Closed Bug 1669424 Opened 4 years ago Closed 4 years ago

HTTPS-Only Mode: Exception should be propagated through redirects

Categories

(Core :: DOM: Security, defect, P3)

defect

Tracking

()

RESOLVED INVALID

People

(Reporter: ckerschb, Unassigned)

References

(Blocks 1 open bug)

Details

(Whiteboard: [domsecurity-backlog1])

Attachments

(1 file)

Adding an exemption to a particular side should probably be propagated throughout redirects, otherwise the only possible way to view a page is to disable HOM entirely.

STRs:

Priority: -- → P3
Whiteboard: [domsecurity-backlog1]
Severity: -- → S3
Attached image redirect-comparison.png

Exceptions get propagated throughout redirects, the issue with the mentioned site is that the redirects for the HTTP version are different than those for the HTTPS version. Latter redirects are sadly also incorrect, which caused the issue.

Since we can't infer if these redirects are unintended we can't fix this issue and similar ones.

Status: NEW → RESOLVED
Closed: 4 years ago
Resolution: --- → INVALID
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: