New issue
Advanced search Search tips

Issue 923580 link

Starred by 3 users

Issue metadata

Status: Duplicate
Merged: issue 918753
Owner: ----
Closed: Yesterday
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Bug



Sign in to add a comment

Developer tools does not include Origin header

Reported by step...@runsignup.com, Jan 18 (4 days ago)

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36

Steps to reproduce the problem:
1. Host the following HTML on a website.
<html><body><link rel="stylesheet" href="http://cdnjs.runsignup.com/ajax/libs/pushy/1.1.2/css/pushy.min.css" integrity="sha256-gLzuRXjdchL4hw3rJV2qaLx1La3q64na8i+1Ayidcb4=" crossorigin="anonymous" /></body></html>
2.  Go to the page you created.
3.  Open the develop tools.
4.  Reload the page.

What is the expected behavior?
pushy.min.css should load without a CORS issue.

What went wrong?
At step 2, Chrome makes web requests for pushy.min.css and push.min.css.map without an Origin header (I saw this in wireshark).  Chrome then caches this new version, but it doesn't have Vary: Origin, so the next page reload gets a CORS issue (No 'Access-Control-Allow-Origin' header is present on the requested resource.)

Did this work before? N/A 

Chrome version: 71.0.3578.98  Channel: stable
OS Version: OS X 10.14.2
Flash Version: 

This seems like it might be related to CSS with a source map.  Also, the example might not work as we'll likely update our CDN to always return Vary: Origin.  However, if you host the file on CloudFront, you can see the same issue because CloudFront will not add Vary: Origin if no Origin is passed in.  You can probably replicate on other CDNs if they don't set Vary: Origin when there's no Origin header.
 

Comment 1 by susan.boorgula@chromium.org, Jan 20 (2 days ago)

Labels: Needs-Triage-M71

Comment 2 Deleted

Comment 3 by l446240525@gmail.com, Yesterday (47 hours ago)

issue 918753

Comment 4 by vamshi.kommuri@chromium.org, Yesterday (43 hours ago)

Cc: vamshi.kommuri@chromium.org
Labels: Triaged-ET
Mergedinto: 918753
Status: Duplicate (was: Unconfirmed)
Thanks for filing the issue!

As the issue seems to be similar to that of Issue 918753, hence merging into it and marking it as Duplicate. Please feel to undupe if not the case.

Comment 5 by step...@runsignup.com, Yesterday (41 hours ago)

It doesn't sound exactly like that issue, but it's very close.  In my case, Disable Cache is always unchecked.  Simply opening the developer tools causes the issue.

Sign in to add a comment