Open Bug 1886790 Opened 2 years ago Updated 8 months ago

CSP frame-ancestor reports are not shown in the devtools network tab

Categories

(DevTools :: Netmonitor, defect, P2)

Firefox 123
defect

Tracking

(Not tracked)

People

(Reporter: jannis, Unassigned, NeedInfo)

References

Details

Attachments

(3 files)

Steps to reproduce:

  • Open devtools
  • Visit a site that embeds an IFrame that sets Content-Security-Policy: frame-ancestors 'none' report-uri <report-uri>
  • Observe the netmonitor

Example URL: https://echo.sectec.rocks/echo/?ecocnt_css=%3Ciframe%20src=%22https://echo.sectec.rocks/echo/?Content-Security-Policy=report-uri%20https://enp8qbj7azvfs.x.pipedream.net;%20frame-ancestors%20%27none%27%22%3E%3C/iframe%3E

Actual results:

No CSP report request can be found in the netmonitor, however a report is send and received at the report-uri.

Expected results:

A CSP report request should be visible in the netmonitor.
In Safari and Chromium the CSP report request is visible in the respective network tabs.
For other CSP directives the CSP report request is also visible in netmonitor in Firefox. For example: https://echo.sectec.rocks/echo/?Content-Security-Policy=report-uri%20https://enp8qbj7azvfs.x.pipedream.net;%20script-src%20%27none%27&ecocnt_js=%3Cscript%3Eabc%3C/script%3E

Thanks for the report jannis.
We can't reproduce on 124 (which is now release). Can you update your Firefox and check if you're still not seeing the request in the Netmonitor?

Type: enhancement → defect
Flags: needinfo?(jannis)
Flags: needinfo?(jannis)

I updated Firefox to 124.0.1 (Build 20240321230221) and still see the same behavior.

No CSP report POST request is visible for the first URL:
https://echo.sectec.rocks/echo/?ecocnt_css=%3Ciframe%20src=%22https://echo.sectec.rocks/echo/?Content-Security-Policy=report-uri%20https://enp8qbj7azvfs.x.pipedream.net;%20frame-ancestors%20%27none%27%22%3E%3C/iframe%3E
See the attached csp-fa-no-csp-report-post-request.png

A CSP report POST request is visible for other CSP violations:
https://echo.sectec.rocks/echo/?Content-Security-Policy=report-uri%20https://enp8qbj7azvfs.x.pipedream.net;%20script-src%20%27none%27&ecocnt_js=%3Cscript%3Eabc%3C/script%3E
See the attached csp-script-csp-post-request.png

In other browsers (e.g., Chrome) a CSP post request is visible for the first URL:
See the attached csp-fa-csp-report-post-request.chrome.png

The error is only with displaying the POST request in the devtools.
The POST request is send correctly as can be observed in the request bin: https://public.requestbin.com/r/enp8qbj7azvfs

Thanks for the additional info, we can reproduce now.

The request is visible in the Browser Toolbox, but we fail to show it in the regular DevTools toolbox. Maybe we are filtering it out in our network observer logic?

Severity: -- → S3
Status: UNCONFIRMED → NEW
Ever confirmed: true
Priority: -- → P3

With the Reporting API being worked on (Bug 1976074), we might want to take a look at this

Whiteboard: [devtools-triage]

We also recently had about missing CSP requests, but that was for worker initiated requests, and I don't think they were showing up in the BrowserToolbox.

See Also: → 2007298

Bomsy offered to take a look at this specific bug

(In reply to Nicolas Chevobbe [:nchevobbe] from comment #7)

With the Reporting API being worked on (Bug 1976074), we might want to take a look at this

For this we will take a look and file another bug if we have the same issue for Reporting API.

Flags: needinfo?(hmanilla)
Priority: P3 → P2
Whiteboard: [devtools-triage]
See Also: → 2013043
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: