omnibox are shown as insecure

Project Member Reported by brucedaw...@chromium.org, Nov 26

Issue description

Chrome Version: Version 70.0.3538.110 (Official Build) (64-bit)
OS: Windows 10 1709

While transitioning my website's downloads from FTP to  HTTPS I wanted to test the new URLs in as many ways as possible. One way was to create a new tab and then paste the download URL into the omnibox. When I hit enter after pasting in the URL (https://www.cygnus-software.com/ftp_pub/fxsetup64.msi) the insecure indicator (i) is shown in the omnibox.

This gives the impression that the download link is insecure. Or maybe it is referring to the NTP page itself. Neither interpretation makes much sense but the overall impression is that something is wrong.

After discussion with elawrence@ I suspect that this is actually just a UI glitch. It would be nice to get it fixed to avoid confusion.

My downloads page is at https://www.cygnus-software.com/downloads/downloads.htm

What steps will reproduce the problem?
(1) Ctrl+T
(2) Paste https://www.cygnus-software.com/ftp_pub/fxsetup64.msi into the omnibox and hit enter
(3) Note that the insecure indicator (i) is shown in the omnibox

What is the expected result? No insecure indicator

What happens instead? Insecure indicator.

 
InsecureDownload.PNG
25.1 KB View Download
This reproduces as far back as Chrome 52, so it's at least not a regression.

If you're on a Chrome url (e.g. chrome://settings) when you hit enter, the download starts and the navigation-abort restores the "Chrome" badge and the Chrome URL to the omnibox. Perhaps the same special case should exist for the New Tab Page scenario. 
Chrome52.png
11.5 KB View Download
Owner: cthomp@chromium.org
Status: Assigned (was: Untriaged)
Yeah, the case for settings described in #1 matches the behavior in regular sites, so it seems like the right behavior. Chris, I'll throw this one your way but feel free to reassign or deassign and mark as available as appropriate. Thanks.

Sign in to add a comment