Closed Bug 1863286 Opened 1 year ago Closed 1 year ago

Schemeless HTTPS-First overrides HTTPS-Only in identity pane

Categories

(Core :: DOM: Security, defect)

defect

Tracking

()

VERIFIED FIXED
121 Branch
Tracking Status
firefox-esr115 --- unaffected
firefox119 --- unaffected
firefox120 --- wontfix
firefox121 --- verified

People

(Reporter: maltejur, Assigned: maltejur)

References

(Regression)

Details

(Keywords: regression)

Attachments

(1 file)

To reproduce:

  1. Enable both dom.security.https_first_schemeless and dom.security.https_only_mode
  2. Visit http://https-everywhere.badssl.com/
  3. Check the identity pane (lock icon)

Expected: We see the HTTPS-Only exception UI
Actually: The HTTPS-Only exception UI is hidden as the identity pane thinks this was a schemeless upgrade

Set release status flags based on info from the regressing bug 1812192

Pushed by fbraun@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/39e7e0a18465 Schemeless HTTPS-First overrides HTTPS-Only in identity pane r=freddyb
Status: ASSIGNED → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
Target Milestone: --- → 121 Branch
Blocks: 1863281

The patch landed in nightly and beta is affected.
:mjurgens, is this bug important enough to require an uplift?

  • If yes, please nominate the patch for beta approval.
  • If no, please set status-firefox120 to wontfix.

For more information, please visit BugBot documentation.

Flags: needinfo?(mjurgens)
Flags: needinfo?(mjurgens)
Flags: qe-verify+

Verified that "Automatically upgrade this site to a secure connection" is not displayed before the fix in Win10x64 using FF build 120.0, but displayed after fix on Win10x64/Mac14 using FF build 121.0b4.

Status: RESOLVED → VERIFIED
Flags: qe-verify+
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: