<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>22262</bug_id>
          
          <creation_ts>2013-06-04 15:51:48 +0000</creation_ts>
          <short_desc>Mixed content / CSP</short_desc>
          <delta_ts>2015-08-11 06:49:01 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WHATWG</product>
          <component>Fetch</component>
          <version>unspecified</version>
          <rep_platform>PC</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>MOVED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>Unsorted</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Anne">annevk</reporter>
          <assigned_to name="Anne">annevk</assigned_to>
          <cc>bruant.d</cc>
    
    <cc>mike</cc>
    
    <cc>mkwst</cc>
          
          <qa_contact>sideshowbarker+fetchspec</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>88624</commentid>
    <comment_count>0</comment_count>
    <who name="Anne">annevk</who>
    <bug_when>2013-06-04 15:51:48 +0000</bug_when>
    <thetext>At some point we should require disallowing http from https for certain types of requests (or maybe all at some point).

This would also require knowing what type of resource was requested, which ties into CSP content categories (or some such).</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>106332</commentid>
    <comment_count>1</comment_count>
    <who name="Anne">annevk</who>
    <bug_when>2014-05-19 10:48:44 +0000</bug_when>
    <thetext>It seems Mike is going to do this.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>106333</commentid>
    <comment_count>2</comment_count>
    <who name="Mike West">mkwst</who>
    <bug_when>2014-05-19 10:52:21 +0000</bug_when>
    <thetext>Yes. Mike is putting a spec together. Should have something for review next weekish.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>107095</commentid>
    <comment_count>3</comment_count>
    <who name="Mike West">mkwst</who>
    <bug_when>2014-06-01 09:53:30 +0000</bug_when>
    <thetext>I&apos;ve put up a draft mixed content spec for review. On the assumption that it&apos;s not completely insane, I&apos;d appreciate it if you could take a close look at the proposed modifications to Fetch: https://w3c.github.io/webappsec/specs/mixedcontent/#fetch-integration

Anne, does that look like the right division of labor between the documents?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>107120</commentid>
    <comment_count>4</comment_count>
    <who name="Anne">annevk</who>
    <bug_when>2014-06-02 10:40:15 +0000</bug_when>
    <thetext>Yeah, I guess I&apos;ll take this bug back to implement the requested hooks once we agree on the details per list discussion: http://lists.w3.org/Archives/Public/public-webappsec/2014Jun/0004.html</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>107125</commentid>
    <comment_count>5</comment_count>
    <who name="Anne">annevk</who>
    <bug_when>2014-06-02 11:56:56 +0000</bug_when>
    <thetext>Placeholder hooks added: https://github.com/whatwg/fetch/commit/f04393aa9815dd6dce350d5d058f2bac9c4d606c</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>107777</commentid>
    <comment_count>6</comment_count>
    <who name="Anne">annevk</who>
    <bug_when>2014-06-13 09:47:42 +0000</bug_when>
    <thetext>Assigning to Mike as I still need a hook for CSP.

Hooks were improved as part of these commits yesterday:

https://github.com/whatwg/fetch/commit/682f68d5f0cce7f9637a8f6d9450b514ed276f9b
https://github.com/whatwg/fetch/commit/567fe8ad5f1804efdefa7aa273f2a366b223c70e</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>120903</commentid>
    <comment_count>7</comment_count>
    <who name="Anne">annevk</who>
    <bug_when>2015-06-11 09:59:29 +0000</bug_when>
    <thetext>What&apos;s the ETA on CSP getting fixed?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>122553</commentid>
    <comment_count>8</comment_count>
    <who name="Anne">annevk</who>
    <bug_when>2015-08-11 06:49:01 +0000</bug_when>
    <thetext>https://github.com/w3c/webappsec/issues/227</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>