Closed Bug 1654139 Opened 4 years ago Closed 4 years ago

mixed download blocking works

Categories

(Core :: DOM: Security, defect, P2)

defect

Tracking

()

RESOLVED DUPLICATE of bug 1660969
Tracking Status
firefox-esr68 --- unaffected
firefox-esr78 --- unaffected
firefox78 --- unaffected
firefox79 --- unaffected
firefox80 --- disabled
firefox81 --- disabled

People

(Reporter: jan, Assigned: sstreich)

References

(Blocks 1 open bug, Regression)

Details

(Keywords: nightly-community, regression, Whiteboard: [domsecurity-active])

Attachments

(1 file)

Actual:

  1. I opened https://packages.debian.org/testing/libfreetype6 and clicked on the link
    [freetype_2.10.2+dfsg-2.debian.tar.xz] multiple times.
  2. Nothing happened.
  3. Then I opened Chromium and the download worked.
  4. 10 minutes later I searched for the cause and found this pref I had forgotten about.

Expected:
Not nothing.
a) Some dialog: "You are not able to download this file insecurely"
b) upgrade-insecure-requests: bug 1601408 - but for files.

I guess we log to console, but ultimately some better indication would be better.

Basti, can we do something about it?

Assignee: nobody → sstreich
Severity: -- → S3
Status: NEW → ASSIGNED
Flags: needinfo?(sstreich)
Priority: -- → P2
Whiteboard: [domsecurity-active]

Yes, about 10% of all downloads are mixed content according to telemetry, i'll add a dialog option for users to choose :)

Flags: needinfo?(sstreich)

We've received a similar report in https://github.com/webcompat/web-bugs/issues/55387.

When trying to download a file on https://www.mysonicwall.com/muir/ui/downloadcenter, nothing happens (note that an account is needed to access the page). It is possible to download the file in Chrome.

No errors are thrown in the console on this site when attempting this download. Interestingly, if I try it in a codepen reduced test case with the same file, the "Blocked loading mixed active content" message is thrown.

Reproduced this issue also on https://www.thinkbroadband.com/download - tested on Windows 7 and Mac OS X 10.15 using the latest Nightly 80.0a1 - the Opening dialog is not displayed when trying to download any file.

OS: Linux → All
Hardware: x86_64 → All
Summary: mixed download blocking works on packges.debian.org → mixed download blocking works

A new indicator was added in bug 656296.

Sorry, correct ID is bug 1656296 for the indicator.

Closing this since we now have an indicator and also the option to unblock :)

Status: ASSIGNED → RESOLVED
Closed: 4 years ago
Resolution: --- → DUPLICATE
Has Regression Range: --- → yes
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: