Open Bug 1562826 Opened 5 years ago Updated 2 years ago

Add test for striking through "https" in the location bar for sites that have mixed active content loaded

Categories

(Firefox :: Security, task, P5)

task

Tracking

()

People

(Reporter: dao, Unassigned)

References

Details

I recently discovered in bug 1562691 that the code that's supposed to strike through "https" was broken. We should have a test for this.

From bug 1562691: Afaik this bug could only manifest on secure pages that load active mixed content after the page finished loading, with mixed content protection disabled through the site identity panel (we block active mixed content by default). That makes this tricky to reproduce, and I'm unsure what the real-world impact is.

Priority: -- → P5
Severity: normal → S3
You need to log in before you can comment on or make changes to this bug.