Closed Bug 1844742 Opened 1 year ago Closed 4 months ago

Expose HTTPS-First in Settings

Categories

(Core :: DOM: Security, enhancement)

enhancement

Tracking

()

RESOLVED WONTFIX

People

(Reporter: maltejur, Assigned: maltejur)

References

(Blocks 1 open bug)

Details

(Whiteboard: [domsecurity-active])

Attachments

(3 obsolete files)

Attached image Screenshot_20230721_104558.png (obsolete) —

Since HTTPS-First is already enabled by default in Private Browsing, it would only make sense to let the user have some more control over it in the settings. Currently, this is only possible via about:config.

There also still is the open terminology question about how "HTTPS-First" should be called for the user. Having both "HTTPS-Only" and "HTTPS-First", which do two very similar things could be confusing. So we could consider calling both "HTTPS-Only", and only have a checkbox which allows you to enable or disable "silent fallbacks to HTTP", which would correspond to HTTPS-First. I have attached an experimental implementation of how this could look like, but keep in mind that this is just an early exploration of how these settings could look like. This implementation would also have the downside that the user could not enable HTTPS-First everywhere and HTTPS-Only in PBM.

Severity: -- → N/A
Whiteboard: [domsecurity-active]
Attachment #9345025 - Attachment description: WIP: Bug 1844742: Experimental https-only fallback checkbox → WIP: Bug 1844742: Expand HTTPS-Only settings to include HTTPS-First and Schemeless Upgrades r?freddyb
Blocks: 1859850
Duplicate of this bug: 1859850
Attachment #9345025 - Attachment is obsolete: true
Attachment #9345024 - Attachment is obsolete: true
Attachment #9366892 - Attachment is obsolete: true
No longer duplicate of this bug: 1859850

Due to HTTPS-First being standardized as HTTPS Upgrades, we have decided to continue not including a option to toggle it in the settings UI.

As there could still be confusion though by requests being upgraded, even when HTTPS-Only is disabled in the settings, we still want to update the strings for the HTTPS-Only settings to make it a bit clearer what is happening. I have opened Bug 1907517 for that.

See Also: → 1907517
Status: ASSIGNED → RESOLVED
Closed: 4 months ago
Resolution: --- → WONTFIX
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: