Cross-Origin Read Blocking is too aggressive in v73
Reported by
kurtext...@gmail.com,
Today
(7 hours ago)
|
|||
Issue description
Chrome Version : 73.0.3673.0 and 73.0.3679.0
URLs (if applicable) :
Other browsers tested:
Add OK or FAIL, along with the version, after other browsers where you
have tested this issue:
Safari:
Firefox:
Edge:
What steps will reproduce the problem?
(1) Download extension: https://github.com/kurtextrem/Youtube-Description-For-Gmail/blob/master/src/contentscript.js (https://chrome.google.com/webstore/detail/youtube-description-for-g/embohholcgoomfkcgighhokmnpebcoel)
(2) Goto Gmail, open a YT notification. Or do a fetch from Gmail to e.g. "https://www.youtube.com/attribution_link?a=FJ9IAUmE84_jgMoD&u=/watch%3Fv%3DWYPpjM0RyyM%26feature%3Dem-uploademail"
(3) Look at the dev tools
What is the expected result?
Request isn't blocked
What happens instead?
Request is blocked, with the message "Cross-Origin Read Blocking (CORB) blocked cross-origin response https://www.youtube.com/watch?v=5-yQkP5O_1o&feature=em-uploademail with MIME type text/html. See https://www.chromestatus.com/feature/5629709824032768 for more details."
("https://www.youtube.com/attribution_link?a=FJ9IAUmE84_jgMoD&u=/watch%3Fv%3DWYPpjM0RyyM%26feature%3Dem-uploademail" is forwarded to "https://www.youtube.com/watch?v=5-yQkP5O_1o&feature=em-uploademail")
Please provide any additional information below. Attach a screenshot if
possible.
This didn't happen in v72. I'm pretty sure it worked in v73.0.3664.3.
,
Today
(6 hours ago)
,
Today
(6 hours ago)
|
|||
►
Sign in to add a comment |
|||
Comment 1 by lukasza@chromium.org
, Today (6 hours ago)Cc: rdevlin....@chromium.org
Components: Platform>Extensions Internals>Sandbox>SiteIsolation
Owner: lukasza@chromium.org