Dataset_ID,Issue_ID,Issue_Title,Issue_Description,Source Project,Privacy,User Participation,Notice,User Desirability,Data Processing,Breach,Complaint / Request,Security 1,6311,"Suggestion: Make Cookies ""Exempt"" from Deletion","Chrome Version : 2.0.156.1 When clearing Cookies, there should be an option to make certain cookies, or cookies from a certain domain ""Exempt"" from the deletion. This could be a useful feature for people who want to remove ad-related cookies, Et Cetera, but not cookies from sites that they trust. This would be similar to Internet Explorer's trusted sites, and security zones.",Chrome,Yes,0,0,1,0,0,0,0 2,32142,Add hours in Clear Browsing Data Dialog,"Chrome Version : 4.0.266.0 What is the expected result? In clear data from this period, add sub-item, Last hour Last 4 hours Please provide any additional information below. Attach a screenshot if possible. This function take user a ""private browsing"" function too, sometimes, user visit some sites and then they notice the site's content and history should be cleared.",Chrome,Yes,1,0,0,0,0,0,0 3,32985,Delete browsing data dialog is too small,"Chrome Version : 4.0.302.2 URLs (if applicable) : n/a Other browsers tested: n/a What steps will reproduce the problem? 1. Set your chrome language to Dutch 2. Go to options, second tab, delete browsing data 3. Notice the dropdown box is partially hidden under the buttons What is the expected result? Larger dialog What happens instead? Dialog is too small",Chrome,Yes,0,1,0,0,0,0,0 4,33942,"Clear browsing data default focus should be ""Clear browsing data"" button","Chrome Version : 4.0.249.78 unknown (36714) URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 4:n/a Firefox 3.x:n/a IE 7:n/a IE 8:n/a What steps will reproduce the problem? 1.press Ctrl + shift + delete 2.it will ask for ""clear browsing data"" or ""close"" 3.but it doesn't go to default choice like on ""clear browsing data"" What is the expected result? it should show a default choice ""clear browsing data"". that way i can press space bar and clear it like in older version. What happens instead? it doesnt show default choice. i have to select by my mouse, instead of pressing simple spacebar. Please provide any additional information below. Attach a screenshot if possible.",Chrome,Yes,0,1,0,0,0,0,0 5,34344,Delete really all LSOs on close,"Delete flash cookies - Delete appcache",Chrome,Yes,1,0,0,0,0,0,0 6,35316,Click to play plugins,"Chrome Version : 5.0.317.2 (Official Build 38193) dev i like having some sites set to block plugins (flash) by default when occasionally i do want to enable the flash content there are exactly two options in the new omnibox menu: Continue blocking popups & Always allow plugins on [URL] i am missing an ""Allow this time only"" option. (if it means reload the page to do that then reload...) just like you can still choose to open the blocked popups you should be able to temporarily allow the plugins i guess the same probably goes for blocking images",Chrome,Yes,0,0,1,0,0,0,0 7,36006,"Content settings: even after saying ""remember"" this value, queued prompts are still shown","Even after saying ""remember"" this value in the modal cookie content setting dialog, queued prompts are still shown.",Chrome,Yes,0,0,1,0,0,0,0 8,36025,"[Content Settings - Images] ""Do not show any images"" doesn't work for local pages","What steps will reproduce the problem? 1. Set ""Content Settings"" -> ""Images"" -> ""Do not show any images"" 2. Open any local page with Chrome (you may also save any web page to local and hen open in with Chrome) What is the expected output? What do you see instead? Images on page should be blocked, but now they are shown Issue is detected in Beta candidate 4.1.249.1011 (Official Build 39069), it also happens in latest trunk 5.0.331.0 (Developer Build 39220) Please use labels and text to provide additional information.",Chrome,Yes,0,0,1,0,0,0,0 9,36435,"When database.open access is blocked, we don't display the blocked content icon","When database.open access is blocked, we don't display the blocked content icon. Since we handle the blocking at the VFS openFile layer (which is triggered by a control message) it'll be hard to know which view to apply this to. I'm not sure whether or not the approach we use in DOM Storage would work (see renderer_webstoragearea_impl.cc's setItem). There's a good chance this is something we can punt to mstone5, but I'm opening it under 4.1 until someone confirms this isn't a must have feature.",Chrome,Yes,0,1,0,0,0,0,0 10,36490,N^2 notifications sent for host content settings changed,"Sorry to dump this on you instead of just fixing, but my hands are kinda full and you wrote this code. When a content setting changes, we fire a notification that all TabContents observe. Then each fires a control message to the renderer process, which enumerates over all render views. This means each of the N render views get notified N times. Instead, we should either have the TabContents send a routed message to the appropriate render view, or have the RenderViewHost be the observer and send a control message that the renderer process farms out.",Chrome,Yes,0,1,0,0,0,0,0 11,37394,Cookie exception for google.com should match subdomains,"Chrome Version: 5.0.344.0 (Developer Build 40612) Is this the most recent version: yes OS + version: Linux CPU architecture (32-bit / 64-bit): 32-bit Behavior in Linux Firefox: WORKS What steps will reproduce the problem? 1. set cookies to ""block sites from setting any data"" 2. add exceptions for ""google.com"" and ""google.de"" 3. try to login to e.g. gmail What is the expected result? It should work or there should at least be any indication which cookie was blocked so that it does not work What happens instead? ""Your browser's cookie functionality is turned off. Please turn it on."" with no blocked cookie indication.",Chrome,Yes,0,0,1,0,0,0,0 12,37426,[Content Settings] Chrome crashes when setting prompt for cookies/data,"What steps will reproduce the problem? 1. Install some extensions, like top 20 popular extensions plus Aniweather extension 2. Set ""Content Settings""->""Cookies""->""Ask me when a site tries to set data"" 3. Clear the exception list and delete all existing cookies/data 4. Set http://www.google.com as you home page and set open the homepage on startup 5. Close chrome browser and then relaunch it. 6. On startup, chrome opens several tabs to www.google.com and extensions options pages, and set cookie/data prompt is also shown 7. Close those extensions options tabs 8. From the set cookie/data prompt, check ""Ask me every time"" and then click Allow button What is the expected output? What do you see instead? Chrome crashes, closes itself without any error dialog. This issues is detected in 5.0.342.1 (Official Build 40461) with Ubuntu9.10, it doesn't happen in windows. This could be a beta blocker of chrome Linux version Please use labels and text to provide additional information.",Chrome,Yes,0,0,1,0,0,0,0 13,37525,Content settings and Incognito mode do not work well together,"Cookie prompt's ""remember"" feature doesn't play nicely with incognito mode It doesn't make sense to default the cookie prompt to remember when you are browsing in incognito mode. Remembering such settings is leaving a local record of your incognito browsing, which defeats the point of incognito mode.",Chrome,Yes,0,1,0,0,0,0,0 14,37623,Plugin can play even though it is set to block,"Chrome Version : 5.0.342.2 (Official Build 40685) dev URLs (if applicable) : http://us.mdbg.net/chindict/chindict.php? page=worddict&wdrst=0&wdqb=chinese Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 4: Firefox 3.x: IE 7: IE 8: What steps will reproduce the problem? 1. Set plugins to block using the content settings so that the plugin blocked icon will appear 2. Go to the URL 3. Click on one the the sound icons for definition What is the expected result? The plugin cannot be played and the URL is http://us.mdbg.net/chindict/chindict.php?page=worddict&wdrst=0&wdqb=chinese since it has no URL What happens instead? The page opens up with about:blank as the URL and the Flash can load Please provide any additional information below. Attach a screenshot if possible.",Chrome,Yes,1,0,0,0,0,0,0 15,37909,"Clear browsing data from Incognito's window, should clear the downloads history","Build: 5.0.342.3 -Have some entries in Downloads page. -Click on 'Clear all' link from Incognito's Downloads page. Issue: Actually the entries in the downloads page got cleared, but not physically. I mean to say, after clicking on Clear all link, the entries in Downloads page in Normal/Incognito windows still show up. This requires to restart the browser window to get the list to get cleared. PS: Repros on Windows and Linux. Need to check on Mac.",Chrome,Yes,1,0,0,0,0,0,0 16,38317,IDN doesn't work on the Content settings/Exceptions,"Chrome Version : 5.0.342.5 (Official Build 41542 URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 4: Firefox 3.x: IE 7: IE 8: What steps will reproduce the problem? 1. launch Chrome with non-English UI (ex: ja) 2. click Wrench => Options => Under the Hood => Content Setting => Images 3. select ""Do not show any images"" radio button 4. click ""Exceptions..."" => ""Add..."" button 5. enter IDN on the ""Host"" field (ex: _____.jp), and select ""Allow"" on the ""Action"" field 6. enter http://_____.jp/ on the Omnibox What is the expected result? What happens instead? There is no images displayed on the website. Image blocked notification icon appears in the right side of omnibox. Please provide any additional information below. Attach a screenshot if possible. Exceptions isn't working for the other features(Cookies, javascript, plugins, popups)",Chrome,Yes,0,0,1,0,0,0,0 17,38349,content settings : double click on an exception doesn't open edit exception dailog,"Issue reproducible on Fedora 11 Chrome 5.0.342.5 (Official Build 41542) dev NOT reproducible on Windows XP Chrome 5.0.342.5 (Official Build 41542) dev What steps will reproduce the problem? 1. Go to wrench > options > under the hood > content settings... 2. click on Exceptions 3. Add an exception 4. Double click on that exception What is the expected output? dialog to edit exception should open on double click What do you see instead? nothing happens on double clicking exception Please use labels and text to provide additional information.",Chrome,Yes,1,0,0,0,0,0,0 18,39066,"[Content Settings] The expires drop-down box option ""When I close my browser"" doesn't work in set cookie/data prompt","What steps will reproduce the problem? 1. Go to ""Content Settings"" -> ""Cookies"" 2. Clear exceptions and saved cookies 3. Check the option ""Ask me when a site tries to set data"" 4. Access google.com 5. On pop-up set cookie/data prompt, check ""Ask me every time"" then click on ""Show details"" and change the expires drop-down box to ""When I close my browser"", finally click on ""Allow"" button 6. Repeat steps 5 if other cookies prompt shows 7. Close chrome browser and then relaunch chrome 8. Go to ""Content Settings"" -> ""Cookies"" -> ""Show cookies and other site data"" What is the expected output? What do you see instead? The saved cookies of google.com are still shown in the saved cookies list, and when check the cookie's information, the expires date of cookies is still the original expiration date/time, not the date/time you close your browser. Please use labels and text to provide additional information.",Chrome,Yes,1,0,1,0,0,0,0 19,39067,Only create databases when we need to; delete them when they're empty,"What steps will reproduce the problem? 1. Go to ""Content Settings"" -> ""Cookies"" 2. Clear exceptions and saved cookies 3. Check the option ""Block sites from setting any data"" 4. Access www.cnn.com 5. Check ""Content Settings"" -> ""Cookies"" -> ""Show cookies and other site data"" What is the expected output? What do you see instead? There is still an items saved in the list, and it shows some data saved in localStorage, however this should not happen since ""Block sites from setting any data"" is checked Issues detected in build 5.0.342.6 (Official Build 42040), also happens in latest trunk build 5.0.361.0 (Developer Build 42349). Please use labels and text to provide additional information.",Chrome,Yes,1,0,1,0,0,0,0 20,39302,Documentation on how to opt out from advertising cookies is wrong,"Chrome Version : Google Chrome 5.0.342.7 (Official Build 42476) beta WebKit 533.2 V8 2.1.2.7 User Agent Mozilla/5.0 (X11; U; Linux x86_64; en-US) AppleWebKit/533.2 (KHTML, like Gecko) Chrome/5.0.342.7 Safari/533.2 Command Line /usr/bin/google-chrome URLs (if applicable) : http://www.google.com/ads/preferences/plugin/browsers.html#chrome The description on the help page for how to opt-out of advertising cookies does not match the Chrome version above. I.e., you have to go Options > Unter the Hood > Content settings... > Cookies. The ""Content settings..."" step is missing. Cheers, Matthias",Chrome,Yes,0,1,0,0,0,0,0 21,39389,[Content Settings] Empty entry remains in list after all its sub-entries have been removed,"Chrome 5.0.360.0 (Official Build 42309) OS: Win XP What steps will reproduce the problem? -------------------------------------- 1. Go to http://www.google.com. 2. Look in Content Settings > Cookies > Show cookies and other site data 3. Expand the entry ""google.com"" 4. Remove all cookies under this site. What is the expected output? ---------------------------- Should remove ""Cookies"" item for a site when there are no cookies for that site. Otherwise, you are left with an empty item. What do you see instead? ------------------------ There is an empty ""Cookies"" entry. Similarly, if you remove all items under ""google.com"", then ""google.com"" should also be removed.",Chrome,Yes,1,0,0,0,0,0,0 22,39740,Plugins are not always blocked by content settings,"Plugins are not always blocked by content settings Observed in 5.0.365.0 (Developer Build 42941) Repro steps: 1- Modify content settings to block all plugins 2- Load test case 3- Click button 4- Notice that the plugin loads and can be played The bug is likely related to the fact that we only send down the blocked content settings in response to a top-level navigation. In this example, there is no top-level navigation since the newly opened window is to about:blank.",Chrome,Yes,0,0,1,0,0,0,0 23,39817,Geolocation: implement the content settings exception dialog,"As per http://mocks/glen/chrome/spec/89_geo2/4/#04_exceptions.png http://mocks/glen/chrome/spec/89_geo2/4/#05_exceptionsproperties.png + Peter's modifications.",Chrome,Yes,0,1,1,0,0,0,0 24,40067,Fine grain Javascript permissions,"Chrome Version : 5.0.364.0 (Developer Build 42859) URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 4: Firefox 3.x: OK IE 7: IE 8: What steps will reproduce the problem? 1. Go to Content Settings -> Javascript What is the expected result? Fine grained control of individual Javascript actions to be allowed or disallowed. What happens instead? Can only turn Javascript on or completely off. THIS IS A FEATURE REQUEST NOT A BUG It would be a great feature to be able to control Javascript permissions at a much finer grained level. For example, Firefox has a dialogue to allow you to allow scripts to: [ ] Move or resize existing windows [ ] Raise or lower windows [ ] Disable or replace context menus [ ] Hide the status bar [ ] Change status bar text These controls can make some really annoying practices by some websites go away and really puts the user in control.",Chrome,Yes,0,0,1,0,0,0,0 25,40095,"When database.open access is blocked for workers, we don't display the blocked content icon","What steps will reproduce the problem? 1. block all cookies 2. have a worker open a web database What is the expected output? What do you see instead? blocked content icon should appear",Chrome,Yes,0,1,0,0,0,0,0 26,40263,"[Geolocation] ""Clear these settings for future visits"" in location tracking/blocking notification bubble seems not work","Currently it seems the ""Clear these settings for future visits"" in location tracking/blocking notification bubble seems not to take effect yet, when clicking on it nothing is affected. This link need to be more meaningful, like when it is in block bubble then it should give user option to allow location tracking, and if it is in tracking bubble then it should give user option to deny location tracking. Refer to the options in image/javascript blocked notification bubble.",Chrome,Yes,1,0,0,1,0,0,0 27,40613,Geolocation doesn't work accurately with wireless network on linux,"What steps will reproduce the problem? 1. Make sure you allow location tracking 2. Access http://maps.google.com 3. Click on ""Detect my location"" button What is the expected output? What do you see instead? With wireless network it should show a blue dot with a shaded blue circle on the map for your estimated location, but now it doesn't Issues happens in build 5.0.369.2-r43644 with Ubuntu8.04, and it shows some errors on the background terminal console, refer to the attached screen-shot. Please use labels and text to provide additional information.",Chrome,Yes,0,1,0,0,0,0,1 28,40718,Popup blocking when leaving a page uses next page's content settings,"Visit popuptest.com. Click ""multi popup test #1"". Now manually navigate to chrome://extensions/. Be surprised when two popups open. The page tries to open two popups when exiting, and all chrome:// URLs are whitelisted to allow all content, so I think this means we're using the wrong settings to check what to do?",Chrome,Yes,0,1,0,0,0,0,0 29,40742,Geolocation: ( maps.google.com ): Geolocation icon flashes a second and failed to sit in omnibox after we allow,"Platform: Hostname: ismail-macbookpro15.local Mac OS X Version 10.5.8 (Build 9L31a) Processor: 2 Intel 2.33 GHz RAM: 2048 MB Chrome: Chrome version: 5.0.370.0 r43790 <<>> QuickTime Player: 7.6.4 QuickTime PlayerX: Flash Player: 10.0.45.2 What steps will reproduce the problem? 1. Open maps.google.com 2. Content settings --> Location --> Allow all sites to track my location or Ask me when sites try to track my location 3. Click on the dot( my location pointer) Result: It detects the location , but Geolocation icon flashes in omnibox once and finally failed to sit in omnibox even after we allow. Note: When you ""deny"" the site, the icon sits happily in omnibox. Other geolocation sites : http://www.aniweather.com/aniweather.config6.html#settings http://smithsrus.com/geo.html (are good and shows the icon @ omnibox)",Chrome,Yes,0,1,0,0,0,0,0 30,40813,Remove button is enabled after opening cookies editor window though nothing is selected,"What steps will reproduce the problem? 1. Go to ""Content Settings"" -> ""Cookies"" -> ""Show cookie and other site data"" What is the expected output? Remove not enabled. What do you see instead? Remove enabled.",Chrome,Yes,0,1,0,0,0,0,0 31,40839,Add 'temporary' exceptions for javascript blocking,"Chrome Version : Future URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 4: Firefox 3.x: Ok (with NoScript) IE 7: IE 8: What steps will reproduce the problem? 1. Options|Content Settings|Javascript|Do not allow any site to run JavaScript 2. Navigate to a site without an exception entry. 3. Click javascript-blocked icon in omnibox. What is the expected result? Options: * Always allow javascript to run on . * Allow javascript to run on temporarily for this session/window/page. * Continue blocking javascript. [manage javascript blocking] What happens instead? Options: * Always allow javascript to run on . * Continue blocking javascript. [manage javascript blocking] Please provide any additional information below. Attach a screenshot if possible. An exception which expires saves the user from having to manually remove it from the permanent exception list later, if the intent was only to run script on a single page (or for a single session), but normally they would prefer script to be blocked on that domain.",Chrome,Yes,0,1,1,0,0,0,0 32,40973,Search text available outside of Incognito mode,"Splitting off the Mac version of Issue 32021. Things will be a little harder on the Mac because of the find pasteboard What steps will reproduce the problem? 1. Open non incognito window 2. Open an incognito window, cmd + F, enter search text, close incognito window 3. In non incognito window, cmd + F What is the expected result? Search field does no contain text of Incognito search text What happens instead? The search text I typed into the Incognito window is also in the non Incognito window which means Private information was leaked out of Incognito.",Chrome,Yes,0,0,0,1,0,0,0 33,41113,Content settings bubbles should clamp max length of page-controlled strings,"using 5.0.371.0 (Official Build 43900) dev under XP 1. visit http://tinyurl.com/yamf56s 2. click on a little magnifying glass image under an image in the article. the popup will be blocked because the website is opened though an external frame, if you open the popup bubble you will only see a part of it- the rest is out of screen",Chrome,Yes,1,0,0,0,0,0,0 34,41224,"[Content Settings] In image/javascript/plugin/popup blocked notification bubble, check one option should make the previous checked option unchecked","What steps will reproduce the problem? 1. Set Content Settings -> Images -> Do not show any images 2. Access a website e.g. www.google.com 3. Click the image blocked notification icon to show the bubble 4. Option ""Continue blocking images"" is checked be default, now check ""Always allow... to show images"" What is the expected output? What do you see instead? Option ""Continue blocking images"" should be unchecked, but now it is still checked. This also happens to javascript/plugin/popup. See attached screen-shot for reference. Issues happens in build 5.0.375.3 (Official Build 44229) Please use labels and text to provide additional information.",Chrome,Yes,1,0,0,0,0,0,0 35,42359,Chrome creates multiple content settings for same site,"Platform: Hostname: testings-mac-mini-4.local Mac OS X Version 10.6.3 (Build 10D573) Processor: 1 Intel 1.50 GHz RAM: 1024 MB Chrome: Chrome version: 5.0.381.0 r44886 <<>> QuickTime Player: 7.6.6 QuickTime PlayerX: 113 Flash Player: 10.0.45.2 What steps will reproduce the problem? Precondition : clear browser history before starting. 1. Open content settings add exception blocking images/ javascript add specifically "" www.bing.com "" 2. open bing.com , observer images and scripts are blocked. 3. Click on the omnibox -image blocking icon and on the bubble click select , allow images for bing.con and click done. 4. refresh the page. What is the expected output? Images should be allowed , as use has selected in the bubble and refresh the page. The preference should be update with the new rule in exceptions. What do you see instead? Images are still blocked and in exceptions list 2 rules are added one for allow and one for block for bing,com. Please use labels and text to provide additional information.",Chrome,Yes,1,0,1,0,0,0,0 36,42380,Should be able to close a note in Incognito mode,"Repros on ToT (r45335) and 5.0.375.17. Looks like, it never worked. User can't close a note in incognito window. -Navigate to http://webkit.org/demos/sticky-notes/ in Incognito mode. -Create a note I will notice two differences/issues here with Incognito Vs normal window. Incognito: 1)Navigating to the above url, does not open a note, where as it does in normal window. - I don't know, which is one is the right behavior. 2) Try to close a note in incognito window - you can't. PS: Issue2 Works fine in Linux.",Chrome,Yes,0,0,0,1,0,0,1 37,42403,Cookie prompt does not allow to set expire date for HTML cookies,"What steps will reproduce the problem? 1. Set cookies settings to ""Ask"" 2. Go to a site with cookies 3. Expand ""details"" What is the expected output? What do you see instead? You should be offered the option to restrict cookies to session cookies Please use labels and text to provide additional information.",Chrome,Yes,0,0,1,0,0,0,0 38,42789,[Geolocation] The location tracking prompt info-bar shows the wrong site when tracking location in multiple frame cross origin location tracking page,"What steps will reproduce the problem? 1. Access http://go/chromehtml5/geolocation-in-multi-frame.html 2. In Location section of the second frame, click on ""Detect my location"" What is the expected output? What do you see instead? It should only shows the prompt info-bar for http://www.aniweather.com/, but now it first shows the prompt info-bar for http://map.google.com/ and then shows the prompt info-bar for http://www.aniweather.com/. The prompt info-bar for http://map.google.com/ should not be shown since I didn't click ""Show my location"" in the first frame. Issue is detected in build 5.0.375.25 (Official Build 45690). Please use labels and text to provide additional information.",Chrome,Yes,1,0,0,0,0,0,1 39,42869,[Geolocation] The location tracking notification icon still shows even location tracking is blocked,"What steps will reproduce the problem? 1. Check ""Content Settings"" -> ""Location"" -> ""Allow all sites to track..."" 2. Access http://maps.google.com and click ""Show My Location"", now the location tracking notification icon is shown in omnibox 3. Now Check ""Do not allow any site..."" 4. Reload http://maps.google.com and click ""Show My Location"" What is the expected output? What do you see instead? The location tracking blocked notification icon (the one with red cross hair) should be shown, but now it still shows the tracking notification icon. When you click on the icon, the description in pop-up bubble is also shown improperly. This issue could caused by the fix of issue 40742. It doesn't happen before. Please use labels and text to provide additional information.",Chrome,Yes,1,1,0,0,0,0,0 40,42887,[Content Settings] In incognito changes on content settings only take effect after current incognito window closed,"What steps will reproduce the problem? 1. Open an incognito window and then go to Content Settings 2. Do some setting changes on Cookies, Images, Javascript, Plug-ins, Pop-ups and Location 3. Access websites to see if the changes take effect What is the expected output? What do you see instead? The changes are not working, unless close the existing incognito window and then open a new incognito window. This problem doesn't happen in normal window. Issue is detected with build 5.0.375.28 (Official Build 45883) in both Windows and Linux Please use labels and text to provide additional information.",Chrome,Yes,1,0,1,0,0,0,0 41,42905,[Content Settings] Cookies expires date is not set correctly when accept it from set cookie prompt in Linux,"What steps will reproduce the problem? 1. Set ""Content Settings"" -> ""Cookies"" -> """"Ask me when a site tries to set data"" and clear cookie exception list and saved cookies 2. Access http://www.google.com, the set cookie prompt should pop up 3. Click on ""Show details"" to make sure the Expires field is a date later than now 4. Check ""Ask me every time"" and then click Allow 5. Go to saved cookies list and check the cookie expires date What is the expected output? What do you see instead? The cookies expires date is ""When I close my browser"", this is wrong. This issue only happens in Linux, it doesn't happen in Windows. Issue is detected with build 5.0.375.28 (Official Build 45883) in Ubuntu8.04. Please use labels and text to provide additional information.",Chrome,Yes,0,1,0,0,0,0,0 42,42909,[Content Settings] Exceptions of content settings should be sortable by Pattern or Action field in Linux,"What steps will reproduce the problem? 1. Go to Content Settings and click Exceptions button 2. Add several exceptions 3. Click on Pattern or Action field to try to sort exceptions What is the expected output? What do you see instead? Nothing happens, but it should work just like in Windows. Issues is detected with build 5.0.375.28 (Official Build 45883) in Ubuntu8.04. Please use labels and text to provide additional information.",Chrome,Yes,0,1,0,0,0,0,0 43,42920,[Content Settings] closing an incognito window before answering the cookie prompt crashes the browser,"What steps will reproduce the problem? 1. Set cookie settings to ""Ask"" 2. Open an incognito window and go to a site that sets cookies 3. Wait for the first cookie prompt to appear 4. Close all incognito windows 5. accept the cookie What is the expected output? What do you see instead? browser crashes. Tested on Linux 5.0.375.23 Please use labels and text to provide additional information.",Chrome,Yes,1,0,0,0,0,0,0 44,43040,Browser crash on clicking content settings links @ Browser::HandleCrossAppNavigation,"Chrome Version : Build 46195 URLs (if applicable) : N/A Other browsers tested: N/A What steps will reproduce the problem? 1. Options > Under the Hood 2. Privacy > Content Settings 3. Plugins > Disable individual plugins What is the expected result? Checklist of some sort to disable various plugins installed. What happens instead? Chromium crashes and restart of the browser is required.",Chrome,Yes,1,0,1,0,0,0,0 45,43249,deleting individual cookies does not work,"Chromium Version : 5.0.342.9 (Build 43360) Ubuntu In the Options dialog, there's a dialog to manage cookies (Click the ""Content settings..."" button, then click ""Show cookies and other site data...""). That dialog has two buttons on the bottom: ""Remove"", and ""Remove all"". It's nice, except that they don't work. They will only remove the cookie(s) from the view, but if you refresh the cookie list by changing the filter/search terms (ex: type "" "" and then do backspace), the cookie(s) you just deleted will show up again. Note: deleting all the cookies by using the ""Clear browsing data..."" button (in the main Options dialog) does work. I'd prefer being able to delete select cookies instead of nuking everything :)",Chrome,Yes,1,0,0,0,0,0,0 46,45064,"The ""save to"" directory from Incognito will be remembered in the ""choose file"" dialog in non-Incognito","This bug affects the privacy of users, who might not want their Incognito save locations shown in non-Incognito mode. Steps to reproduce the problem: 1) Open Incognito mode; you can leave regular mode open or close it, it doesn't seem to matter 2) Save any file from Incognito mode in a directory other than your default download directory 3) Switch back to non-Incognito mode. 3) Use a ""choose file"" dialog, such as in a file upload page 4) The dialog's directory will be the saved directory from Incognito mode",Chrome,Yes,0,0,0,1,0,0,0 47,45109,cookie domain wildcard fails for https://mail.google.com,"Chrome Version : 5.0.375.55 beta URLs (if applicable) : mail.google.com/ What steps will reproduce the problem? 1. Clear all cookies from *.google.com 2. In Content Settings, select ""Block sites from setting any data"" 3. Clear ""Block all third-party cookies without exception"" 4. Enter a cookie exception, ""[*.]google.com"" 5. Navigate to //mail.google.com/ (redirects to https://www.google.com/accounts/ServiceLogin?service=mail...) 6. Enter username and password What is the expected result? Log in to gmail account What happens instead? Warning about redirect loop: This webpage has a redirect loop. The webpage at https://mail.google.com/mail/? ui=html&zy=l&pli=1&auth=[redacted]&gausr=[redacted]%40gmail.com has resulted in too many redirects. Clearing your cookies for this site or allowing third-party cookies may fix the problem. If not, it is possibly a server configuration issue and not a problem with your computer. ...If I manually add ""mail.google.com"" as a cookie exception and hit reload, the login succeeds. I would've expected ""[*.]google.com"" to include ""mail.google.com"".",Chrome,Yes,1,0,0,0,0,0,0 48,45230,Collect blocked/allowed cookies and show to the user on demand,"What steps will reproduce the problem? 1. Disallow cookies 2. Visit a site that uses cookies 3. What is the expected output? What do you see instead? There should be some way to see what cookies the site accessed (which were blocked).",Chrome,Yes,1,0,0,0,0,0,0 49,45546,Content Settings dialog should have a list of categories on the left instead of tabs at the top,Content Settings dialog should have a list of categories on the left instead of tabs at the top,Chrome,Yes,0,1,0,0,0,0,0 50,45547,Add Notifications panel to content settings window,Add Notifications panel to content settings window,Chrome,Yes,0,1,0,0,0,0,0 51,45644,NOTREACHED() when changing cookie preferences in incognito mode,"What steps will reproduce the problem? 1. Open a new incognito window 2. Preferences > Under the Hood > Content Settings > Cookies 3. Change ""Block third-party cookies"" What is the expected output? What do you see instead? You get a NOTREACHED assertion failure.",Chrome,Yes,1,0,0,0,0,0,0 52,47049,Support session-only mode for all cookie-like data,"Right now, you can force a single cookie to expire after the session using the ask mode for cookies. It should be possible to force other cookie-like data to be session only (e.g. web databases), and it should be possible to persist this decission.",Chrome,Yes,0,0,1,1,0,0,0 53,47841,Sorting content exceptions does not work,"According to issue 47614... What steps will reproduce the problem? 1. Have a few content exceptions 2. Sort them by action 3. edit an entry What is the expected output? What do you see instead? The editor will come up for the entry that would be at this position if the table wasn't sorted. I think the problem is that the TableAdapter only updates the list store when the table model changes, but not the other way round (sorting the gtktreeview results in updates to the list store).",Chrome,Yes,0,1,0,0,0,0,0 54,48484,Spurious patterns added to content settings,"What steps will reproduce the problem? 1. Configure Image Content Settings to ""Do not show any images"" 2. Go to google.com 3. Click ""Images have been blocked"" bubble 4. Choose ""Always allow images"" 5. Choose ""Continue blocking"" 6. Set Image Content Setting to ""Show all images"" 7. Reload page What is the expected output? What do you see instead? Images should be shown. Instead, they're still blocked. The reason for this is that after step 4, [.*]www.google.com is added as ""Allow"" exception (good). It becomes a ""Block"" exception after step 5 (bad; the exception should just be removed).",Chrome,Yes,1,0,1,0,0,0,0 55,48941,Disable the cookie prompt,"1. There should be no UI to select a prompt mode for cookies 2. the whole infrastructure should be reverted to not block on cookie operations.",Chrome,Yes,0,1,1,0,0,0,0 56,49677,"Add ""Load all plugins on this page"" to blocked plugins bubble","When plugins are blocked in the content settings, it can be activated using click to play (Issue 35316) While this is a great feature, there are many websites where blocked content cannot be activated using click to play For example http://news.nana10.co.il/Article/?ArticleID=733285 (since this is a Hebrew site, instructions on where to click to play the video is attached) There are many other examples where clicked to play isn't even expectd to work... I'll recycle Issue 35316 description: There are exactly two options in the plugins blocked bubble: 1. Continue blocking popups & Always 2. Allow plugins on [URL] If Click to play can't handle theses cases, i think a third option is logical- An ""Allow this time only"" option. (if it means reload the page to do that then reload...) i guess the same suggestion probably goes for blocking images",Chrome,Yes,0,0,1,0,0,0,0 57,49826,Need visual feedback on creation of content settings,"Chrome Version : 6.0.472.0 (Official Build 53024) What steps will reproduce the problem? 1. Launch Chrome 2. block cookies of any sites from the Content Settings 3. go to http://google.com 4. right click on the cookies blocking icon 5. click on the ""Show cookies and other site data..."" link 6. select google.com or www.google.com from the ""The following cookies were blocked:"" field 7. Then click ""Allow"" or ""Allow for session only"" button What is the expected result? The google site cookies should be allowed. What happens instead? Nothing happens. Please provide any additional information below. Attach a screenshot if possible. Test Environment : Ubuntu9.04 /32bit It works fine in Windows platform.",Chrome,Yes,1,0,0,0,0,0,0 58,51204,Geolocation settings through incognito persist even after ending that session,"What steps will reproduce the problem? 1. Open incognito window 2. Navigate to maps.google.com 3. Click on the button above zoom bar to get the geolocation infobar 4. Click on allow 5. Close the incognito window 6. Using normal window, go to options > under the hood > content settings > location > exceptions What is the expected output? The content settings changed in incognito mode should not be remembered when the incognito session ends(Just the way other features in content settings work) What do you see instead? The settings are remembered forever. Google Chrome 6.0.472.22 (Official Build 54852)",Chrome,Yes,0,0,0,1,0,0,0 59,51959,Browser crash on pop-up for a website in incognito,"Build: 6.0.490.1 OS: XP -Allow a pop-up for a website from Incognito window. -Open Pop-up Exceptions dialog. -Close the Incognito window. -Delete the Pop-up exception. -Boom The crash report can be found @ http://crash/reportdetail?reportid=ae02730d71c1cc76 Crash Stack ########### Thread 0 *CRASHED* ( EXCEPTION_ACCESS_VIOLATION_WRITE @ 0x00000010 ) 0x7c91b21a [ntdll.dll + 0x0001b21a] RtlpWaitForCriticalSection 0x7c901045 [ntdll.dll + 0x00001045] RtlEnterCriticalSection 0x01dd2681 [chrome.dll - host_content_settings_map.cc:507] HostContentSettingsMap::SetContentSetting(HostContentSettingsMap::Pattern const &,ContentSettingsType,std::basic_string,std::allocator > const &,ContentSetting) 0x01ff7010 [chrome.dll - content_exceptions_table_model.cc:56] ContentExceptionsTableModel::RemoveException(int) 0x01fd3b4e [chrome.dll - exceptions_view.cc:265] ExceptionsView::Remove() 0x01fd323f [chrome.dll - exceptions_view.cc:73] ExceptionsView::ButtonPressed(views::Button *,views::Event const &) 0x025bc925 [chrome.dll - button.cc:63] views::Button::NotifyClick(views::Event const &) 0x025b6e08 [chrome.dll - native_button.cc:126] views::NativeButton::ButtonPressed() 0x025d0f93 [chrome.dll - native_button_win.cc:110] views::NativeButtonWin::ProcessMessage(unsigned int,unsigned int,long,long *) 0x025b91be [chrome.dll - widget_win.cc:1227] views::WidgetWin::OnWndProc(unsigned int,unsigned int,long) 0x024bec35 [chrome.dll - window_impl.cc:195] gfx::WindowImpl::WndProc(HWND__ *,unsigned int,unsigned int,long) 0x7e418733 [user32.dll + 0x00008733] InternalCallWinProc 0x7e418815 [user32.dll + 0x00008815] UserCallWinProcCheckWow 0x7e42927a [user32.dll + 0x0001927a] SendMessageWorker 0x7e4292e2 [user32.dll + 0x000192e2] SendMessageW 0x773f7353 [comctl32.dll + 0x00027353] Button_NotifyParent 0x773f7435 [comctl32.dll + 0x00027435] Button_ReleaseCapture 0x773f973a [comctl32.dll + 0x0002973a] Button_WndProc 0x7e418733 [user32.dll + 0x00008733] InternalCallWinProc 0x7e418815 [user32.dll + 0x00008815] UserCallWinProcCheckWow 0x7e42a012 [user32.dll + 0x0001a012] CallWindowProcAorW 0x7e42a038 [user32.dll + 0x0001a038] CallWindowProcW 0x025d1aa4 [chrome.dll - native_control_win.cc:217] views::NativeControlWin::NativeControlWndProc(HWND__ *,unsigned int,unsigned int,long) 0x7e418733 [user32.dll + 0x00008733] InternalCallWinProc 0x7e418815 [user32.dll + 0x00008815] UserCallWinProcCheckWow 0x7e4189cc [user32.dll + 0x000089cc] DispatchMessageWorker 0x7e418a0f [user32.dll + 0x00008a0f] DispatchMessageW 0x025b02c6 [chrome.dll - accelerator_handler_win.cc:57] views::AcceleratorHandler::Dispatch(tagMSG const &) 0x01cffc1b [chrome.dll - message_pump_win.cc:353] base::MessagePumpForUI::ProcessMessageHelper(tagMSG const &) 0x01cffa79 [chrome.dll - message_pump_win.cc:198] base::MessagePumpForUI::DoRunLoop() 0x01cff8a0 [chrome.dll - message_pump_win.cc:51] base::MessagePumpWin::RunWithDispatcher(base::MessagePump::Delegate *,base::MessagePumpWin::Dispatcher *) 0x01cee173 [chrome.dll - message_loop.cc:252] MessageLoop::RunInternal() 0x01cee103 [chrome.dll - message_loop.cc:229] MessageLoop::RunHandler() 0x01cee802 [chrome.dll - message_loop.cc:655] MessageLoopForUI::Run(base::MessagePumpWin::Dispatcher *) 0x01d6d873 [chrome.dll - browser_main.cc:448] `anonymous namespace'::RunUIMessageLoop(BrowserProcess *) 0x01d6f0b4 [chrome.dll - browser_main.cc:1391] BrowserMain(MainFunctionParams const &) 0x01c33ca3 [chrome.dll - chrome_dll_main.cc:898] ChromeMain 0x00403875 [chrome.exe - client_util.cc:240] MainDllLoader::Launch(HINSTANCE__ *,sandbox::SandboxInterfaceInfo *) 0x00403e87 [chrome.exe - chrome_exe_main.cc:46] wWinMain 0x00446e82 [chrome.exe - crt0.c:263] __tmainCRTStartup 0x7c817076 [kernel32.dll + 0x00017076] BaseProcessStart Thread 1 0x7c90e514 [ntdll.dll + 0x0000e514] KiFastSystemCallRet 0x7c90d219 [ntdll.dll + 0x0000d219] ZwDelayExecution 0x7c927f21 [ntdll.dll + 0x00027f21] RtlpTimerThread 0x7c80b728 [kernel32.dll + 0x0000b728] BaseThreadStart Thread 2 0x7c90e514 [ntdll.dll + 0x0000e514] KiFastSystemCallRet 0x7c90df49 [ntdll.dll + 0x0000df49] NtWaitForMultipleObjects 0x7c929cb5 [ntdll.dll + 0x00029cb5] RtlpWaitThread 0x7c80b728 [kernel32.dll + 0x0000b728] BaseThreadStart Thread 3 0x7c90e514 [ntdll.dll + 0x0000e514] KiFastSystemCallRet 0x7c90da49 [ntdll.dll + 0x0000da49] ZwRemoveIoCompletion 0x7c80a7e5 [kernel32.dll + 0x0000a7e5] GetQueuedCompletionStatus 0x00410f26 [chrome.exe - broker_services.cc:155] sandbox::BrokerServicesBase::TargetEventsThread(void *) 0x7c80b728 [kernel32.dll + 0x0000b728] BaseThreadStart Thread 4 0x7c90e514 [ntdll.dll + 0x0000e514] KiFastSystemCallRet 0x7c90df49 [ntdll.dll + 0x0000df49] NtWaitForMultipleObjects 0x7c80958f [kernel32.dll + 0x0000958f] CreateFileMappingA 0x7c80a114 [kernel32.dll + 0x0000a114] WaitForMultipleObjects 0x769c87bc [userenv.dll + 0x000087bc] NotificationThread() 0x7c80b728 [kernel32.dll + 0x0000b728] BaseThreadStart Thread 5 0x7c90e514 [ntdll.dll + 0x0000e514] KiFastSystemCallRet 0x7c90df59 [ntdll.dll + 0x0000df59] ZwWaitForSingleObject 0x7c8025da [kernel32.dll + 0x000025da] WaitForSingleObjectEx 0x7c802541 [kernel32.dll + 0x00002541] WaitForSingleObject 0x01cfc106 [chrome.dll - waitable_event_win.cc:50] base::WaitableEvent::Wait() 0x01cff5dd [chrome.dll - message_pump_default.cc:42] base::MessagePumpDefault::Run(base::MessagePump::Delegate *) 0x01cee17e [chrome.dll - message_loop.cc:257] MessageLoop::RunInternal() 0x01cee103 [chrome.dll - message_loop.cc:229] MessageLoop::RunHandler() 0x01cee0b1 [chrome.dll - message_loop.cc:207] MessageLoop::Run() 0x025a6152 [chrome.dll - thread.cc:141] base::Thread::Run(MessageLoop *) 0x025a61f8 [chrome.dll - thread.cc:165] base::Thread::ThreadMain() 0x01cf7f81 [chrome.dll - platform_thread_win.cc:26] `anonymous namespace'::ThreadFunc(void *) 0x7c80b728 [kernel32.dll + 0x0000b728] BaseThreadStart",Chrome,Yes,1,0,0,0,0,0,0 60,53339,"The location tracking blocked notification icon still shows, even after the exception is removed","Build: 7.0.503.0 -Navigate to maps.google.com -Click ""Show My Location"" and click on ""Deny"" on the location info bar. -Remove the exception Through the ""manage location settings"" dialog. -Refresh maps.google.com page. Expected: The location tracking blocked notification icon should disappear in Omnibox. Issue: It still shows up in the omnibox. User has to refresh the page one more time or navigate to another tab and then come back to google maps page.",Chrome,Yes,1,1,0,0,0,0,0 61,53571,Cookie dialog extremely slow,"Chrome Version : 6.0.472.41 (Official Build 56471) beta, on Windows 7 32-bit What steps will reproduce the problem? 1. Presumably have a large amount of cookies and local storage? 2. Open ""Cookies and other Data"" dialog 3. type something into the Search field What is the expected result? fast response What happens instead? The whole Chrome user interface freezes completely for a few seconds after the dialog is opened, and then for about 15 seconds when anything is typed into the Search field. My Cookies file is 1 MB, my Local Storage directory contains nearly 2000 files totaling 8.9 MB. The slow behavior seems to be caused mainly by the files in the Local Storage directory; if I rename it away but keep the Cookies file, the dialog responds much faster, with delays of only 2 or 3 seconds.",Chrome,Yes,0,1,0,0,0,0,0 62,53624,Content settings: option not seen for - do not show images / run javascript,"ChromeOS : 0.8.67.0 (Official Build 8899d5a9) Chrome : 7.0.503.0 (Official Build 57033) Not reproducible on Ubuntu 8.04 Chrome 7.0.503.1 (Official Build 57041) What steps will reproduce the problem? 1. Go to Options > Under the hood > Content Settings > Images What is the expected output? Under Image Settings, there should be option for ""Do not show any images"". Same issue for Javascript settings, there should be option for ""Do not allow any site to run Javascript"". What do you see instead? No option for ""Do not show any images"". No option for ""Do not allow any site to run Javascript"". Please use labels and text to provide additional information.",Chrome,Yes,0,0,1,0,0,0,0 63,54675,Improve the 'This page was prevented from setting cookies' button,"Chrome Version : 6.0.472.53 (57914) URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 4: Firefox 3.x: IE 7: IE 8: What steps will reproduce the problem? 1.Disable cookies (block websites from setting any data) 2.Visit a webpage that sets a cookie 3.Click on the button What is the expected result? Like the 'JS was blocked on this webpage' button, the 'cookies' button should allow to enable the cookies for the current web page without having to open the content settings. Thanks",Chrome,Yes,0,1,0,0,0,0,0 64,54853,Provide a way for extensions to clear the browser cache,"Chrome Version : 6.0.472.55 beta URLs (if applicable) : N/A Other browsers tested: N/A I am writing a browser automation extension. It would be useful if there were a way for my extension to clear the browser cache.",Chrome,Yes,1,0,0,1,0,0,0 65,55363,RLZ data included in search requests from organic installs,"What steps will reproduce the problem? 1. Install an organic version of Chrome 2. Search for something on Google using the omnibox What is the expected output? What do you see instead? an rlz= parameter with brand GGLS is send. Nothing should be send Please use labels and text to provide additional information.",Chrome,Yes,0,0,0,0,0,0,1 66,56248,hook up indexed db to content settings,"step 1: query content settings before allowing access to indexed db step 2: implement a browsing data helper to handle indexed db step 3: add indexed db to the collected cookies dialog",Chrome,Yes,0,0,0,0,0,0,1 67,56249,Delete indexed DBs from the browsing data deleters,"It should be possible to delete indexed DBs from: - BrowsingDataRemover (probably via WebkitContext::DeleteDataModifiedSince) - ExtensionDataDeleter (if extensions can create indexed DBs) - a static method run on shutdown (see DomStorageContext::ClearLocalState) - BrowsingDataIndexedDBHelper::DeleteIndexedDBInWebKitThread",Chrome,Yes,1,0,0,0,0,0,0 68,56514,Click to Play is vulnerable to UI redressing,"When the click to play functionality is enabled (presently only through --enable-click-to-play), it's possible for an attacker to run installed plugins even when they are globally disabled. This is due to the fact that click-to-play is not guarded against UI redressing (also referred to as ""clickjacking""). The ideal fix would prevent a user click from going to a not visible / noticeable ""Click to play"" box. Another fix could be to have two options to disabled plugins: ""disable in the old fashion"" or ""click to play"".",Chrome,Yes,0,0,1,0,0,0,1 69,57215,Windows 7 Jumplist Items not cleared after deleting browser history,"What steps will reproduce the problem? 1. Open one or more tabs to any web site (e.g., google.com) and then close them. 2. Clear all browsing data. 3. Before closing any other tabs, right click the Windows 7 icon to view the Jumplist. What is the expected output? What do you see instead? The recently closed tab(s) should not be displayed in ""Recently Closed,"" and there should be no ""Most Visited"" entries. Instead, those entries are still present (posing a privacy risk) until you close another tab.",Chrome,Yes,1,0,0,0,0,0,0 70,57677,"""Session only"" BLOCKS rather than CONVERTS non-session cookies","Chrome Version : 7.0.536.2 dev URLs (if applicable) : eg http://www.facebook.com Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 4: Firefox 3.x: OK IE 7: IE 8: What steps will reproduce the problem? 1. Ensure cookies set to being allowed. 2. Add following rules: Pattern [*.]facebook.com Action Session only. 3. Attempt to log in to facebook. What is the expected result? Should be able to log in to facebook What happens instead? Facebook says cookies not enabled, and thus you cannot log in. Please provide any additional information below. Attach a screenshot if possible. Inspecting which cookies are allowed with and without the ""Session only"" setting reveals cookies that aren't sent as session only by facebook are BLOCKED when the ""Session only"" setting is set. This is a non-intuitive behaviour - Chrome should CONVERT non-session cookies to being session only. This would then match Firefox's behaviour, and what I believe is the intuitive behaviour. See also http://www.google.com/support/forum/p/Chrome/thread?tid=5a81f96d72e80d8a&hl=en",Chrome,Yes,1,0,0,0,0,0,1 71,58235,Integrate with API for deleting Flash Player LSOs,"you know what I'm talking about. Either jochen or bauerb - not sure which.",Chrome,Yes,1,0,0,0,0,0,0 72,59377,"Browser crash on geolocation @ MessageLoop::PostTask_Helper(tracked_objects::Location const &,Task *,__int64,bool)","What steps will reproduce the problem? 1.Launch chrome 2.make sure Wrench -> Under the Hood -> Content settings -> Location is set to ""Ask me when..."" 2.navigate to maps.google.com 3.click on geolocator ring above zoom control 4.refresh the page and click on geolocator ring again What is the expected output? Infobar should display that site is trying to use geolocation What do you see instead? @3 Infobar is not displayed, instead geolocator shows present location @4 browser crashes with crash-id: 4443dcc064e61bd3 Crash summary @ http://crash/reportdetail?reportid=4443dcc064e61bd3 8.0.552.0 (Official Build 62249) Please use labels and text to provide additional information.",Chrome,Yes,0,0,1,0,0,0,0 73,59806,"""Run all plug-ins this time"" can't handle a case where plugins are loaded gradually","What steps will reproduce the problem? 1. Configure content settings plug-ins option to Click to play 2. Visit http://10tv.nana10.co.il/ 3. Use the ""Run all plug-ins this time"" option from the Omnibox icon to load the movie. 4. After the first film is done (that's a commercial), the online broadcasting which should follow will not load. Maybe a different approach is worth considering?",Chrome,Yes,0,0,1,0,0,0,0 74,62338,Request: Add ability to block Javascript from individual sites,"Chrome Version : 7.0.517.44 (Official Build 64615) Currently, it appears that while I can block Javascript on a website by website basis, I can't block individual sources of Javascript. While this is better than Chrome has had in the past, I'm looking for more Firefox/NoScript like behavior, where you can block based on where the Javascript is being downloaded from. Lots of sites use Javascript from third parties, and I want to be able to block those third party scripts.",Chrome,Yes,0,0,1,0,0,0,0 75,62891,Security: Chromium Perminently Saves Some Browsing History in ~/.config/chromium/,"VULNERABILITY DETAILS User data is not cleared as reported. VERSION Chrome Version: [7.0.517.44] Operating System: [Ubuntu 10.04] REPRODUCTION CASE Wrench->Preferences->Tab to Under the Hood->Click ""Clear browsing data... ->Check all boxes->Select Everything for ""Clear data from this period:""->Click ""Clear browsing data"" ERROR CONDITIONS Then grep ~/.config/chromium/Local\ State for ""HostReferralList"" also ~/.config/chromium/Default/Preferences Zoom configuration by URL -- not expected that this is a permanent preference and permanently records visited URLs.",Chrome,Yes,1,0,0,0,0,0,0 76,63172,Open Link in Incognito Window tabs share state with non-incognito,"Chrome Version : 9.0.576.0 (Official Build 65344) dev [Linux 64-bit] URLs (if applicable) : http://www.google.com/ Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: N/A Firefox 3.x: No simultaneous private + non-private windows. IE 7/8: N/A What steps will reproduce the problem? 1. In a normal window, log into a site (such as Google). 2. Open a new incognito window 3. In the normal window, Right click on a link (such as ""Images""), and select ""Open Link in Incognito Window"". 5. In the Incognito window, select the newly created Google tab. 6. In the Incognito window, open a new tab and go to Google. Notice that only the new tab is not logged in. What is the expected result? Any tabs in incognito windows should share the same cookies+state, and should not interact at all with tabs in a non-incognito window. What happens instead? You can now get two tabs opened side-by-side in the same incognito window with different cookies. The non-incognito state propagates even to manually entered URLs, so any page loaded in this tab could access cookies from the non-incognito window. Please provide any additional information below. Attach a screenshot if possible. As far as I know, there don't seem to be any privacy implications--it seems just as though someone managed to drag a tab from a normal window into an incognito window. The confusing part may be that a user forgot that a certain tab was not incognito, so went to a private site with that tab. I also checked about:cache in both side-by-side tabs, and they were completely different.",Chrome,Yes,0,0,0,1,0,0,0 77,63258,Session only cookie rules don't work,"What steps will reproduce the problem? 1. clear all cookies, block cookies, clear all exceptions 2. goto mail.google.com, add a ""session only"" exception for [*.]google.com, reload, login 3. click on the calendar link What is the expected output? What do you see instead? calendar should open. instead, you go into a redirect loop Please use labels and text to provide additional information.",Chrome,Yes,0,0,1,1,0,0,0 78,63309,navigator.cookieEnabled always true,"Chrome Version : 9.0.576.0 / 7 Operating system : Windows 7 URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: OK Firefox 3.x: OK IE 7/8: OK Opera 10: OK What steps will reproduce the problem? 1. enable cookie 2. alert(navigator.cookieEnabled); 3. disable cookie 4. alert(navigator.cookieEnabled); What is the expected result? It should output ""false"". What happens instead? It output ""true"" instead! I don't have plugins installed and any exception!",Chrome,Yes,1,0,0,0,0,0,1 79,63578,Chrome seg faults trying to save new cookie settings,"Chrome Version (from the about:version page): 7.0.517.44 (Official Build 64615) Is this the most recent version: Yes OS + version: Ubuntu Linux 9.10 CPU architecture (32-bit / 64-bit): 32-bit Window manager: sawfish URLs (if relevant): anything with cookies Behavior in Linux Firefox: n/a Behavior in Windows Chrome (if you have access to it): don't have it What steps will reproduce the problem? 1. Go to Content Settings... -> Cookies -> Exceptions. Find the lines for google.com and/or www.google.com to reset them to their default (unconfigured) state. 2. Go to Content Settings... -> Cookies and select the ""Block sites from setting any data"" radio button. 3. Close the dialogs. 4. Open a tab, visit google.com 5. You should see a cookie with a red x on the right side of the url bar. Click it, and select ""Show cookies and other site data..."" 6. The bottom half of the dialog which comes up will show google.com and www.google.com, both with reveal triangles. Reveal everything all the way down. 7. Click the first line to select. Scroll to the bottom of the last thing (which is probably session storage for http://www.google.com), and shift-click to select all the rows. 8. Click ""Allow for session only"". What is the expected result? My cookie settings should get saved, and I should be able to continue browsing. What happens instead? The browser seg faults. This is 100% reproducible for me. Please provide any additional information below. Attach a screenshot and backtrace if possible. I'll generate a backtrace if you tell me how. googling didn't find anything quickly, and attaching to the zygote process and then reproducing the bug didn't work. There's about 20 children, so it's not at all clear what I should do.",Chrome,Yes,0,0,1,0,0,0,0 80,63645,"Tell the user to reload the page after modifying cookie settings, or just reload it right away?","when changing content settings in the in-tab cookies dialog, the site needs to be reloaded for the settings to take effect. we could either point this out to the user when the dialog gets closed and something was modified, or just reload right-away",Chrome,Yes,0,1,0,0,0,0,0 81,63646,"Have the option to unblock cookies for the main frame URL from within the bubble, similar to the image/javascript bubble","there should be an easy way to unblock cookies for the current site from within the content blocked bubble. either add rules to accept all cookies on the current site, or (probably better) just the mainframe URL",Chrome,Yes,1,0,1,0,0,0,0 82,63649,"On the redirect-loop error page, indicate whether cookies were blocked","If you go into a redirect loop, the cookies blocked icon is removed from the omnibox, so the user doesn't have an easy way to unblock cookies. maybe the page should also point out that you might want to check your cookie settings",Chrome,Yes,1,0,0,0,0,0,0 83,63650,show details about blocked/set cookies,"in contrast to the ""show cookies and site data"" dialog, the in-tabs cookie dialog doesn't show the cookie details. I could imagine to add tooltips to the cookies, or to use the lower half of the dialog to show the details, and make the upper half tabbed, so you'd have a tab accepted and blocked cookies.",Chrome,Yes,0,1,0,0,0,0,0 84,63652,hook up new site data types to content settings,"Feature description: there's a number of new site data types being added that should be hooked up to content settings: - check content setting type ""cookies"" before setting/reading data - show up in the ""cookies and other site data"" dialog - show up in the in-tab cookies dialog - delete on shutdown, if the users selects this option - delete in the ""remove browsing data"" dialog - delete when uninstalling an extension currently, there's indexed db, filewriter api, and spdy settings Eng owner: jochen Expected date landing on trunk: Any new strings? some describing the site data types",Chrome,Yes,0,1,1,0,0,0,0 85,63656,refactor host content settings map,"Feature description: refactor the host content settings map to be so much more versatile! Eng owner: jochen Expected date landing on trunk: some time after tabbed settings are released Any new strings? no Any implications for Google webservices (i.e. sync, translate)? no",Chrome,Yes,0,0,0,1,0,0,1 86,63662,show the origin of the site setting the cookie in the in-tab dialog instead of the domain of the cookie,"right now, when www.google.com sets a cookie for .google.com, it will show up in the in-tab cookie dialog under google.com. that's surprising to the users in two ways: when they allowed cookies for www.google.com it's strange that there's a cookie for google.com. also, if they allow cookies for www.google.com, and mail.google.com tries to access a cookie on .google.com, there will be a blocked cookie for google.com and accepted cookies for google.com",Chrome,Yes,0,1,0,0,0,0,0 87,63663,include read cookies in the in-tab cookies dialog,"right now, the in-tab cookies dialog only shows set cookies, but not read cookies. include them, too.",Chrome,Yes,0,1,0,0,0,0,0 88,63700,Add delete methods for filesystem/filewriter to browsing data deleters,"It should be possible to delete FileSystem API data (includes FileWriter data) from: - BrowsingDataRemover - ExtensionDataDeleter - on shutdown for temporary storage? Note from jochen: > the most tricky part about these kind of things is when a user wants to delete something a web page is currently using: on windows, you can't delete an open file, so there needs to be a way to signal all renderers to stop using that file. Might be worthwhile to keep this in mind while implementing it.",Chrome,Yes,1,0,0,0,0,0,0 89,63723,Chrome doesn't have clearing of active logins (aka authenticated sessions),"Chrome Version : 9.0.584.0 (Developer Build 66229) URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: Firefox 3.x: OK IE 7/8: What steps will reproduce the problem? 1.Enable a proxy that requires authentication 2.Access a page 3. What is the expected result? It should be possible to clear the active login to force re-authentication What happens instead? No clearing of active logins is available Please provide any additional information below. Attach a screenshot if possible. Clearing of cookies and other site data doesn't clear active sessions",Chrome,Yes,1,0,0,0,0,0,0 90,64050,"When we delete ""cookies"" we should handle open IndexedDB's more gracefully","When we delete ""cookies"" we should handle open IndexedDB's more gracefully. I believe at the moment, these just aren't deleted correctly. Making mstone 10 as IndexedDB isn't widely used in practice yet, but maybe we need to target 9? The easiest way to handle this might be to wire some sort of close command into IndexedDB in WebCore (and have it then lazily re-open on next use). This will become more complicated when IndexedDB becomes multi-threaded. Another possibility is to tell the user that the delete failed and that they should close open tabs. (Why didn't we do this for WebSQLDatabase?)",Chrome,Yes,1,1,0,0,0,0,0 91,64920,Refactor cookies persistent store clean-up on shutdown,"In the same effort as cleaning up DOM local storage and Indexed DB storage clean up code we want to move clean up code for the cookies persistent store too. The current state is that static methods are being called upon when the browser process is shutting down. Aim is to move this code to the point where the respective objects are being destroyed which could then happen in parallel to other shutdown activities. Moreover the refactoring will enable to hook up code for persistent store clean up on demand during the life time of the browser (triggered from the UI).",Chrome,Yes,0,0,0,1,0,0,0 92,65338,Clear browsing data doesn't remove about:dns and chrome://net-internals/ data,"Platform: Hostname: testings-mac-mini-7.local Mac OS X Version 10.6.5 (Build 10H574) Processor: 4 Intel 2.66 GHz RAM: 2048 MB Chrome: Chrome version: 9.0.597.7.7 r68111 <<>> QuickTime Player: QuickTime PlayerX: 118 What steps will reproduce the problem? 1. Clear all browsing data from Preferences > 'Under the Hood' > 'Clear Browsing Data'. 2. Visit few sites. ie. yahoo.com, amazon.com, cnn.com, engadget.com 3. Go to about:dns 4. Repeat step 1. 5. Go to about:dns Expected result: 5.1 After clearing all browsing data, about:dns and chrome://net-internals/ data also should be cleared. Actual result: 5.2 about:dns and chrome://net-internals/ still shows visited urls. Note: We could remove chrome://net-internals/#dns data using 'Clear host cache'.",Chrome,Yes,1,0,0,1,0,0,0 93,65675,Permissions granted by hosted apps don't show up in content settings,"What steps will reproduce the problem? 1. Install a hosted app that grants the ""notifications"" permission to a set of URLs (like mail.google.com) 2. Go to content settings->Notifications and hunt around for some explanation for why notifications are enabled for mail.google.com What is the expected output? What do you see instead? Expected: Maybe see the domains listed under ""Exceptions""? Actual: See nothing - there's no indication under Content Settings why notifications are enabled for the domain covered by the hosted app. Please use labels and text to provide additional information.",Chrome,Yes,0,1,0,0,0,0,0 94,66817,Incognito profile created by cookie extension API,"When an extension is allowed to run in incognito mode and enumerates all cookie stores, an incognito profile is created.",Chrome,Yes,0,0,0,1,0,0,0 95,69066,"""Block all 3rd party cookies"" doesn't block all 3rd party cookies","PRIVACY ISSUE ""Block all 3rd party cookies"" doesn't block all 3rd party cookies. VERSION: Chrome Version: 8.0.552.224 + stable (it says it is the latest) Operating System: Latest MS Windows XP REPRODUCTION STEPS In the ""Options"" window, ""Advanced options"" tab, click on ""content parameters"" (or whatever that is in English as my interface is in French by default and I can't change it). Then enable ""block all third party cookies"". Remove all cookies. Restart Chrome to make sure the change is effective. Go browse on any other website where a Facebook box is used and you can see a list of your friends ""like"" it (I personally use http://lesoir.be/ for my tests). Open facebook.com. Login (since the cookie is gone). Go back on the website and refresh the page. Result: by miracle, your friends who ""like"" it on Facebook are shown in the Facebook box. So somehow the cookies of embedded scripts aren't blocked even if on that page they should be considered as 3rd party. I expect not to see my friends list when I browse such websites when I have checked the ""block all 3rd party cookies"" checkbox.",Chrome,Yes,0,0,1,0,0,0,1 96,69732,"chrome://net-internals/ ""Dump data"" feature leaks incognito activity","PRIVACY ISSUE after using and closing an Incognito tab, traces of the activity are easily discoverable in chrome://net-internals by using the ""Dump data"" tool VERSION: Chromium Version: 10.0.612.0 (69221) Ubuntu 10.04 [dev] Chrome Version: 9.0.597.19 dev Operating System: Ubuntu Linux 10.04 REPRODUCTION STEPS 1. Open an Incognito Window 2. Navigate to http://www.secret.com/ 3. Close the Window. 4. Navigate to chrome://net-internals 5. Press the ""Dump to Text"" button 6. Search for ""www.secret.com"" in the resulting text. Incognito Mode claims: ""Pages you view in this window won't appear in your browser history or search history, and they won't leave other traces."" Unfortunately, the steps outlined above lead to viewing data that is very easy and quick to find if you know where to look, while a user of incognito mode won't realize that they've left this trace. ( By contrast, I see that as soon as I close an Incognito window, the DNS cache tab entries are cleared: chrome://net-internals/#dns -- Good! ) Mark",Chrome,Yes,0,0,0,1,0,0,0 97,69811,Exceptions for cookie clearing,"Chrome Version : 10.0.634.0 (Official Build 70875) dev I marked 'clear cookies and other site data when i close my browser' option and also i have some sites in 'cookie and site date exceptions', in Allow status The problem: after i close chrome and re-open it ,all the cookies are automatically deleted including the sites in allow status in exceptions .. the 'cookies and other data' is empty when i open chrome and when i browse to these sites all my cookie-customized settings are gone. in second thought..i think it is working as it supposed to be and the Allow is relvent only for when 'block sites from setting any data' is on,but i think that there should be an option to delete all except of specific cookies and etc like there in ccleaner for example.",Chrome,Yes,0,0,1,0,0,0,0 98,69831,Show http only flag in cookies view,"The cookies view should not only show the ""secure"" flag, but also the ""http"" flag. I guess it's enough to fix this in the dom ui version..",Chrome,Yes,0,1,0,0,0,0,0 99,71067,Implement content settings extension API,See https://docs.google.com/document/d/1IIQLPtUAuLBHjUHGVsGw6w84BMcvmwq5Ef8Esd3mC74/edit?hl=en&authkey=CKnZrZIE&pli=1#.,Chrome,Yes,1,0,1,0,0,0,0 100,72735,"""Cookies blocked"" icon shows even when cookies aren't blocked","Chrome Version : 9.0.597.94 (Official Build 73967) URLs (if applicable) : Other browsers tested: n/a Add OK or FAIL after other browsers where you have tested this issue: Safari 5: lacks functionality Firefox 3.x: lacks functionality IE 7/8: not tested What steps will reproduce the problem? 1. Switch off cookies by default. 2. Whitelist a specific domain which doesn't use any third-party cookies. 3. Go to that domain. The cookie icon appears at the right end of the address bar. 4. Click the cookie icon, click ""Show cookies and other site data"". 5. Verify that the ""The following cookies were blocked"" box is empty. What is the expected result? The icon should only show if cookies were actually blocked. What happens instead? The icon always shows. Please provide any additional information below. Attach a screenshot if possible.",Chrome,Yes,0,1,0,0,0,0,1 101,72772,client side certificates silently sent when in incognito mode,"PRIVACY ISSUE When in incognito mode, client side certificates which have previously been presented in normal mode, are silently presented again. Quite a large privacy issue. VERSION: Chrome Version: 9.0.597.86 beta Operating System: Vista 64 REPRODUCTION STEPS Visit a website which asks for a client side certificate select and present a certificate open a new incognito window on the same site certificate is silently sent automatically to the site",Chrome,Yes,0,0,1,0,0,0,1 102,75781,Cookie and Site Data Exceptions should scroll,"Chrome Version : 11.0.696.3 (Official Build 77593) dev URLs (if applicable) :chrome://settings/contentExceptions#cookies Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: NA Firefox 3.x: NA IE 7/8: NA What steps will reproduce the problem? 1. Turn on Cookie blocking 2. Add a lot of exceptions 3. View the cookie exceptions What is the expected result? With a large list, I would expect the window to be a set size and the list contents to scroll. I would expect this on all the dialog popups in the options tab that have lists of information. What happens instead? There is no scrolling, except the main window. The large amount of information causes the whole options tab to be slow and unwieldy.",Chrome,Yes,0,1,0,0,0,0,0 103,76548,Chrome shows the 'have you moved' infobar every time you search,"I am Greek but I use google.com as my default search site. With this new, just installed, version canary 12.0.706.0, every time I make a search I get a notification bar asking me whether I have moved and prompts me to use google.gr. This is good in case that I have indeed forgotten that I have moved, BUT I SHOULD BE ABLE TO DISABLE ITÉ",Chrome,Yes,0,1,1,0,0,0,0 104,77149,Support wildcard file:// patterns in content settings,"We should support content settings patterns that match all file: URLs, to allow people to whitelist local files in content settings, e.g. for plug-ins.",Chrome,Yes,1,0,1,0,0,0,0 105,77756,"removed site still visible in ""most visited"" in Win7 taskbar","PRIVACY ISSUE Removed website still visible after right-click on icon in Win7 taskbar. VERSION: Chrome Version: [10.0.648.204] + stable Operating System: Windows 7 SP1 REPRODUCTION STEPS Remove some specific website in history (but be sure that it belongs to ""most visited""). And now it will not show up in ""most visited"" on your starting page, but you can still see that removed site when you right-click on chrome icon in Win7 taskbar. It will be under ""most visited"". I can provide screenshots of this if it's not clear enough.",Chrome,Yes,1,0,0,0,0,0,0 106,77783,User opt-in/opt-out to prerender,"After discussing with UI leads, the existing ""DNS prefetch"" checkbox will be reworded and used to control whether prerender is enabled.",Chrome,Yes,0,1,1,0,0,0,0 107,78428,Allow specific plug-ins on all pages,"Chrome Version : 12.0.726.0 (Developer Build 80423) It would be nice the have a setting to allow a plugin to run on all pages and not only to allow all plugins for a page For example this is useful to allow the internal pdf the run on all pages if you have click to play enabled.",Chrome,Yes,0,0,1,0,0,0,0 108,78469,Change privacy settings text to reflect new behavior of DNS prefetch option,"http://www.google.com/support/chrome/bin/answer.py?answer=114836&hl=en-US This page mentions ""DNS Prefetch"". The option is being changed to ""Network Prediction"", and this help document will likely need to change. Please use labels and text to provide additional information.",Chrome,Yes,0,1,0,0,0,0,0 109,79304,JavaScript cannot be disabled in data URIs,"PRIVACY ISSUE JavaScript cannot be disabled in data URIs. VERSION: Chrome Version: 12.0.725.0 dev Operating System: GNU/Linux REPRODUCTION STEPS 1. Disable JavaScript in Chromium's settings 2. Browse to a data URI that contains scripts, e.g. data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg== 3. See the scripts run A malicious website that needs to run JavaScript can exploit this with a simple redirect: ",Chrome,Yes,1,0,1,0,0,0,0 110,80556,Add extension content settings provider,"Add a content settings provider that provides content settings set by extensions. Content settings set by extensions will overwrite(hide) content settings from the user preferences. So user preferences are restored once all extensions that manage content settings are uninstalled. If several extensions that set content settings are installed, the settings of the most recently install extension wins. E.g. 1) Default setting for notifications is ASK: (* , notifications, ASK) GetNotificationsSetting(""http://mail.google.com) -> ASK GetNotificationsSetting(""http://www.youtube.com) -> ASK 2) Set user preferences to: (http://mail.google.com, notifications, ALLOW) GetNotificationsSetting(""http://mail.google.com) -> ALLOW GetNotificationsSetting(""http://www.youtube.com) -> ASK 3) Install extension A that sets (http://[*.]google.com, notifications, BLOCK) (http://[*.]youtube.com, notifications, BLOCK) GetNotificationsSetting(""http://mail.google.com) -> BLOCK GetNotificationsSetting(""http://www.youtube.com) -> BLOCK 4) Install extension B that sets (http://[*.]google.com, notifications, ALLOW) GetNotificationsSetting(""http://mail.google.com) -> ALLOW GetNotificationsSetting(""http://www.youtube.com) -> BLOCK 5) Uninstall extension A and extension B GetNotificationsSetting(""http://mail.google.com) -> ALLOW GetNotificationsSetting(""http://www.youtube.com) -> ASK",Chrome,Yes,0,0,1,0,0,0,0 111,81179,Content setting exceptions based on top-level frame and individual item URL,"Chrome Version : URLs (if applicable) : any from google images cache Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: What steps will reproduce the problem? 1. disallow all javascript and plugins 2. white list only trusted sites/domains for javascript & plugins 3. include in whitelist [*.]google.com 4. Go to google images. search for any image. 5. click the image. website that hosts image loads in background. image you want loads in an AJAX overlay 6. plugins and javascript in background image load and run What is the expected result? plugins and javascript should not run, because they are not in the whitelist. What happens instead? plugins run. javascript runs. that damned ""congratulations, you've won"" advertisement plays in the background. It's an iFrame, right, that is being displayed of the website? The parent domain, even with iframes, shouldn't allow non-whitelisted things to run.",Chrome,Yes,0,0,1,0,0,0,1 112,81588,"Some websites show always ""blocked cookies"" icon","Chrome Version : 13.0.756.0 (84103) URLs (if applicable) : OS version : Mac OS 10.6.7 Behavior in Safari 3.x/4.x (if applicable): - Behavior in Firefox 3.x (if applicable): - Behavior in Chrome for Windows: not tesed What steps will reproduce the problem? 1. visit google.de or apple.com/de What is the expected result? The blocked cookies-Icon should not be in the Omnibox What happens instead? Blocked cookies-Icon is to see Can't reproduce it with 12.0.742.16 dev but I can reproduce it with 13.0.755.0 canary and 13.0.756.0 (84103) Trunk.",Chrome,Yes,0,1,0,0,0,0,0 113,81844,Implement Do Not Track,"The Do Not Track HTTP request header (""DNT: 1"") expresses a user's preference to opt out of web tracking. Firefox 4, Internet Explorer 9, and Safari 5.1 all support Do Not Track, and the header is likely to be standardized in either the IETF (http://datatracker.ietf.org/doc/draft-mayer-do-not-track/) or W3C (http://www.w3.org/Submission/web-tracking-protection/). Chromium should be brought to feature parity with its peers. I've attached a patch that adds a Do Not Track header to HTTP requests if the preference ""do_not_track"" is enabled. (This is my first Chromium work, apologies in advance for missteps.) The implementation of Do Not Track that ships should, of course, have a user-facing option.",Chrome,Yes,0,0,0,0,0,0,1 114,82039,"""Ignore exceptions and block third-party cookies from being set"" doesn't do what I want","This template is ONLY for reporting privacy issues. Please use a different template for other types of bug reports. Please see http://www.chromium.org/Home/chromium-privacy for further information. PRIVACY ISSUE In Cookies Content Settings, there's an option to ""Ignore exceptions and block third-party cookies from being set."" This seems inverted. I often want to block all third-party cookies EXCEPT for a whitelist that I allow (for specific sites that require third-party). In Chrome, my only option for using doing this is to uncheck this and allow all third-party cookies. The option should instead read ""Block third-party cookies from being set, except where allowed by host-specific exceptions"". VERSION: Chrome Version: 13.0.756.0 (Official Build 84163) canary Operating System: Mac 10.6.7 REPRODUCTION STEPS N/A because this is more of a fundamental design issue.",Chrome,Yes,0,0,1,0,0,0,0 115,83530,Add extension API to clear browsing history data,"We should have an extension API to clear browsing history data. Specifically, it should have the ability to do anything that this panel currently does: chrome://settings/clearBrowserData - browsing history (already available in history API) - download history (perhaps availbale in a downloads API) - web page cache (see also bug 54853) - cookies + other site and plugin data (cookies API provides part of this?) - saved passwords - autofill data The API should provide the same time/date range options the panel provides. Also, does one of these options clear the ""recently closed tabs"" list or the ""most visited pages"" list? Even if clearing browsing history does this implicitly, maybe we should give control over these things separately.",Chrome,Yes,1,0,0,0,0,0,0 116,83597,Change UI for password settings to reflect sync settings,"What steps will reproduce the problem? 1. Go to chrome://settings/personal 2. 3. What is the expected output? What do you see instead? Wouldn't it be much more consistent to handle Autofill and Passwords in the same way here and change the password settings from (o) Offer to save passwords () Never save passwords to?: [x] Offer to save passwords This would make the UI more consistent, would remove the opaque semantics of ""Never save passwords"" and would IMHO remove the conflict of expectations between storing passwords and sync.",Chrome,Yes,0,1,0,0,0,0,0 117,83765,WebRequest API allows extensions to manipulate web store pages,"VULNERABILITY DETAILS Using the webrequest API, extensions can redirect files in the web store (for example, javascript files) to other files that do malicious things. The attached extension redirects the Google Analytics file to one within the extension, causing an app/extension to be installed whenever the user clicks somewhere on the web store page (as the web store cannot install items without user interaction). VERSION Chrome Version: 13.0.772.0 + dev Operating System: Windows 7 SP1 REPRODUCTION CASE Attached is a sample extension in a ZIP file. jQuery is included at the top of crxgal.js for convenience, scroll down to the bottom for the code that installs the app/extension. FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION Not applicable",Chrome,Yes,0,0,0,0,0,0,1 118,83825,Add a histogram for the number of hostname patterns for content settings,Add a histogram for the number of hostname patterns for content settings,Chrome,Yes,0,1,0,0,0,0,0 119,86108,Security: FileSystem API can be used to learn about installed software on the user's computer,"FileSystem API can be used to learn about installed software on the user's computer. VULNERABILITY DETAILS Files created in the local sandboxed filesystem have an associated mime type (exposed via Blob.type). The mime type is determined by analyzing the file extension if present. Chrome has a table of well known file extensions, but when it encounters a file extension that it does not know, it consults the registry (or other OS equivalents). This can reveal whether software for a particular file extension / mime type is installed on the user's system. This seems like both a privacy leak (can be used to fingerprint users), and it also carries the risk of revealing to a potential attacker the set of available software on the system that could be targetted for other exploits (i.e., get the user to download a .foo file in hopes of exploiting FooEditor.exe). VERSION Starting with Chrome 13, any web page can perform this attack by creating files silently in the temporary file system. In previous versions of Chrome, only an installed app was able to use the file system API.",Chrome,Yes,0,0,0,0,0,0,1 120,86210,Popup's not blocked for the URL's specified in the Exception when Allow all sites to show pop-up's is selected in the content settings of the browser,"Chrome Version : 13.0.782.24 dev URLs (if applicable) : OS version : 10.6.7 Behavior in Safari 3.x/4.x (if applicable): Behavior in Firefox 3.x (if applicable): Behavior in Chrome for Windows: What steps will reproduce the problem? 1. Open chrome://settings/content. Select the checkbox Allow all sites to show pop-ups. Click on Manage Exceptions and the user should land on chrome://settings/contentExceptions#popups 2. Set [*.]www.popuptest.com as hostname pattern and select the behavior as ""Block"" 3. Refresh the browser and then open any URL (Eor eg: www.eenadu,net). A pop should be shown 4. Open the URL www.popuptest.com in a new tab and click on mouse over popup. What is the expected result? Pop up should not be shown as the URL is specified as to be blocked in the Pop Up exception. What happens instead? Popup's are shown for the blocked URL's also",Chrome,Yes,0,0,1,0,0,0,0 121,86308,QuotaManager should provide support for BrowsingDataRemover to handle quota-managed storage types properly,"There's been some discussion around how the BrowsingDataRemover should handle data deletion with time constraings (e.g. ""Obliterate the following items from: the past xxx""), but current agreement is like: we should delete the entire origin data if any data of the origin has been touched in the given timeframe. To achieve this cleanly the quota manager could provide two additional interfaces like following: void GetOriginsModifiedSince(StorageType /*pers vs temp*/, date_time, callback); void DeleteOriginData(StorageType, origin, callback); This would make it possible for BDR to handle all quota managed storaged types in a consistent way. Related discussion can be found in: issue 63700, http://codereview.chromium.org/7129018/",Chrome,Yes,0,0,0,1,0,0,0 122,87187,Browsing history deletion from chrome://history should be more straightforward,"The below data is provided based on user reports in 'GoogleFeedback'. we did not reproduce the issue. Chrome Version : 12.0.742.100 URLs (if applicable) :chrome://history/ What steps will reproduce the problem? 1.While using Chrome browser session, try clearing browsing data What is the expected result? The history stored in chrome should be deleted based on the selection made in ""Obliterate the following items from"". What happens instead? By clicking 'Clear Browsing Data' will not help in clearing the browsing history. Unless the user removes each item one by one the browser history will not be cleared. Sample Report Urls: http://goto.google.com/33183397 http://goto.google.com/38752784 http://goto.google.com/39568236 For more user reports, refer the Cluster URL below: http://goto.google.com/1261283",Chrome,Yes,1,0,0,0,0,0,0 123,87322,Verify that TemplateURLService correctly responds to URL history deletions,Currently TemplateURLService does not observe HISTORY_URLS_DELETED notification - verify that it actually processed by indirect means and implement it if necessary,Chrome,Yes,0,0,0,0,0,0,1 124,87685,"Clear search engines, content settings, etc. from Clear Browsing Data dialog?","Should we provide a (off-by-default) checkbox to clear search engines, content settings, and similar from the Clear Browsing Data dialog? If users expect to be able to nuke evidence of visiting sites from this dialog, then it seems like we should (and similar for anything else that we don't save when exiting incognito mode). I'm not sure what the right behavior is. Privacy folks?",Chrome,Yes,1,0,0,0,0,0,0 125,87938,Crash in ContentSettingsPattern::Matches,"http://crash/reportdetail?reportid=1e872d40299644a4 Product, Version Chrome_Linux , 14.0.803.0 ptype browser Thread 7 *CRASHED* ( SIGSEGV @ 0x00000000 ) 0x7f6cae2f982c [chrome - basic_string.h:624] IsSubDomainOrEqual 0x7f6cae2fb911 [chrome - chrome/browser/content_settings/content_settings_pattern.cc:401] ContentSettingsPattern::Matches 0x7f6cae58430e [chrome - chrome/browser/content_settings/content_settings_origin_identifier_value_map.cc:56] content_settings::OriginIdentifierValueMap::GetValue 0x7f6cae2ff1e7 [chrome - chrome/browser/content_settings/content_settings_pref_provider.cc:473] content_settings::PrefProvider::GetContentSetting 0x7f6cadfc8012 [chrome - chrome/browser/content_settings/host_content_settings_map.cc:243] HostContentSettingsMap::GetNonDefaultContentSetting 0x7f6cadfc9630 [chrome - chrome/browser/content_settings/host_content_settings_map.cc:281] HostContentSettingsMap::GetNonDefaultContentSettings 0x7f6cadfc9b5a [chrome - chrome/browser/content_settings/host_content_settings_map.cc:254] HostContentSettingsMap::GetContentSettings 0x7f6cae0d9f54 [chrome - chrome/browser/renderer_host/chrome_resource_dispatcher_host_delegate.cc:223] ChromeResourceDispatcherHostDelegate::OnResponseStarted 0x7f6cafafc123 [chrome - content/browser/renderer_host/async_resource_handler.cc:126] AsyncResourceHandler::OnResponseStarted 0x7f6cafafef05 [chrome - content/browser/renderer_host/buffered_resource_handler.cc:321] BufferedResourceHandler::CompleteResponseStarted 0x7f6cae0dc086 [chrome - chrome/browser/renderer_host/safe_browsing_resource_handler.cc:103] SafeBrowsingResourceHandler::OnResponseStarted 0x7f6cafaad4f9 [chrome - content/browser/renderer_host/resource_dispatcher_host.cc:1193] ResourceDispatcherHost::CompleteResponseStarted 0x7f6cafab1075 [chrome - content/browser/renderer_host/resource_dispatcher_host.cc:1152] ResourceDispatcherHost::OnResponseStarted 0x7f6caea9497d [chrome - net/url_request/url_request.cc:533] net::URLRequest::ResponseStarted ...",Chrome,Yes,1,0,0,0,0,0,0 126,88030,Expose privacy-relevant preferences via an extension API,"I'd like extensions to have access to user preferences like ""Use a web service to help resolve navigation errors"" (basically, everything under chrome://settings/advanced that we mention in the privacy whitepaper). I see two distinct use-cases: 1. I'd like to creation an app-version of the whitepaper itself that offers users the ability to change settings trivially. 2. I'd like external developers (and perhaps also us) to be able to create extensions that help guide users into certain groups of settings. I talked with bauerb@ a moment ago about this, and he's into the idea, but I'd appreciate feedback from the extension team before I start putting together a strawman CL. Specifically, if this is something that you guys agree we should implement, where should it sit? Under `chrome.contentSettings.[something]`? Thanks!",Chrome,Yes,0,0,1,0,0,0,0 127,88341,Extension-controlled settings should be disabled in chrome://settings,"When a preference which is also exposed in chrome://settings is set by an extension, the corresponding UI element there should be disabled, because extension-defined settings have higher precedence.",Chrome,Yes,0,1,1,0,0,0,1 128,88342,Managed content settings exceptions should be locked in the WebUI,"What steps will reproduce the problem? 1. Set one or two content settings exceptions via policy for e.g. CONTENT_SETTINGS_TYPE_COOKIES 2. Open the content settings exception preferences (WebUI) for cookies 3. The policy managed content settings exceptions in the exceptions list show the button to delete the list item if you move the mouse over the list item. What is the expected output? What do you see instead? List-items for managed content settings exceptions should be locked. This means they should - not be deletable, - not show a delete-button - should be marked as policy-managed Please use labels and text to provide additional information.",Chrome,Yes,0,0,1,0,0,0,0 129,88411,Change help text on Incognito NTP,"As per previous discussion, apply the following changes to the texts on the Incognito NTP to better reflect the behavior of Incognito mode and to be consistent with help center articles: ""after you close all incognito windows"" instead of ""after you close the incognito window"" and ""Other open incognito windows, which might share cookies or other state""",Chrome,Yes,0,1,0,0,0,0,0 130,90454,Feature: Add the ability to purge the SSL session cache for a browsing session,"This is a request for parity with Mozilla ( https://bugzilla.mozilla.org/show_bug.cgi?id=285440 ) and IE ( http://support.microsoft.com/kb/290345 ), but I believe the issue stand on its own as well. The SSL session cache should be something that can be cleared on demand (via Under the Hood -> Clear Browsing Data), as it represents state similar to the HTTP auth cache or cookies (when used for authentication data). In addition to clearing the SSL session cache, this should also clear the SSL client certificate cache, as clearing one without the other would prevent the use case from being realized. The use case for this feature is to allow a user to switch identities/""log out"" of a site protected by SSL client certificate authentication. As currently implemented, the user must restart the browser entirely to log out. This is somewhat related to Issue 30877/Issue 72772 (as clearing the cache per-profile would necessary require per-profile caches, allowing a per-incognito cache) and Issue 29784, which would need such selective clearing for a ""log out"" type function.",Chrome,Yes,0,0,0,1,0,0,0 131,90490,Invalid secondary content settings pattern detected while migrating the obsolete content settings preference,"DCHECK(pattern_pair.second.IsValid()) is triggered on ChromeOS development device. It is getting called from PrefProvider::MigrateObsoleteContentSettingsPatternPref() with pattern_str=""[*.]www.corp.google.com,""",Chrome,Yes,1,0,0,0,0,0,0 132,90643,Support general third-party content setting patterns,"We should have a way to specify rules for third-party origins for all content settings, not only cookies. We could do this by allowing a special secondary pattern that matches whatever the primary origin is.",Chrome,Yes,1,0,1,0,0,0,0 133,90843,"Extension-provided content scripts should execute, even when JavaScript is otherwise blocked","It would be useful for extensions like NoScript to be able to inject JavaScript that can be executed in the context of a page even when JavaScript is otherwise disabled on that page (per content settings, for example).",Chrome,Yes,0,0,1,0,0,0,0 134,91335,In-page navigations reset blocked plug-ins,"What steps will reproduce the problem? 1. Go to goto/yqxcr (sorry, internal only) 2. Run all plug-ins this time 3. Click ""daily"" What is the expected output? The plug-in created as a result of clicking on ""daily"" (an in-page navigation) should be allowed. What do you see instead? The plug-in is blocked, but the ""Run all plug-ins this time"" button in the blocked plug-in bubble is disabled. On the renderer side, we reset the |plugins_temporarily_allowed_| flag in |DidCommitProvisionalLoad| (which happens also for in-page navigations), but on the browser side we only reset the UI for a navigation to a different page (which seems to be the right behavior).",Chrome,Yes,1,0,0,0,0,0,0 135,91571,Plugin blocking controls in content settings should not apply to NaCl,"Plugin blocking controls in content settings should not apply to NaCl. Reason: NaCl is subjected to the same sandbox as JavaScript. We should probably disable NaCl if JavaScript has been disabled.",Chrome,Yes,1,0,0,0,0,0,0 136,91633,Chrome will run js and load image which had be disabled in chrome,"VULNERABILITY DETAILS Please provide a brief explanation of the security issue: I upgrade my chrome to 13.0.782.107, I found although I had disabled Images as ""Do not show any images"", and disabled js as "" Do not allow any site to run JavaScript"", when I open some sites which I never visited before, for example bbc.com, ge.com, the js and images loaded and shown in my chrome. When I refresh the page, all js and images disappear, else if I only input the URL in browser, all images and js will loaded yet. VERSION Chrome Version: 13.0.782.107 + stable Operating System: windows 7 REPRODUCTION CASE In under the hood option: I only enabled ""Enable phishing and malware protection"" In content settings option: I only enable: cookies: ""Allow local data to be set for the current session only"" and disabled all other options.",Chrome,Yes,0,0,1,0,0,0,1 137,92170,Add UMA stats for click-to-play usage,"Add UMA stats for click-to-play usage (how often are plug-ins blocked vs. click-to-play, how often are loaded afterwards, etc.)",Chrome,Yes,0,1,0,0,0,0,0 138,92457,Content settings set by a disabled extension show up in chrome://settings/content,"What steps will reproduce the problem? 1. Install an extension that uses the contentSettings API 2. Set some settings 3. Disable the extension 4. Go to chrome://settings/content What is the expected output? As the settings aren't effective, they shouldn't show up in chrome://settings/content. What do you see instead? They do.",Chrome,Yes,0,0,1,0,0,0,0 139,92818,Remove UMA users from instant field trial as soon as they opt out,"PRIVACY ISSUE UMA users should be opted out of the instant field trial (Issue 91820) as soon as they opt out of UMA. VERSION: Chrome Version: 14dev Operating System: all",Chrome,Yes,0,0,1,1,0,0,0 140,93335,it should not be possible to set inconsistent cookie content settings,"It should not be possible to allow cookies for a certain origin in the first party context, while restricting it to session only in third party context and vice versa. In the UI, this setting cannot be done anyway. The content settings UI should disallow this (and the host content settings map should probably have some sanity checks for this)",Chrome,Yes,0,0,1,0,0,0,0 141,93361,Add NP_ClearSiteData API to Flapper,"We should add an equivalent of the NPAPI NP_ClearSiteData API to Flapper, to allow clearing Flash LSOs from the browser.",Chrome,Yes,1,0,0,0,0,0,0 142,94206,"Incognito ""remembers"" Flash Cookies when Flash is open in default profile","This template is ONLY for reporting privacy issues. Please use a different template for other types of bug reports. Please see http://www.chromium.org/Home/chromium-privacy for further information. PRIVACY ISSUE Incognito ""remembers"" Flash Cookies when Flash is open in default profile. VERSION: Chrome Version: 15.0.861.0 (Official Build 97996) dev-m Operating System: Windows NT 6.1 (Windows 7 Professional SP1 64bit) REPRODUCTION STEPS 1. Open Chrome 2. Navigate to http://ie.microsoft.com/testdrive/Browser/FlashCookies/Default.html and set a flash cookie 3. Leaving the page open in the background, open an incognito window (Ctrl+Shift+N) 4. Navigate to http://ie.microsoft.com/testdrive/Browser/FlashCookies/Default.html in the incognito window and set another (different) flash cookie 5. Opening the url in another incognito tab, the flash cookie will persist as expected. 6. Close the incognito window completely, leaving only the default profile window open. 7. Open a incognito window again, and navigate to http://ie.microsoft.com/testdrive/Browser/FlashCookies/Default.html 8. Notice that the flash cookie persists between incognito sessions. If the above steps are reproduced without Flash running in the ""Default Profile"", this behaviour is not observed and the second incognito window correctly does not have any flash cookies set.",Chrome,Yes,0,0,0,1,0,0,0 143,94334,Allow developers to selectively delete data in different storage mechanisms,"Chrome is currently interpreting deleting cookies as ""site data"", which includes Local Storage, WebSQL, etc. This is too broad for a developer, who often wants fine grained control over which storage mechanism is cleared. For example, a game developer will use the File System API to locally cache assets on the client. During the developer flow, they want to simply wipe the File System clear easily (for instance, via an extension which can call chrome.experimental.clear.fileSystem()",Chrome,Yes,1,0,0,0,0,0,0 144,94343,"""Clear these settings for the feature visits"" doesn't work in incognito window","Chrome Version : 15.0.862.0 (Official Build 98198) URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: Firefox 4.x: IE 7/8/9: What steps will reproduce the problem? 1. navigate to maps.google.com on the incognito window 2. click on the radio button to enable the ""My Location is active"". ""http://maps.google.com:80 Allow"" is added on ""Geolocation Exceptions, chrome://settings"" 3. right click on the location tracking notification icon, and click on the ""Clear these settings for the feature visits"" link. 4. check the ""Geolocation Exceptions"" from chrome://settings/contentExceptions#location What is the expected result? ""http://maps.google.com:80 Allow"" should be deleted after clicking the ""Clear these ..."" link. What happens instead? ""http://maps.google.com:80 Allow"" is existed in the Geolocation Exceptions after clicking the ""Clear these settings for the feature visits"" link. Please provide any additional information below. Attach a screenshot if possible.",Chrome,Yes,1,0,1,0,0,0,0 145,95030,crash on Clear Browsing Data -> Delete cookies,"Chrome Version : 15.0.868.0, r99127 OS Version: 5.1 (Windows XP) URLs (if applicable) : chrome://settings/clearBrowserData Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: Firefox 4.x: IE 7/8/9: What steps will reproduce the problem? 1. go to chrome://settings/clearBrowserData 2. select from ""the beginning of time"" 3. mark ""Delete cookies and other site and plug-in data"" 4. click ""Clear browsing data"" What is the expected result? no crash What happens instead? crash Please provide any additional information below. Attach a screenshot if possible. UserAgentString: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.2 (KHTML, like Gecko) Chrome/15.0.868.0 Safari/535.2",Chrome,Yes,1,0,0,0,0,0,0 146,95062,can't delete a range of cookies,"Chrome Version : 15.0.865.0 OS Version: Ubuntu 11.04/64 URLs (if applicable) : chrome://settings/cookies Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: Firefox 4.x: IE 7/8/9: What steps will reproduce the problem? 1. go to chrome://settings/cookies 2. try to select a more than one hostname using shift-click and ctrl-click 3. What is the expected result? select more than one hostname to then delete them What happens instead? only one can be selected at the time Please provide any additional information below. Attach a screenshot if possible. UserAgentString: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/535.2 (KHTML, like Gecko) Chrome/15.0.865.0 Safari/535.2",Chrome,Yes,1,0,0,0,0,0,0 147,95079,Multiple profiles: Fail to delete any profiles datadirs after browser shutdown,"ENVIRONMENT Google Chrome 15.0.868.0 (Official Build 98568) dev OS Linux REPRO STEPS 1. Enable multiple profiles; 2. Create two profiles and have both of them sync; 3. Delete one of the profiles (confirm 'Are you sure you want to delete ""User 3"" and all the data associated with it from this computer? This cannot be undone!'); 4. Open the profile datadir. ACTUAL RESULTS All profile data is still available (in particular everything sync related). EXPECTED RESULTS Expected that when a profile is deleted, all its associated content will be deleted. ADDITIONAL INFO Elevating priority on this both on behalf of data not being wiped out and sync still being functional (which may present itself as a perf degradation as more and more profiles survive).",Chrome,Yes,1,0,0,0,0,0,0 148,95175,Standard window receiving auth from incognito window (http basic auth),"Chrome Version : 12.0.733.0 OS Version: Ubuntu Linux 11.04 URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: Firefox 4.x: IE 7/8/9: What steps will reproduce the problem? 1. Open url which requires HTTP BASIC AUTH, do not eneter user and password 2. Open same URL in Incognito mode 3. enter username and password in incognito mode What is the expected result? Incognito window logged in and standard window still waiting for password What happens instead? You are now logged in in both windows, without entering password in standard window Please provide any additional information below. Attach a screenshot if possible. UserAgentString: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/534.29 (KHTML, like Gecko) Chrome/12.0.733.0 Safari/534.29",Chrome,Yes,0,0,1,1,0,0,0 149,96728,"HQP backend can ""leak"" data when users delete individual URLs/date ranges","Per discussion on mailing lists (I haven't investigated this myself, so apologies for errors): Apparently the backing data structures used by the HQP have a privacy ""leak"" if the user deletes individual URLs or date ranges (as opposed to clearing all of history). In these cases, the deleted URLs are removed from the system, but the words pulled from them are left in, even if those words are not found in any remaining URLs. This means that the serialized data on disk can contain fragments of URLs and titles that the user wished to completely expunge. We've elected not to block M14 or (in my understanding) 15 on this but it needs to be fixed ASAP.",Chrome,Yes,1,0,0,0,0,0,0 150,97381,Chrome crashed when an incognito windows is opened while the settings tab is already open,"What steps will reproduce the problem? 1. Start Chrome, open the settings tab and keep it open. 2. Open an incognito window 3. Chrome crashes What is the expected output? What do you see instead? Chrome should not crash [24742:24742:2003286754681:FATAL:content_settings_policy_provider.cc(510)] Check failed: setting != CONTENT_SETTING_DEFAULT. Backtrace: base::debug::StackTrace::StackTrace() [0x7f02019936b6] logging::LogMessage::~LogMessage() [0x7f02019b85c2] content_settings::PolicyProvider::GetAllContentSettingsRules() [0x7f020104a54b] HostContentSettingsMap::GetSettingsForOneType() [0x7f0200c64922] ContentSettingsHandler::UpdateExceptionsViewFromOTRHostContentSettingsMap() [0x7f0200f004ee] ContentSettingsHandler::UpdateOTRExceptionsViewFromModel() [0x7f0200effb39] ContentSettingsHandler::UpdateAllOTRExceptionsViewsFromModel() [0x7f0200effa0a] ContentSettingsHandler::Observe() [0x7f0200eff4d1] NotificationService::Notify() [0x7f0202686636] ProfileImpl::GetOffTheRecordProfile() [0x7f020131a670] Browser::NewIncognitoWindow() [0x7f0200dffd39] Browser::ExecuteCommandWithDisposition() [0x7f0200e041e0] Browser::ExecuteCommand() [0x7f0200e05039] WrenchMenuModel::ExecuteCommand() [0x7f020148dc60] ui::SimpleMenuModel::Delegate::ExecuteCommand() [0x7f0201ca20a2] ui::SimpleMenuModel::ActivatedAt() [0x7f0201ca3830] MenuGtk::ExecuteCommand() [0x7f0200e7d67a] MenuGtk::OnMenuItemActivated() [0x7f0200e7d1b9] MenuGtk::OnMenuItemActivatedThunk() [0x7f0200e7df64] 0x7f01fcbd75de 0x7f01fcbeb598 0x7f01fcbeca76 0x7f01fcbed033 0x7f01fe7cba2e 0x7f01fe6bf56d 0x7f01fe6c0c9b gtk_custom_menu_button_release() [0x7f020145bfbf] 0x7f01fe6b1178 0x7f01fcbd75de 0x7f01fcbeb1dd 0x7f01fcbec8b9 0x7f01fcbed033 0x7f01fe7c80bf 0x7f01fe6a9643 0x7f01fe6aa71b base::MessagePumpGtk::DispatchEvents() [0x7f0201a23e32] base::MessagePumpGtk::EventDispatcher() [0x7f0201a24013] 0x7f01fe31e86c 0x7f01feddf8c2 0x7f01fede3748 0x7f01fede38fc base::MessagePumpGtk::RunOnce() [0x7f0201a23ef5] base::MessagePumpGlib::RunWithDispatcher() [0x7f0201a22340] base::MessagePumpGlib::Run() [0x7f0201a2276a] MessageLoop::RunInternal() [0x7f02019bd7cd] MessageLoop::RunHandler() [0x7f02019bd680] MessageLoopForUI::Run() [0x7f02019be922] ChromeBrowserMainParts::MainMessageLoopRun() [0x7f02015b4121] content::BrowserMainParts::RunMainMessageLoopParts() [0x7f02039afa95] BrowserMain() [0x7f02039afd72] (anonymous namespace)::RunNamedProcessTypeMain() [0x7f02018bdbcf] content::ContentMain() [0x7f02018be1c0] ChromeMain [0x7f0200bad934] main [0x7f0200bac31c] 0x7f01f8f08c4d 0x7f0200bac229 Trace/breakpoint trap",Chrome,Yes,1,0,0,0,0,0,0 151,98029,ContentSettings bubble ui is not disabled when content settings are managed by policies or extensions,"What steps will reproduce the problem? 1. Set a policy for e.g. default cookie settings. 2. Visit a website that uses cookies 3. Click on the little icon on the right side of the omnibar that indicates that cookies were blocked. What is the expected output? What do you see instead? The UI in the bubble that pops up should be disabled but it is not. Please use labels and text to provide additional information.",Chrome,Yes,0,1,1,0,0,0,0 152,98241,Changing third-party cookie blocking behavior to prevent reading as well as setting,what the summary says,Chrome,Yes,0,0,0,0,0,0,1 153,98258,Extensions managed content settings exceptions should be marked accordingly in the UI,"What steps will reproduce the problem? 1. Set a content settings exceptions (e.g for images) via an extension (e.g. the sample extension for the content settings extension API) 2. Open the content settings extension settings: chrome://settings/contentExceptions#images What is the expected output? What do you see instead? The set exception should not be editable but it is. Please use labels and text to provide additional information.",Chrome,Yes,0,0,1,0,0,0,0 154,98441,Reporting mis-detected languages exposes https urls over http,"VULNERABILITY DETAILS The option to report that Chrome has mis-detected the language of a page causes the full url to be transmitted in an unencrypted http query string. When the mis-detected page was accessed over https, the action of reporting mis-detection violates the expectation that https urls visited by the user will not be transmitted over http. VERSION Chrome Version: 16.0.891.0 dev Operating System: OS X 10.6.8 REPRODUCTION CASE Visit a page over https that is not in a language specified by the user (Preferences > Under the Hood > Languages and Spell-checker Settings) so that the ""This page is in (language) Would you like to translate it?"" bar appears. With my languages as [English (United States), English], the French Wikipedia landing page works reliably: https://secure.wikimedia.org/wikipedia/fr/wiki/Wikip%C3%A9dia:Accueil_principal From the Options menu on the bar, select the ""Not in (language)? Report this error"" item. For the example above, this opens the following url in a new tab: http://translate.google.com/translate_error?client=cr&action=langidc&u=https://secure.wikimedia.org/wikipedia/fr/wiki/Wikip%25C3%25A9dia:Accueil_principal&sl=fr&hl=en Note that the specific page I was viewing has now been exposed to the local network. If the mis-detected url had included a security token or session id, that too would have been exposed. Also note that the url is incorrectly represented on the page as being an ""http"" url with a specified port of 443: ""The web page at http://secure.wikimedia.org:443/wikipedia/fr/wiki/Wikip%C3%A9dia:Accueil_principal was detected as French."" RELATED ISSUES 42121 Previously reported to security@google.com (#879396464), re-reporting as requested.",Chrome,Yes,0,1,0,0,0,0,0 155,99588,"""Session-only"" content setting should apply to extension requests","Chrome Version : 14.0.835.202 OS Version: Debian Linux, kernel 3.0.0 URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: Firefox 4.x: IE 7/8/9: What steps will reproduce the problem? 1. Clear all cookies. 2. Set cookies to ""Allow local data to be set for the current session only"" 3. Browse to google.com and alexa.com 4. Close browser 5. Start browser 6. Cookies have not all been deleted. What is the expected result? - All cookies deleted What happens instead? - Cookies from Google.com and Alexa.com are not deleted Please provide any additional information below. Attach a screenshot if possible. - The option ""Clear cookies and other site and plug-in data when I close my browser"" does work correctly, but this also deletes cookies that should not be deleted as defined in ""Manage exceptions"" UserAgentString: Mozilla/5.0 (X11; Linux i686) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.202 Safari/535.1",Chrome,Yes,0,0,1,0,0,0,0 156,100785,disable third-party cookie experiment on M16 branch,Revert http://crrev.com/103112 on M16 branch,Chrome,Yes,1,0,0,0,0,0,0 157,100787,do filesystems resepect third-party blocking rules,"not sure about this, so filing a bug to track this",Chrome,Yes,0,0,1,0,0,0,0 158,101640,Content setting patterns don't support wildcards in file: URLs,"Chrome Version : 14.0.835.202 OS Version: 6.1 (Windows 7, Windows Server 2008 R2) URLs (if applicable) : What steps will reproduce the problem? 1. Set options to block all plug-ins 2. Attempt to open a local file in chrome that requires a plugin (IE: pdf), note plugin is blocked 3. Set to always allow plugin from that location. Reopen file, note it now works. 4. Attempt to change the file name to a wildcard to allow files open from the directory (IE: change ""file:///C:/foo/bar.pdf"" to ""file:///c:/foo/*""). Note C:/ is dropped. 5. Attempt to open similar file (IE: Another Pdf) from the directory, plugin does not work. What is the expected result? Expect to be able to add file:///C:/* to plugin exceptions to allow local files to be allowed to run plugins. What happens instead? The file:///C:/ removes the C:/, and this causes local files that require plugins to not work. Please provide any additional information below. Attach a screenshot if possible. File:/// is what's messing things up. I don't know why file:///C:/* is automatically changed. I have tried file:///* to allow plugins, but this also fails. UserAgentString: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.202 Safari/535.1",Chrome,Yes,1,0,0,0,0,0,1 159,102637,Replace/Remove all methods that return |ContentSetting|s with methods that return |Value|s,The HostContentSettingsMap only have methods that return |Value| objects instead of |ContentSetting|s.,Chrome,Yes,1,0,0,0,0,0,1 160,102654,A support for a context sensitive secondary content settings pattern that allows to match the primary pattern,"A context sensitive secondary content settings pattern (""$1"")) that allows to match the primary pattern enables user/extensions to define content settings for blocking third party content. E.g. a content settings like ""*"", ""*"", , BLOCK ""*"", ""$1"", , ALLOW Allows chrome to display only content from the same domain. The wildcard (""*"") primary pattern matches any origin e.g. http://www.example.com. But the context sensitive secondary pattern (""$1"") will only match whatever was matched by the primary pattern. So for http://www.example.com:80 chrome will only display content (e.g. images) from the same origin http://www.example.com, but not from http://www.thirdparty.com.",Chrome,Yes,1,0,0,0,0,0,0 161,102655,ContentSettingsPattern should support filesystem URLs,ContentSettingsPattern should support filesystem URLs,Chrome,Yes,1,0,0,0,0,0,0 162,102657,Create better auto-generated content setting exceptions,"The radio buttons in the blocked content bubble allow setting exceptions. We should: - Fix the generated rules so that they always override the current setting - Be a bit smarter about things like stripping ""www"" from the hostname.",Chrome,Yes,0,1,0,0,0,0,0 163,102662,Remove unused content types from ContentSettings struct,"To make it easier to add new content types, we should change ContentSettings from an array to a struct containing only the content settings that are pushed to the renderer.",Chrome,Yes,0,0,0,0,0,0,1 164,103272,DCHECK in content_settings::PrefProvider::UpdateObsoleteGeolocationPref,"Signed in to sync with personal account on ToT (r108893). A second or so after signing in, this DCHECK was hit. It appears this dcheck is from http://codereview.chromium.org/7484072 Crash stack below: [59192:2307:2083267459104444:FATAL:content_settings_pref_provider.cc(581)] Check failed: requesting_origin.is_valid() && embedding_origin.is_valid(). Backtrace: 0 Chromium Framework 0x112ed7bf base::debug::StackTrace::StackTrace() + 63 1 Chromium Framework 0x112ed75b base::debug::StackTrace::StackTrace() + 43 2 Chromium Framework 0x113367bc logging::LogMessage::~LogMessage() + 76 3 Chromium Framework 0x1133588b logging::LogMessage::~LogMessage() + 43 4 Chromium Framework 0x0fe162c4 content_settings::PrefProvider::UpdateObsoleteGeolocationPref(ContentSettingsPattern const&, ContentSettingsPattern const&, ContentSetting) + 452 5 Chromium Framework 0x0fe153a5 content_settings::PrefProvider::SyncObsoletePrefs() + 1557 6 Chromium Framework 0x0fe1437f content_settings::PrefProvider::Observe(int, content::NotificationSource const&, content::NotificationDetails const&) + 783 7 Chromium Framework 0x0fe15464 non-virtual thunk to content_settings::PrefProvider::Observe(int, content::NotificationSource const&, content::NotificationDetails const&) + 68 8 Chromium Framework 0x1057eb94 PrefNotifierImpl::FireObservers(std::string const&) + 676 9 Chromium Framework 0x1057e6e1 PrefNotifierImpl::OnPreferenceChanged(std::string const&) + 65 10 Chromium Framework 0x10594c94 PrefValueStore::NotifyPrefChanged(char const*, PrefValueStore::PrefStoreType) + 436 11 Chromium Framework 0x10593a35 PrefValueStore::OnPrefValueChanged(PrefValueStore::PrefStoreType, std::string const&) + 85 12 Chromium Framework 0x105939b3 PrefValueStore::PrefStoreKeeper::OnPrefValueChanged(std::string const&) + 67 13 Chromium Framework 0x0fa5a9bf JsonPrefStore::ReportValueChanged(std::string const&) + 143 14 Chromium Framework 0x0fa59866 JsonPrefStore::SetValue(std::string const&, base::Value*) + 486 15 Chromium Framework 0x1058b960 PrefService::SetUserPrefValue(char const*, base::Value*) + 1056 16 Chromium Framework 0x1058b51b PrefService::Set(char const*, base::Value const&) + 91 17 Chromium Framework 0x1057a7d8 PrefModelAssociator::InitPrefAndAssociate(SyncData const&, std::string const&, std::vector >*) + 2024 18 Chromium Framework 0x1057b5bf PrefModelAssociator::MergeDataAndStartSyncing(syncable::ModelType, std::vector > const&, SyncChangeProcessor*) + 1279 19 Chromium Framework 0x109186c2 browser_sync::SyncableServiceAdapter::AssociateModels(SyncError*) + 306 20 Chromium Framework 0x108d943f browser_sync::FrontendDataTypeController::Associate() + 831 21 Chromium Framework 0x108d8e1f browser_sync::FrontendDataTypeController::Start(CallbackRunner >*) + 927 22 Chromium Framework 0x108cb92c browser_sync::DataTypeManagerImpl::StartNextType() + 572 23 Chromium Framework 0x108cc45f browser_sync::DataTypeManagerImpl::TypeStartCallback(browser_sync::DataTypeController::StartResult, SyncError const&) + 2095",Chrome,Yes,0,0,1,0,0,0,0 165,103530,Geolocation is whitelisted for extensions,"What steps will reproduce the problem? 1. Install an extension *without* the ""geolocation"" permission 2. Attempt to use the geolocation API What is the expected output? You should be asked whether you want to allow geolocation. What do you see instead? You aren't. The geolocation API is automatically allowed.",Chrome,Yes,0,0,1,0,0,0,0 166,104073,Choosing 'always allow' from Cookie dialog reached via icon in URL bar fails to add exclusion,"Chrome Version : 17.0.932.0 OS Version : OS X 10.6.8 URLs (if applicable) : I noticed this while at http://www.blogger.com/home Other browsers tested: None What steps will reproduce the problem? 1. Visit website a website that shows the blocked cookie icon in the URL bar 2. Click the blocked cookie icon in the URL bar 3. When presented with the dialog, ensure the 'always allow' radio button is selected 4. Click 'Done' 5. Go and view your Cookie and Site Data Exceptions in Preferences What is the expected result? Having chosen 'Always allow www.blogger.com to set cookies' and clicked done, I'd expect to see an exception listed for either www.blogger.com, or [*.].blogger.com. What happens instead? There was no exception listed for any domain related to blogger.com Please provide any additional information below. Attach a screenshot if possible. 1. My cookie settings are: - Allow local data to be set (recommended) - Block third-party cookies from being set 2. I already had 3 exceptions, one for [*.]google.co.uk, one for [*.]google.com, and one for my own domain. Nothing was added to or removed from this list. 3. I tried at another domain, uk.yahoo.com, and saw the same behaviour, so it is not limited to one site. 4. Oddly, I only see the blocked cookie icon at www.blogger.com/home if I refresh the page. If I focus the URL and press Enter, the icon does not appear. Probably most importantly: 5. When clicking the blocked cookie icon, the 'always allow' radio button is selected by default. Clicking 'Continue blocking cookies' and then 'Always allow' before then clicking 'Done' has no effect. However, clicking 'Continue blocking', then 'Done', then the blocked cookie icon again, then 'Always allow', and then 'Done' does result in an exception being added (for ""[*.]www.blogger.com""). Note: I did not click the Reload button offered after initially clicking 'Done' to see the result. Doing so resulted in an redirect infinite loop between www.blogger.com and www.google.com/accounts.",Chrome,Yes,1,0,1,0,0,0,0 167,104291,DonÕt apply Òdelete on shutdownÓ rules when chrome auto-restarts,"If the user has selected ""delete on shutdown"" for site data (appcache, etc.), don't delete it. Also, don't delete the site data for session-only origins (localStorage etc.).",Chrome,Yes,0,0,1,0,0,0,0 168,104293,Persist POST data of navigation history when chrome auto-restarts (or crashes),.,Chrome,Yes,0,0,0,1,0,0,0 169,105141,[*.]127.0.0.1 shouldn't be a valid content settings pattern,"[*.]127.0.0.1 shouldn't be a valid content settings pattern, but it is. Also, some tests use this pattern, so we need to watch out for that when changing the behavior.",Chrome,Yes,1,0,0,0,0,0,0 170,105695,Merge prefs::kContentSettingsPatternPairs on sync,"The dictionary preference prefs::kContentSettingsPatternPairs should be merged when it is synced. This prevents local content settings patterns (exceptions) from being overwritten when sync is turned on and a previously synced version of the preferences is fetched.",Chrome,Yes,1,0,0,0,0,0,0 171,107290,"""Cookie and Site data exceptions"" doesn't work on Incognito window","Chrome Version : 17.0.963.6 (Official Build 113986) URLs (if applicable) : Other browsers tested: What steps will reproduce the problem? 1. open ""chrome://settings/content"" 2. select the Allow local data to be set (recommended) 3. click ""Manage Exceptions..."" to open the ""Cookie and Site Data Exceptions"" page 4. add [*.]www.redhat.com with Block option on the ""Exceptions below only apply to the current incognito session."" field 5. open the Incognito windows and navigate to www.redhat.com What is the expected result? The icon should be shown in Omnibox and should block the cookies What happens instead? Cookies blocked notification icon doesn't appear on the omnibox. It doesn't block the cookies. Please provide any additional information below. Attach a screenshot if possible. It works fine in Chrome 16.0.912.63(official build 113337)",Chrome,Yes,0,1,0,0,0,0,0 172,107544,No entry for default content settings should not be added to the list of incognito content settings exceptions,"What steps will reproduce the problem? 1. 2. 3. What is the expected output? What do you see instead? Please use labels and text to provide additional information.",Chrome,Yes,0,1,0,0,0,0,0 173,108291,Clearing saved HTTP auth storage,"Chrome Version : 16.0.912.63 OS Version: 2.6.41.1-1.fc15.i686 URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: OK Firefox 4.x: OK IE 7/8/9: OK What steps will reproduce the problem? 1. Open tab and page with HTTP auth (Authorization:Basic); 2. Success Log in. 3. Close tab. 4. Full delete browsing data. 5. Open tab with same page. What is the expected result? When you delete Full browsing data through Under The Hood -> Clear Browsing Data... -> check all -> clear we expect to clear all saved Authorization:Basic. What happens instead? After Full cleaning Browsing data and opening again same page we see header: Authorization:Basic with auth, which is not deleted. Maybe somewhere in datastorage it is. Please provide any additional information below. Attach a screenshot if possible. UserAgentString: Mozilla/5.0 (X11; Linux i686) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/16.0.912.63 Safari/535.7",Chrome,Yes,1,0,1,0,0,0,1 174,108671,Clearing cache also clears application data,"Chrome Version : 16.0.912.63 OS Version: 6.1 (Windows 7, Windows Server 2008 R2) URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: N/A Firefox 4.x: N/A IE 7/8/9: N/A What steps will reproduce the problem? 1. Clear Chrome's cache What is the expected result? One should be able to clear website data from Chrome's cache without losing application data. What happens instead? All data for all installed applications is cleared as well. Since Chrome's cache just grows and grows and grows and grows, it becomes necessary to clear it once in a while to speed up the browser. If doing so will automatically clear all app data, then what is the point of Chrome apps? Please provide any additional information below. Attach a screenshot if possible. UserAgentString: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/16.0.912.63 Safari/535.7",Chrome,Yes,1,0,0,1,0,0,0 175,109305,History: Removed history entry still appears in omnibox results,"This template is ONLY for reporting privacy issues. Please use a different template for other types of bug reports. Please see http://www.chromium.org/Home/chromium-privacy for further information. PRIVACY ISSUE Removing Single Site from histroy doesn't change Histroy Files VERSION: Chrome Version: 18.0.998.0 + chromium Operating System: Windows 7 SP REPRODUCTION STEPS Please provide detailed reproduction steps, and any additional information below. Include an URL demonstrating the issue and attach a screenshot if applicable. Be sure to include in your description how this issue affects your privacy. One friend asked my if it is possible to remove one single page from the suggestions in omnibox history. So i made a test with a clear chromium profil. I opened to pages. google.de and chromium.org and mozilla.com/mozilla.org after that i removed google.de and mozilla.com/mozilla.org via chrome://history, but kept youtube. i also removed google.de and mozilla.com/mozilla.org cookies when i entered g into omnibox it suggested me google.de again. So i looked into the history files in the profile and noticed the following. google.de and mozilla.com/mozilla.org was still stored in that files (view via a sqlite client or inside notepad++): -Favicons -History -History Index 2012-01 -History Provider Cache -Shortcuts i have attached several screenshot. I think it is a privacy issue because a third person could restore deleted history, when he has got a copy of the files. i can share a copy of the profile with you. I made a zipped copy if it.",Chrome,Yes,1,0,0,0,0,0,0 176,112498,Context menu on password field should not have search options,"Chrome Version : 16.0.912.77 OS Version: OS X 10.6.8 The context menu when selecting text in an input type=password field has an option to use ""Search Google For""; that option should not be there. It simply searches google for a few dot characters. C",Chrome,Yes,0,0,0,0,0,0,1 177,112981,Content exceptions added by omnibox dialog may not take effect due to existing exceptions,"Chrome Version : 18.0.1025.3 OS Version: 6.1 (Windows 7, Windows Server 2008 R2) URLs (if applicable) : http://www.livesets.us/pl/mediaobject/content/the_thrillseekers_-_nightmusic_radio_show_042_on_ah.fm_01-02-2012.html What steps will reproduce the problem? 1. Forbid javascript for hostname rule ""www.livesets.us"" 2. Go to above URL 3. Note that Javascript was blocked 4. Select ""Always allow on ..."" 5. Refresh What is the expected result? Javascript is no longer blocked What happens instead? Javascript is still blocked. Content exceptions include these: www.livesets.us Block [*.]www.livesets.us Allow Please provide any additional information below. Attach a screenshot if possible. In my opinion, if the user selects ""Always allow on ..."", any existing (sub-)rules still blocking Javascript should and can be removed. I guess similar situations exist with Cookies etc. UserAgentString: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.19 (KHTML, like Gecko) Chrome/18.0.1025.3 Safari/535.19",Chrome,Yes,0,0,1,0,0,0,0 178,113194,`browsingData` API should allow additional filtering options,"The `browsingData` API currently allows time-based deletion of all browsing data of a specific type. It should support two additional options: it should support host-based deletion, and deletion of data from otehrwise ""protected"" origins. I'd suggest changing the `RemovalRange` argument to a `Filter` object that looks something like: { ""since"": [TIMESTAMP (default: 0)], ""host"": [HOSTNAME (pattern? default: all urls)], ""protected"": [BOOLEAN (default: false)] }",Chrome,Yes,0,0,1,0,0,0,0 179,113621,browsingData extension API should support origin-based deletion,"Given an origin, delete its data: 1. Fiddle with `BrowsingDataRemover` to allow an origin filter. 2. Fiddle with extension API to expose it.",Chrome,Yes,1,0,0,0,0,0,0 180,113647,Can't set cookies while private browsing and cookies are globally disabled.,"Chrome Version : 17.0.963.46 URLs (if applicable) : What steps will reproduce the problem? 1. Disable cookies. 2. Open a private browsing window. 3. Go to a web-site that set cookies. 4. From right-side of url bar allow cookie for that web site. 5. Refresh the page as it says, to take effect. What is the expected result? Web site can set cookies till the end of that private browsing session but it can't. What happens instead? Web site still can't set cookies. When i look at the cookie settings again from the right-side of url bar, it still says that website doesn't have permsision to set any cookie. I can re-check to allow website to set cookies and refresh but it still don't works. - It was working until i ugrade Google Chrome to v17 from v16 and then that bug appeared. It's not about a single web page. I tried that situation at many many websites but i still can't set cookies.",Chrome,Yes,1,0,1,0,0,0,0 181,113688,Add Website Settings UI behind a flag,"Replace the PageInfoBubble with the WebsiteSettingsUI v1(Bubble). Hide the new bubble behind a flag. V1: - Show PageInfoBubble content - Cookies information - Provide links to Page Cookies dialog",Chrome,Yes,0,1,0,0,0,0,0 182,113735,Reset UMA client_id when a user opts out of UMA,"What steps will reproduce the problem? 1. Opt in to UMA metrics reporting by checking the ""Automatically send usage statistics and crash reports to Google"" checkbox under chrome://settings/advanced. 2. Verify that your local preferences file includes a client_id. 3. Opt out of UMA metrics reporting by unchecking this checkbox. What is the expected output? Local preferences no longer include a client_id. What do you see instead? Local preferences still include a client_id.",Chrome,Yes,0,0,1,1,0,0,0 183,113965,BrowsingDataRemover: Enable origin-based deletion for history,see title.,Chrome,Yes,1,0,0,0,0,0,0 184,113966,BrowsingDataRemover: Enable origin-based deletion for quota-managed data,"Appcache, IndexedDB, WebSQL, FileSystem",Chrome,Yes,0,0,1,0,0,0,0 185,113967,BrowsingDataRemover: Enable origin-based deletion for cache,Maybe?,Chrome,Yes,1,0,1,0,0,0,0 186,113969,BrowsingDataRemover: Enable origin-based deletion for downloads,see title.,Chrome,Yes,1,0,0,0,0,0,0 187,113971,BrowsingDataRemover: Enable origin-based deletion for localStorage,See title.,Chrome,Yes,1,0,1,0,0,0,0 188,113972,BrowsingDataRemover: Enable origin-based deletion for plugin data,Is this even possible?,Chrome,Yes,1,0,0,1,0,0,0 189,113973,BrowsingDataRemover: Enable origin-based deletion for passwords,see title.,Chrome,Yes,1,0,0,0,0,0,0 190,114584,Cookie store of SafeBrowsing should be cleared with browser data,"The cookie store owned by the SafeBrowsing context should be cleared if the browsing data is cleared via chrome://settings/clearBrowserData or via extension APIs. Please close this bug, in case you have taken care of that already.",Chrome,Yes,1,0,0,0,0,0,0 191,116253,Chrome and Chromium allowing unauthorized local storage,"Chrome Version : Chromium 19.0.1056.0 (Build 124014) and Chrome 17.0.936.56 URLs (if applicable) : www.amazon.com, www.blekko.com, www.youtube.com, www.ecosia.org, www.cnn.com, www.yippy.com Other browsers tested: NA What steps will reproduce the problem? 1. With a new install of Chrome or Chromium, disable allowing the setting of site data and 3rd party cookies in 'Under the Hood', 'Content Settings'. 2. Visit the above links 3. Now go to 'All Cookies and Site Data' in 'Content settings' to see the cookies set by those domains. 4. Close the browser, then reopen it. Some of the cookies are still there. What is the expected result? No cookies whatsoever would be stored from the session. What happens instead? Cookies from the above websites will be stored in Chrome and Chromium's cache, regardless of the browser's settings to not locally store any content. These cookies also retain their original expiration dates so some do not delete themselves for up to 24 years (Amazon). Please provide any additional information below. Attach a screenshot if possible. A 2.5 minute video demonstrating the problem http://youtu.be/mFW-4tgkBDM",Chrome,Yes,0,0,0,1,0,0,0 192,116372,"Add ""Clear App Data"" to ""Clear Browsing Data""","The ""Clear Browsing Data"" dialog should contain a check box (disabled by default) [ ] Clear App Data If checked, localStorage of hosted apps which is currently protected by ExtensionSpecialStoragePolicy should be also cleared.",Chrome,Yes,0,1,1,0,0,0,0 193,116518,Typos in privacy API documentation,"The privacy API documentation has a couple of typos (""it's"" instead of ""its"", ""you"" instead of ""your"", ""visibly"" instead of ""visually"").",Chrome,Yes,0,1,0,0,0,0,0 194,117236,"""Always allowed"" in chrome://plugins should whitelist for security infobars","Chrome Version : 19.0.1063.0 OS Version: OS X 10.8.0 URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: Firefox 4.x: IE 7/8/9: What steps will reproduce the problem? 1. 2.since version 19 i think chromium has a serious bug with plugins, they always ask for permission even i always allow them (even on the same site!!!!!) see the three screenshot of my setup so everything should be clear best regards to all 3. What is the expected result? What happens instead? Please provide any additional information below. Attach a screenshot if possible. UserAgentString: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_0) AppleWebKit/536.3 (KHTML, like Gecko) Chrome/19.0.1063.0 Safari/536.3",Chrome,Yes,0,0,1,0,0,0,0 195,117348,"Extension quota-based storage shouldn't show up in the ""Cookies and site data"" list","It looks like the BrowsingDataQuotaHelper isn't filtering origins, leading to ""empty"" extension entries without details. Extension storage is simply confusing to see appear in the ""Site data"" list, as they're not site data. We should fix this.",Chrome,Yes,0,1,0,0,0,0,1 196,118721,Extensions resources can be fetched across incognito,See bug 118693 for reproduction.,Chrome,Yes,0,0,0,0,0,0,1 197,118914,Audit of URLFetchers to respect content settings for cookies,"We are conducting an audit for all uses of URLFetchers to respect the content settings for cookies (i.e. permission to send / save cookies). Some of the URLFetchers may not need cookies at all. Please follow these instructions: If a URLFetcher uses a profile URLRequestContext ================================================ Option 1 (preferred): Disable sending and saving cookies. Reach out to the server side team and figure out whether they are ok with not receiving cookies. Then set the load flags net::LOAD_DO_NOT_SEND_COOKIES and net::LOAD_DO_NOT_SAVE_COOKIES via URLFetcher::SetLoadFlags. Option 2: If the URLFetcher needs cookies and lives in the context of a tab, this code has to follow the content settings of the profile. In order to follow the content settings of the profile, plumb the WebContents to the URLFetcher via URLFetcher::AssociateWithRenderView( web_contents->GetURL(), web_contents->GetRenderProcessHost()->GetID(), web_contents->GetRenderViewHost()->GetRoutingID()). The web_contents->GetURL() is used as ""first party"" for cookie checks. Make sure that this is correct for the service in question. If cookies are blocked due to content settings, the user is warned with a ""Blocked cookies"" indicator in the URL bar. Option 3: If the URLFetcher needs cookies but can't be associated to a tab contents. Start a discussion with chrome-privacy, chrome-ui-reviews, and the service owner on whether silently failing is ok, or whether we need some special UI. If a URLFetcher uses a system URLRequestContext =============================================== Option 1 (preferred): Reach out to the server team and add the load flags to disable cookies as described above. Option 2: Start a discussion on chrome-privacy@ (incl. the server owners) on why it's ok to send and store cookies here. If a URLFetcher uses its own URLRequestContext ============================================== Please start a discussion with the service owner and chrome-privacy whether it is possible to use one of the two options above. Note that if you use your own URLRequestContext, cookies are disabled now. I will create sub-bugs for various components and assign them to owners.",Chrome,Yes,0,0,1,0,0,0,0 198,120657,Ensure that google_util methods are not used where strong authenticity requirements are necessary,"prerender::IsGoogleDomain() contains this gem: return StartsWithASCII(url.host(), std::string(""www.google.""), true); Luckily, we already have a method google_util::IsGoogleHostname()! Oh wait, it accepts ""google."" + *any* effective TLD (as defined by net/base/effective_tld_names.dat). Google might have many domains, but not *all* of them (plus, they contain things like .local or .appspot.com). This doesn't seem to be a problem now, but it could be if we decide one day to trust all content on google domains, for example (""because we control the content anyway"").",Chrome,Yes,0,0,0,0,0,0,1 199,120848,Remove obsolete unused legacy preferences: kPopupWhitelistedHosts and kPerHostContentSettigns,"The preferences: kPopupWhitelistedHosts and kPerHostContentSettigns are deprecated since Feb 2010. They were kept around to migrate user settings. Now it's time to remove the obsolete preferences and to remove the migration code.",Chrome,Yes,1,0,0,0,0,0,0 200,121441,"Devtools data shows up in ""Cookies and site data""","Devtools data shows up in ""Cookies and site data"" in Canary (20.xxx probably). It probably shouldn't. This is almost certainly another variety of Issue #117348. I'll take a look.",Chrome,Yes,0,0,0,0,0,0,1 201,121896,The spelling service option should be available via `chrome.privacy`,The spelling service toggle is currently not available via the extension API. It should be.,Chrome,Yes,1,0,0,0,0,0,1 202,122740,Expiring/Deleting a Single History Item Failed to Delete,"What steps will reproduce the problem? 1. Visit a page. 2. Show all History. 3. Checkmark the page just visited. 4. Click ""Remove selected items"". 5. Go to chrome://omnibox and enter a term from the URL or page title of the page just visited and press ""Submit"". What is the expected output? - The page just visited should not be shown in the list of results. What do you see instead? - The HistoryQuickProvider shows the page that was supposed to be deleted.",Chrome,Yes,1,0,0,0,0,0,0 203,122776,Storage Quota Issues: queryUsageAndQuota does not show 0 after clearing cache,"Hello, (Testing on window 7 / perpper 18 / GlibC / many different chrome versions) We're facing several issues with Local Storage : 1 - With latest stable version (chrome 18.0.1025.151), there is a problem with quota management. With a clean profile, I request 1 GB of local storage. If I request the current usage with window.webkitStorageInfo.queryUsageAndQuota I get 0 Byte (correct!). After launching my application, I get 260 MB so it's correct too. But if I clean my cache in the browser, I can see that ""User Data\Default\File System"" directory is well cleaned but queryUsageAndQuota still returns 260 MB instead of 0. With an older chromium version 18.0.1025.39) it's working fine. 2 - With Chrome Canary (chrome 20.0.1096.1). We get a Not Enough Space error whatever quota we requested. We don't have this problem with chrome 19. 3 - When trying to produce a simple test example, we noticed that the pong example is not working using pepper 18 whatever Chrome version you're using. The same example from chrome web store (http://gonativeclient.appspot.com/dev/demos/sdk_examples/) is working fine. Thx, Julien",Chrome,Yes,1,1,1,0,0,0,0 204,123403,Regression: Can't delete individual cookies,"Version: 19.0.1084.24 OS: all What steps will reproduce the problem? 1. Go to chrome://chrome/settings/cookies 2. Hover over an entry to bring up the 'x' 3. Click the 'x' to remove the entry What is the expected output? What do you see instead? - Expect entry to be removed - Instead nothing happens. Can still click the ""Remove all"" button to remove all cookies, but can't delete individual cookies. Regression from 19.0.1084.15 You are probably looking for build 130891. CHANGELOG URL: http://build.chromium.org/f/chromium/perf/dashboard/ui/changelog.html?url=/trunk/src&range=130888:130891 Built at revision: http://src.chromium.org/viewvc/chrome?view=rev&revision=130891 Most likely candidate: http://src.chromium.org/viewvc/chrome?view=rev&revision=130891 Assigning to author of 130891",Chrome,Yes,1,0,0,0,0,0,0 205,123716,dns prefetching leaks dns queries when using a proxy,"Chrome Version : 20.0.1098.0 (Entwickler-Build 131548) OS Version: 6.1 (Windows 7, Windows Server 2008 R2) URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: Firefox 11: OK IE 7/8/9: Chromium has a DNS-leak! I want to route ALL traffic trough TOR (www.torproject.org) and configured using my localhost (127.0.0.1) as TOR-server. I configured Chromium using a SOCKS-proxy through the chromium-configuration, but Wireshark shows me DNS-leaks and TOR-log shows me this as well this . Disabling DNS-prefetching in the ""Configuration""-File doesn't help. Firefox 11 works great instead!",Chrome,Yes,0,0,0,0,0,0,1 206,124019,Instant may leak UMA opt-in state via URL,"Instant field trials send UMA opt-in state via the URL to Google, and this may leak in referrers when navigating from the search results page. It'd be best if Instant didn't send UMA opt-in state anywhere at all.",Chrome,Yes,0,0,0,0,0,0,1 207,125303,"Says ""This site has no cookies"" even though there are cookies on the page","Chrome Version : 20.0.1118.0 OS Version: 6.1 (Windows 7, Windows Server 2008 R2) URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: Firefox 4.x: IE 7/8/9: What steps will reproduce the problem? 1. Login to some site which uses cookies. (eg: facebook.com) 2. Go to the resources panel and check for cookies for the site. What is the expected result? 3. It shows the cookies for the site. What happens instead? 3. It says ""This site has no cookies"" - http://i.imgur.com/acrxj.png Please provide any additional information below. Attach a screenshot if possible. All sites work as expected, even the ones using cookies. I am able to see & use the cookies in my JavaScript code. They are just not showing up in the resources > cookies panel. I am using Chrome Canary along with Chrome stable (which does not have this problem). UserAgentString: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.9 (KHTML, like Gecko) Chrome/20.0.1118.0 Safari/536.9",Chrome,Yes,0,1,0,0,0,0,0 208,126180,Chrome leaks URL information when using an Incognito window,"Chrome Version : 18.0.1025.168 OS Version: OS X 10.6.8 URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: Firefox 4.x: IE 7/8/9: What steps will reproduce the problem? 1. open an incognito window 2. go to www.thegeekstuff.com (other sites show the same behaviour) 3. check /var/log/system.log What is the expected result? When using an Incognito window, I expect to *never* find any part of a url I visit in a log file. What happens instead? Instead I find this in /var/log/system.log: May 3 23:31:56 prozac [0x0-0x1f01f].com.google.Chrome[410]: [410:-1273409536:11006454327318:ERROR:ssl_client_socket_nss.cc(1534)] handshake with server www.thegeekstuff.com:443 failed; NSS error code -12263, net_error -107 Please provide any additional information below. Attach a screenshot if possible. UserAgentString: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit/535.19 (KHTML, like Gecko) Chrome/18.0.1025.168 Safari/535.19",Chrome,Yes,0,0,0,1,0,0,0 209,127247,All Notification settings are cleared after browser restart,"OS: ALL What steps will reproduce the problem? 1. Start Chrome with a clear profile directory. 2. Navigate to ""http://slides.html5rocks.com/"" 3. Set Notification settings 4. Open: chrome://settings/content and verify under Notifications exceptions that a content settings exception was created 5. Restart Chrome 6. The Notification settings is cleared What is the expected output? What do you see instead? The Notification settings should not be cleared.",Chrome,Yes,1,0,0,0,0,0,0 210,128160,Add link to CWS app details page to an app's context menu on the NTP,"In order to provide easier access to the detailed description of the app incl. any permissions that the app requested at install time, let's add a link ""Details"" to the context menue: ""Options"" ""Details"" ""Remove from Chrome"" Link: https://chrome.google.com/webstore/detail/?utm_source=chrome-ntp-icon",Chrome,Yes,0,1,0,0,0,0,0 211,128567,"""Keep local data only until I quit my browser"" should clear cookies even if ""continue where I left off"" is set","Chrome Version :19.0.1084.46 m URLs (if applicable) : Other browsers tested: none Add OK or FAIL after other browsers where you have tested this issue: What steps will reproduce the problem? 1. open browser with sites set as ""session only"" 2. OR ""Allow local data to be set for the current session only"" 3. close browser, and when reopened ""session only"" cookies have not been deleted What is the expected result? Before the update to version 19, session only cookies deleted. What happens instead? Cookies don't delete Please provide any additional information below. Attach a screenshot if possible.",Chrome,Yes,0,0,0,1,0,0,0 212,129094,Incognito split mode extension hosts cause incognito profile to never be destroyed,"If an extension is enabled in incognito and has ""incognito"": ""split"" in its manifest and it has a background page, it has a separate incognito background page managed by an IncognitoExtensionProcessManager. ProfileDestroyer::DestroyProfileWhenAppropriate does not destroy a profile as long as it has some hosts open. Of course, for an incognito profile, this would include incognito split mode background pages. What causes these extension hosts to unload is the profile getting destroyed along with its profile services (ExtensionSystem in particular). Because of the circular dependence here, though, the incognito profile never gets destroyed.",Chrome,Yes,1,0,0,0,0,0,0 213,129353,chrome.webRequest.onBeforeRequest doesn't intercept WebSocket requests,"Chrome Version : 21.0.1148.0 What steps will reproduce the problem? 1. Create an extension with ""webRequest"" and ""*://*/*"" host permissions. 2. Add listener to ""chrome.webRequest.onBeforeRequest"" in extension's code. 3. Open new tab and perform a WebSocket request to any URL. What is the expected result? Listener intercepts request. What happens instead? Request is sent without interception. Please provide any additional information below. Attach a screenshot if possible. Also, it seems that ""ws://"" and ""wss://"" schemes per se are not supported in ""permissions"" property in application manifest, same as in ""urls"" property in RequestFilter object. The extension described above intercepts other (non-WebSocket) types of requests as expected.",Chrome,Yes,1,0,0,0,0,0,1 214,131760,server bound certificates installed for 3rd party sites while blocking 3rd party cookies is on,"Steps to reproduce: 1) check block 3rd party cookies 2) clear all server bound certs (clear site data in BDR) 3) surf sites using dblclk ads You'll end up with certs from dblclk",Chrome,Yes,0,0,1,0,0,0,0 215,131763,App extends should be displayed in the cookies content settings exception editor,"Since app extends storage protect site data, they should also be displayed in the content settings editor for cookies & site data",Chrome,Yes,0,1,0,0,0,0,0 216,132409,Integrate Flash LSOs into chrome://settings/cookies,We should show Flash LSOs in the cookie list under chrome://settings/cookies.,Chrome,Yes,0,1,0,0,0,0,0 217,132410,Integrate Flash storage settings with content settings,Flash storage settings (which site is allowed to set Flash LSOs) should be integrated with Chrome content settings instead of doing their own thing.,Chrome,Yes,0,0,1,0,0,0,0 218,133768,Have 3rd Party Cookie Blocking Override Other Rules,"Feature Request. PRIVACY ISSUE The current behavior for Chromium is that if you block 3rd party cookies and then create per-host rules ie: https://* always allow, http://* temporarily allow, the 3rd party cookie rule is 'overridden.' I'm proposing that this behavior change so that 3rd party cookies rule takes precedence over other rules. VERSION: Chrome Version: Any Operating System: Any REPRODUCTION STEPS",Chrome,Yes,0,0,0,0,0,0,1 219,134051,Third party cookie blocking page action opt-back-in seems broken,"Chrome Version : 21.0.1180.0 OS Version: OS X 10.7.4 Enable ""block third party cookies"" Try to go to http://www.vibrantmedia.com/whatIsIntelliTXT.asp?ipid=33551&cc=us&server=msnbc.us.intellitxt.com If you hover over ""disable"" and then click ""Click here to disable"" it redirects you through msnbc.us.intellitxt.com and then back to vibrantmedia.com. For me, I see the page action showing ""cookies have been blocked"". If I choose ""always allow www.vibrantmedia.com to set cookies"" and then try clicking disable again, I go through the redirect and still see the blocked cookies icon and the note that cookies were blocked on this page. It seems like even though I'm trying to explicitly allow the cookies, I have no way to do that (or, the cookies are being allowed but it's still telling me they were disallowed). Something seems wrong here.",Chrome,Yes,1,0,0,0,0,0,0 220,134825,Databases and filesystems not being removed after using the Clear Browsing Data dialog,"Version: 20.0.1132.43 (Official Build 143823) OS: Mac OS X (not reproducible on Windows/Chrome OS) What steps will reproduce the problem? 1. Visit a couple of websites 2. Open chrome://settings/clearBrowserData and select ""Delete cookies and other site and plugin data"" ""from the beginning of time"" 3. Open chrome://chrome/settings/cookies What is the expected output? Cookies should be removed. What do you see instead? Cookies are still present for all websites (not only hosted apps).",Chrome,Yes,1,0,0,1,0,0,0 221,134983,Clear browsing data clearing some cookies/data even when Delete cookies is unchecked,"Chrome Version : 21.0.1180.11 OS Version: 6.1 (Windows 7, Windows Server 2008 R2) URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: Firefox 4.x: IE 7/8/9: What steps will reproduce the problem? 1.Sign in to Google apps mail or Facebook 2.Clear browsing data with everything checked but Delete Cookies What is the expected result? All cookies/local data remain. History and other things are cleared. What happens instead? Some cookies are retained, but user signed out of Gmail and Facebook Please provide any additional information below. Attach a screenshot if possible. UserAgentString: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.11 Safari/537.1",Chrome,Yes,1,0,0,0,0,0,0 222,135407,Implement website settings bubble on Mac (behind a flag),Implement the Mac version of the website settings bubble (Issue 113688).,Chrome,Yes,0,0,1,0,0,0,0 223,136391,Print Preview should be able to print via cloud print even with third party cookies blocked,Cloud print doesn't work properly from print preview if third party cookies are blocked. This is correct behavior but we need to give a more informative error message.,Chrome,Yes,0,1,0,0,0,0,0 224,136487,Add visual indicators to the cookies dialog for local storage that belongs to protected origins,"We want to add visual indicators to chrome://chrome/settings/cookies to indicate which local storage elements belong to hosted apps and won't be removed using the Clear Browsing Data dialog (unless you choose the hosted apps checkbox). The UI changes include: - Adding the app's icon to the individual local storage entry - Adding a tooltip to the icon, similar to our solution for geolocation and notifications (""Set by app: $appname"")",Chrome,Yes,0,1,0,0,0,0,0 225,137412,per_host_zoom_levels is not cleared with browser history,"This template is ONLY for reporting privacy issues. Please use a different template for other types of bug reports. Please see http://www.chromium.org/Home/chromium-privacy for further information. PRIVACY ISSUE Chrome stores the custom zoom levels for domains in user profile Preferences under 'per_host_zoom_levels'. When deleting browser history, these zoom levels are not deleted, leaving behind a trail of domains that the user has visited. VERSION: Chrome Version: Canary on OSX (22.0.1205) Operating System: OS X Service Pack 2 (10.6.8) REPRODUCTION STEPS 1. visit lots of websites and set different zoom levels 2. go to settings -> show advanced settings (urgh) -> clear browsing data 3. there is no option to delete zoom data, nor is it deleted by default, leaving behind a list of hosts that the user has visited and adjusted the zoom level for while giving the impression that no history data remains on the machine",Chrome,Yes,1,0,0,0,0,0,0 226,137414,"dns_prefetching is never deleted, leaking user visit data","PRIVACY ISSUE When a user deletes their Chrome browser history they are not given the option to remove the DNS prefetch data from Preferences. This results in almost all sites and domains the user has visited in remaining behind in the user preference file despite the browser history having been deleted. VERSION: Chrome Version: Canary on OSX (22.0.1205) Operating System: OS X Service Pack 2 (10.6.8) REPRODUCTION STEPS 1. Use Chrome 2. Delete browser history 3. notice that dns_prefetching array is still in Preferences file 4. Report it to Google",Chrome,Yes,1,0,0,0,0,0,0 227,139154,"""Google Chrome Dev would like to access your contacts"" dialog on 10.8 when submitting a form","Chrome Version : 22.0.1207.1 OS Version: OS X 10.8.0 What steps will reproduce the problem? 1. Use 10.8 2. Submit a bug report What is the expected result? Form submits. What happens instead? I get a dialog that says ""Google Chrome Dev would like to access your contacts"" [cancel] [ok]. I suppose that's because form autofill is looking at address book data for autofill? UserAgentString: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_0) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/22.0.1207.1 Safari/537.1",Chrome,Yes,0,1,0,0,0,0,0 228,139592,Extension resources should only be loadable in contexts the extension has permission to access,"Per discussion in http://codereview.chromium.org/10792008/, `example.com` should not be able to load (or be tricked into loading) resources from an extension with only host permissions for `evil.com`.",Chrome,Yes,0,0,1,0,0,0,0 229,139997,Cookies are not deleted when site data is cleared,"Chrome Version : 22.0.1221.0 OS Version: 5.1 (Windows XP) URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: Firefox 4.x: IE 7/8/9: What steps will reproduce the problem? 1. go to: chrome://chrome/settings/clearBrowserData 2. select the from ""beginning of time"" and tick all the items 3. click on ""clear browsing data"" 4. go to: chrome://chrome/settings/cookies What is the expected result? Cookies should have been deleted What happens instead? Cookies have not been deleted Please provide any additional information below. Attach a screenshot if possible. UserAgentString: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.3 (KHTML, like Gecko) Chrome/22.0.1221.0 Safari/537.3",Chrome,Yes,1,0,0,0,0,0,0 230,140041,The test WebsiteSettingsTest.ShowInfoBar has a memory leak,"Suppression (error hash=#09E4D080CB32DAD9#): For more info on using suppressions see http://dev.chromium.org/developers/tree-sheriffs/sheriff-details-chromium/memory-sheriff#TOC-Suppressing-memory-reports { Memcheck:Leak fun:_Znw* fun:_ZN15WebsiteSettings11OnUIClosingEv fun:_ZN36WebsiteSettingsTest_ShowInfoBar_Test8TestBodyEv } ------------------------------------------------------------------------ Suppression (error hash=#F0BB06EB69EBD61E#): { Heapcheck:Leak fun:WebsiteSettings::OnUIClosing fun:WebsiteSettingsTest_ShowInfoBar_Test::TestBody }",Chrome,Yes,0,0,0,0,0,0,1 231,140450,Implement Website Settings Popup on Linux (GTK),Implement the Linux (GTK) version of the website settings UI (Issue 113688).,Chrome,Yes,0,0,1,0,0,0,0 232,140910,Local storage data not being removed when clearing browsing data,"Chrome Version : 21.0.1180.60 m URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: Firefox 4.x: IE 7/8/9: What steps will reproduce the problem? 1. Go to a page that adds data to local storage 2. Press Shift-Ctrl-Del 3. Select ""the beginning of time"" in the ""Obliterate the following items from"" drop-down 4. Check all boxes including ""Clear Data from Hosted Apps"" 5. Press ""Clear Browsing Data"" button 6. Refresh the page page containing the local storage data What is the expected result? The local storage data should have been cleared/removed. What happens instead? The local storage data is *not* cleared. Please provide any additional information below. Attach a screenshot if possible.",Chrome,Yes,1,0,0,1,0,0,0 233,141062,Disable Website Settings on Windows by default,On Windows the Website Settings UI should be disabled by default like on all other platforms. The Website Settings UI should be made available via a switch on the about:flags page.,Chrome,Yes,0,1,0,0,0,0,1 234,141102,Flash camera and microphone Manage exceptions leaks website history,"PRIVACY ISSUE Chrome Version : 21.0.1180.57 OS Version: 3.2.0-27-generic #43-Ubuntu x86_64 x86_64 x86_64 GNU/Linux What steps will reproduce the problem? pre:0. assume content settings -> flash camera and microphone manage exceptions is empty 0. content settings -> flash camera and microphone, block all sites 1. open gmail 2. check content settings -> flash camera and microphone -> manage exceptions 3. mail.google.com is listed What is the expected result? I'd HOPE that all sites i visit that request this feature are not listend when block all sites is listed. i should be notified in the address bar when a feature is blocked, and have to explicitly add them, just like third party cookie blocking, which is EXACTLY how this should work (well done on that one ) What happens instead? sites are added to content settings -> flash camera and microphone -> manage exceptions",Chrome,Yes,0,0,1,0,0,0,0 235,141285,Browser crash @ ash::internal::WebNotificationContentsView::Update,"Google Chrome : 22.0.1229.0 (Official Build 150285) dev Chrome OS : 2723.0.0 (Official Build) dev-channel stumpy URLs (if applicable) : http://www.corp.google.com/~johnnyg/notify.html What steps will reproduce the problem? 1. navigate to http://www.corp.google.com/~johnnyg/notify.html 2. enter ""testing"" on the ""Title"" field 3. enter ""123"" on the ""Replace ID:"" field 4. click on ""request permission => Allow"" to show desktop notifications 5. click on the ""show"" button, then the notification appears on bottom right corner on the monitor 6. try to click on ""show"" button few times more. 7. close the notification dialog box 8 click on the ""show"" button What is the expected result? What happens instead? Browser crashes after clicking on the ""show"" button. Crash ID : http://crash.corp.google.com/reportdetail?reportid=b174509e40d099ee ====================== Thread 0 *CRASHED* ( SIGSEGV @ 0xfffffffffffffff8 ) 0x7f4d1b5503db [libstdc++.so.6.0.16] + 0x000a73db] 0x7f4d1f8c59cf [chrome] - ash/system/web_notification/web_notification_tray.cc:84] ash::internal::WebNotificationContentsView::Update 0x7f4d1f8c52ab [chrome] - ash/system/web_notification/web_notification_tray.cc:780] ash::WebNotificationTray::Bubble::UpdateBubbleView 0x7f4d1d9be12f [chrome] - ./base/callback.h:388] MessageLoop::RunTask 0x7f4d1d9c14c7 [chrome] - base/message_loop.cc:472] MessageLoop::DeferOrRunPendingTask 0x7f4d1d9c1891 [chrome] - base/message_loop.cc:686] MessageLoop::DoDelayedWork 0x7f4d1d9f211c [chrome] - base/message_pump_glib.cc:105] WorkSourceDispatch 0x7f4d1c0a6f44 [libglib-2.0.so.0.3000.2] - gmain.c:2441] g_main_context_dispatch 0x7f4d1c0a7597 [libglib-2.0.so.0.3000.2] - gmain.c:3089] g_main_context_iterate 0x7f4d1c0a781b [libglib-2.0.so.0.3000.2] - gmain.c:3152] g_main_context_iteration 0x7f4d1d9f1e0e [chrome] - base/message_pump_glib.cc:199] base::MessagePumpGlib::RunWithDispatcher 0x7f4d1d9cf871 [chrome] - base/run_loop.cc:45] base::RunLoop::Run 0x7f4d1d335751 [chrome] - chrome/browser/chrome_browser_main.cc:1411] ChromeBrowserMainParts::MainMessageLoopRun 0x7f4d1f560b60 [chrome] - content/browser/browser_main_loop.cc:471] content::BrowserMainLoop::RunMainMessageLoopParts 0x7f4d1f560c1c [chrome] - content/browser/browser_main_runner.cc:99] BrowserMainRunnerImpl::Run 0x7f4d1f55ef08 [chrome] - content/browser/browser_main.cc:21] BrowserMain 0x7f4d1d955a2f [chrome] - content/app/content_main_runner.cc:634] content::ContentMainRunnerImpl::Run 0x7f4d1d953f30 [chrome] - content/app/content_main.cc:35] content::ContentMain 0x7f4d1cf383c7 [chrome] - chrome/app/chrome_main.cc:32] ChromeMain 0x7f4d1ac1041c [libc-2.15.so] - libc-start.c:234] __libc_start_main 0x7f4d1cf382a8 [chrome] + 0x007842a8] Please provide any additional information below. Attach a screenshot if possible.",Chrome,Yes,1,0,0,0,0,0,0 236,141591,Chrome does not gracefully recover from a broken Cookies SQLite database,"If you have a broken Cookies SQLIte database (i.e. PRAGMA integrity_check returns errors), Chrome won't complain about the profile being busted, but can't load the cookies anyway. If the cookies database is corrupted, we should notify the user (similar to profile corruption), and delete and recreate the Cookies database",Chrome,Yes,1,1,0,0,0,0,0 237,141710,Chrome locks/crashes when programatically adding a large block list via the chrome.contentSettings API,"Chrome Version: 21.0.1180.75 m Chrome OS Version: ALL OS API: chrome.contentSettings OS: Tested on Win7 and Mac OS X Please specify Area-* of the system to which this bug/feature applies (add the label below). Steps To Reproduce: 1. Create a large domain list (700 +) (blockList in my example below); 2. loop through the code and add via your addon: $.each(blockList, function () { var setting = 'block'; var pattern = ""*://*."" + this.domain + ""/*""; chrome.contentSettings['cookies'].set({ 'primaryPattern': pattern, 'setting': setting, 'scope': (incognito ? 'incognito_session_only' : regular') }); }); 3. run. Expected Result: Block list is added to the user's Content Settings. Actual Result: -Chrome slows down, locks up all tabs and eventually fails. Adding images and JS to the loop/block process increases instability. Feels like a memory/resource issue, seems worse when Chrome Tools are open. How frequently does this problem reproduce? (Always, sometimes, hard to reproduce?) -Always What is the impact to the user, and is there a workaround? If so, what is it? -I have been regularly successful with lists that are smaller than 400 domains. Please provide any additional information below. Attach a screen shot or log if possible. *Let me know if you need a link to my block list",Chrome,Yes,0,0,1,0,0,0,1 238,142555,Chrome doesn't delete cookies after browser was closed,"Chrome Version : 21.0.1180.77 OS Version: 6.1 (Windows 7, Windows Server 2008 R2) URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: Firefox 4.x: IE 7/8/9: What steps will reproduce the problem? 1. Open settings and specify ""Save data only till browser will be closed"". (In my native locale: _________ ________ ____ ____ __ ________ ___-___________) 2. Set to Restore previous session. (Start with the same pages that were opened before closing browser) 3. Open and login e.g. to GMail 4. Close browser 5. Open Browser What is the expected result? Session data were deleted. If you were logged in to some system - browser should be able to open it (cause all data were deleted.) I now that there is a ""feature"" that Chrome stores session data to be able to restore it after Close - Open cycle. But from my point of view Cookies policy is more prioritized. What happens instead? Session data were not deleted. Browser able to open all sites. Please provide any additional information below. Attach a screenshot if possible. UserAgentString: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.77 Safari/537.1",Chrome,Yes,0,0,0,1,0,0,0 239,142775,Content Settings feature test case review for feasible browser test coverage,"This is to evaluate how much test cases can be covered by browser test. Test team can then decide if pyauto tests are needed or manual tests are required. You can find all test cases for Cookie, Image, Javascript, Plugins, Popup, in Content Settings. Please help us fill out column C and D, ""if browser test can be added?"" and "" need a pyauto tests?"" test cases are listed here under ContentSettings SHEET: http://goto/automatecontentsettingstest Note: features under Content Settings but not listed here are not in scope of this test plan. features such as handler, fullscreen, web intent... etc. are not covered in this test plan.",Chrome,Yes,0,0,0,1,0,0,1 240,143922,The Website Settings UI should auto select the connection tab in case of an https error or mixed content,"The Website Settings UI displays two tabs. One tab for displaying site permissions (permissions tab) and another tab for displaying connection information (connection tab). By default the permissions tab is selected (visible) when the Website Setting UI is opened. If a site contains mixed content or even has an https error (e.g. bad cert) the connection tab should be selected instead of the permissions tab when the Website Settings UI is opened. In such a case a user is most likely interested to see the connection information when they open the Website Settings UI.",Chrome,Yes,0,1,0,0,0,0,0 241,144203,Website Settings Popup crashes when a setting is changed,On Windows and Linux the chrome crashes when a permissions is changed in the Website Settings Popup.,Chrome,Yes,1,0,0,0,0,0,0 242,144645,On Linux the Website Settings UI does not display the correct permission icon if the default setting is BLOCK,"On Linux: If the default setting for a site permission is set to block, then the corresponding permission icon misses the little red cross.",Chrome,Yes,0,1,0,0,0,0,0 243,144648,On Linux the Website Settings UI does not display managed permissions,On Linux the Website Settings UI does not display managed permissions.,Chrome,Yes,0,1,0,0,0,0,0 244,144874,Clear browsing data never completes with PPAPI flash plugin disabled,"Chrome Version : 21.0.1180.83 OS Version: 5.1 (Windows XP) URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: Firefox 4.x: IE 7/8/9: What steps will reproduce the problem? 1.Disable PPAPI plugin pepflashplayer.dll using chrome://plugins/ 2.CTRL-Shift-Del to delete browsing data 3.Clear browsing data 4.Wait a long time... What is the expected result? Browsing data delete and dialog box exited What happens instead? Process never completes. Please provide any additional information below. Attach a screenshot if possible. It appears the data is deleted but the process then hangs. Specific settings were delete everything, all of time. If I enable PPAPI and try again problem goes away. Note: PPAPI disabled because of slow performance eg issue 142102 UserAgentString: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.83 Safari/537.1",Chrome,Yes,1,0,0,0,0,0,0 245,145680,Clear browsing data does not remove segments for bookmarked pages,"Steps to reproduce: 1) Start with a fresh profile. 2) Visit any site that does not have a redirect (www.google.com works for me in the us) and bookmark the page. 3) Wait for topsites to update to show the page you visited. 4) Clear browsing data, all types, from the beginning of time. After clearing browsing data, the topsites entry for the bookmarked page stays visible. The root cause is that we appear to be deleting entries from the visits table, but we leave the entry in the urls table (because the url is bookmarked). Somehow this is also causing us to keep the entries in the segments and segment_usage tables, which causes the topsites entry to stick around. We should probably also delete segments in this case. This bug was uncovered by r150531 (https://chromiumcodereview.appspot.com/10830210), which changed the BrowsingDataRemover to explicitly specify a delete_end time. Previously, we passed ""0"" for both delete_begin and delete_end, which went through a special case in ExpireHistoryBackend which simply dropped the whole history db. Now, since we specify a delete_end time, we have to manually delete individual visits from the db, even when we're clearing from the beginning of time.",Chrome,Yes,1,0,0,0,0,0,0 246,148718,Issues with the exceptions settings page for location settings,"Fix a couple minor bugs around geolocation settings display 1) The entry with the embedder pattern shouldn't display 'undefined'. 2) The entry with the embedder pattern should not be deletable. 3) The 'embedded on' entries should be indented. See attached screenshots",Chrome,Yes,0,1,0,0,0,0,0 247,149400,Add third-party cookie blocking control,"Originally reported in http://b.corp.google.com/6113913 (Posted on March 05 2012 01:24 GMT by eisinger) Feature: Content settings Chrome for Android Version: 16.0.912.77 Android Version: ICS Device: Galaxy Nexus Please plumb the third-party cookie & site data blocking check box to the Chrome for Android UI (under content settings)",Chrome,Yes,0,0,1,0,0,0,0 248,150075,The arrow of the dropdown button on the Website Settings UI is not displayed on Linux (Ubuntu Precise Pangolin),"The arrow of the dropdown button on the Website Settings UI is not displayed on Linux (Ubuntu Precise Pangolin). See attached screenshot: On the right to the text ""Allowed by default"" there should be a small arrow displayed",Chrome,Yes,0,1,1,0,0,0,0 249,150685,Website Settings Bubble: Identity tab can be cut off,"Version: 23.0.1262.0 OS: Mac 10.8.1 See attached screen shot. The ""What do these mean?"" link gets cut off. When activated, this tab should animatedly resize the bubble window so that the window size always fits the content (no cutting off the bottom, no extra awkward whitespace).",Chrome,Yes,0,1,0,0,0,0,0 250,150750,improve appearance of websites settings bubble on gtk,make it look like the other platforms.,Chrome,Yes,0,1,0,0,0,0,1 251,150771,Browser tests for DNT settings,"The WebUI should have browser tests that verify that the DNT settings work as expected, i.e., the pref service sees what the user clicks on chrome://settings -> Show advanced settings... -> DNT.",Chrome,Yes,0,0,0,0,0,0,1 252,151575,chrome://bookmarks has bogus Website Settings popup,"What steps will reproduce the problem? 1. go to chrome://bookmarks 2. click on the icon next to the URL What is the expected result? Expected result is a bubble that says ""You are viewing a secure Google Chrome page."", simular to what's shown for chrome://history. What happens instead? Instead, you get a full Website Settings popup that shows some bogus info. See screenshot.",Chrome,Yes,0,1,0,0,0,0,0 253,151589,Make the permissions dropdowns on the Website Settings UI focusable via TAB,Make the permissions dropdowns on the Website Settings UI focusable via TAB.,Chrome,Yes,0,0,1,0,0,0,1 254,151615,Clear Browsing Data does not clear http_server_properties,"PRIVACY ISSUE The ""Clear Browsing Data"" feature allows user to delete their history of visited sites. This only works partly, while Chrome shows an empty history, the ""Preferences"" file in the Chrome profile directory still contains a list of visited domain names. This way, a user's surf history can be reconstructed if an attacker has permission to read the user's browser profile, which is a privacy problem especially on computers used by multiple users (family computers, public computers etc.). VERSION Chrome Version: 21.0.1180.89 stable, using the package from google.com Operating System: Ubuntu 12.04.1 LTS REPRODUCTION STEPS 1. Visit a website that supports SYDY (e.g google.com, youtube.com) 2. Take a look at Chrome's history. The website should be listed there. 3. Run ""Clear Browsing Data"". Make sure you tick the checkbox which clears the history. 4. Now look again at Chrome's history, all enries should be deleted. 5. Close Chrome and go to your profile directory. On my machine, it's ~/.config/google-chrome. 6. In the subfolder ""Default"" is a JSON file named ""Preferences"". Search with your text editor for ""http_server_properties"". You will get a list of all SPDY-enabled domains you have visited. FIX SUGGESTION Change the ""Clear Browsing Data"" function so it deletes the ""http_server_properties"" list too. -- I am not a native speaker, so don't hesitate to ask me if you didn't understand something.",Chrome,Yes,1,0,0,0,0,0,0 255,153150,"tabs.executeScript raises ""Unknown error"" when invoked on an Incognito Tab","Chrome Version: 22.0.1229.79 OS Version: 6.1 (Windows 7, Windows Server 2008 R2) What steps will reproduce the problem? 1. I've made a bare-bones extension that clearly shows the problem. 2. Install the test-extension; check ""Allow in Incognito"", in the Extensions page. 3. Click the extension button (black lamp), in an incognito window and you'll see an error in the background-page of the extension. What is the expected result? tabs.executeScript should work in Normal as well as in Incognito tabs. What happens instead? ""Error during tabs.executeScript: Unknown error. -- chromeHidden.handleResponse"" @sendRequest:22 UserAgentString: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.4 (KHTML, like Gecko) Chrome/22.0.1229.79 Safari/537.4",Chrome,Yes,0,0,1,0,0,0,0 256,154280,Show protected storage tooltip on hovering over a storage element in chrome://settings/cookies,"Currently, the cookie dialog has a ""title"" attribute that adds a tooltip for protected storage to the respective app icong of a storage element in the list. Since the icon is quite small, please move the ""title"" attribute to the containing DIV (thus making it show when the user hovers over the respective storage element).",Chrome,Yes,0,1,0,0,0,0,0 257,155903,mail.google.com and chrome.google.com not being cleared on browser exit,"64bit version (For Debian/Ubuntu) 22.0.1229.94 on Linux Mint 13 (MATE) No fancy options changed or extensions installed. On startup I open a new tab. (So no continuing where I left off). I have ENABLED ""Keep local data only until I close my browser"". So why is ""mail.google.com"" and ""chrome.google.com"" not cleared on exit? How can I force this? Even specifically listing them in exception as ""clear on exit"" does not help. Looks like a privacy/security issue to me.",Chrome,Yes,0,0,0,1,0,0,0 258,156371,Chrome crashes when the Website Settings UI is opened on sites for which a media content settings exception was set.,"Chrome crashes when the Website Settings UI is opened on sites for which a media content settings exception was set. [22860:22860:1017/183240:FATAL:content_settings_utils.cc(97)] Check failed: valid. Backtrace: base::debug::StackTrace::StackTrace() [0x7f1acb377fce] logging::LogMessage::~LogMessage() [0x7f1acb3b3242] content_settings::ValueToContentSetting() [0x7f1ace247ba1] WebsiteSettings::PresentSitePermissions() [0x7f1acf8039dd] WebsiteSettings::WebsiteSettings() [0x7f1acf801ca5] WebsiteSettingsPopupGtk::WebsiteSettingsPopupGtk() [0x7f1acf798de5] WebsiteSettingsPopupGtk::Show() [0x7f1acf7989c1] BrowserWindowGtk::ShowWebsiteSettings() [0x7f1acf6fc579] chrome::ShowPageInfo() [0x7f1acf6d1517] LocationBarViewGtk::OnIconReleased() [0x7f1acf754c89] LocationBarViewGtk::OnIconReleasedThunk() [0x7f1acf758e20] 0x7f1ac1274dd8 0x7f1abf6acca2 0x7f1abf6bdd71 0x7f1abf6c5d7e 0x7f1abf6c6242 0x7f1ac138f191 0x7f1ac1272f63 0x7f1ac12732c3 base::MessagePumpGtk::DispatchEvents() [0x7f1acb35263e] base::MessagePumpGtk::EventDispatcher() [0x7f1acb352525] 0x7f1ac0ee7cac 0x7f1abf1edd53 0x7f1abf1ee0a0 0x7f1abf1ee164 base::MessagePumpGlib::RunWithDispatcher() [0x7f1acb3502a0] base::MessagePumpGlib::Run() [0x7f1acb3507f9] MessageLoop::RunInternal() [0x7f1acb3b8c76] MessageLoop::RunHandler() [0x7f1acb3b8b25] base::RunLoop::Run() [0x7f1acb3f5622] ChromeBrowserMainParts::MainMessageLoopRun() [0x7f1ace835e02] content::BrowserMainLoop::RunMainMessageLoopParts() [0x7f1ac3f56a9f] (anonymous namespace)::BrowserMainRunnerImpl::Run() [0x7f1ac3f5a487] BrowserMain() [0x7f1ac3f54ea6] content::RunNamedProcessTypeMain() [0x7f1ac3f2ac0a] content::ContentMainRunnerImpl::Run() [0x7f1ac3f2badd] content::ContentMain() [0x7f1ac3f2a214] ChromeMain [0x7f1ace086c4e] main [0x7f1ace086c02] 0x7f1abbf2476d 0x7f1ace086b09 Trace/breakpoint trap (core dumped)",Chrome,Yes,1,0,0,0,0,0,0 259,156632,DNT help URL is 404,"Version: 24.0.1297.0 OS: All When enabling DNT, the Learn More link goes to: https://support.google.com/chrome/bin/answer.py?hl=en&answer=2790761&p=settings_do_not_track which returns a (pretty) 404 error. (Reported externally, just copying it into the bug tracker.)",Chrome,Yes,0,0,0,0,0,0,1 260,158353,The CollectedCookiesDialog displays cookie duplicates,"The CollectedCookiesDialog shows some cookies as host only and as ""domain"" cookie at the same time. Steps to reproduce the issue: 1) Start a trunk build of chrome using a prestine profile. 2) Visit https://mail.google.com (don't login). 3) Open the collected cookies dialog via the Website Settings UI. 4) Check the cookies for mail.google.com. 5) Some cookies appear twice. The only difference is that the domain value of one cookie starts with a ""."" .",Chrome,Yes,0,1,0,0,0,0,0 261,161758,Blocked Flash LSO access should be reported,"Chrome Version : 23.0.1271.64 URLs (if applicable) : espn.go.com Other browsers tested: Firefox 16.0.2 OK Add OK or FAIL after other browsers where you have tested this issue: Safari 5: Firefox 4.x: IE 7/8/9: What steps will reproduce the problem? 1. Completely close Chrome 2. Open chrome anew 3. Go to espn.go.com What is the expected result? Video play button should appear anywhere there is a video and I should be able to play video on the website. I am able to use flash on other websites. Maybe it is ESPN's fault? What happens instead? Nothing appears besides a black abyss of nothingness. Please provide any additional information below. Attach a screenshot if possible. I have restarted my entire computer and that did not do anything to fix the problem.",Chrome,Yes,0,0,1,0,0,0,0 262,164227,Show Google Now notifications in Chrome,Show Google Now notifications in Chrome.,Chrome,Yes,0,1,0,0,0,0,0 263,164340,Still go back to the previous page after clearing the history,"Chrome Version : URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: Firefox 4.x: IE 7/8/9: What steps will reproduce the problem? 1. Clearing the history does not disable the back button. Still go back to the previous browsed page. What is the expected result? Back button should be disabled as firefox does What happens instead? Can go back to the previous pages. Please provide any additional information below. Attach a screenshot if possible.",Chrome,Yes,1,0,0,0,0,0,0 264,164584,Translate should load resources over HTTPS even if the original page is loaded via HTTP,"According to http://code.google.com/p/chromium/issues/detail?id=164547#c4, Translate's resources should be loaded over HTTPS. At the moment, they don't seem to be. In today's Canary (25.0.1350.0 (Official Build 171238) canary) I just tested translating `http://www.ru.nl` into English: the following resources are loaded: * http://translate.googleapis.com/translate_static/css/translateelement.css * http://translate.googleapis.com/translate_static/js/element/main.js * http://translate.googleapis.com/translate_static/js/element/10/element_main.js * http://translate.google.com/gen204?nca=te_li&client=te_lib&logld=v10 * http://www.google.com/images/icons/product/translate-32.png * http://translate.googleapis.com/translate_a/t?anno=3&client=te_lib&format=html&v=1.0&logld=v10 * http://translate.googleapis.com/translate_a/t?anno=3&client=te_lib&format=html&v=1.0&logld=v10 It looks like we ought to be loading things over HTTPS, based on the strings in translation_manager.cc, but practically, I'm seeing HTTP connections. Thanks!",Chrome,Yes,0,0,0,0,0,0,1 265,165251,Clear browsing data does not close any open sockets that used the channel ids being deleted,"Version: 25.0.1354.0 OS: Windows/ Mac Note: When you visit a site like https://google.com (secured google.com) a channel id is created during establishment of connection with the server. If channel id for that particular domain already exists it will not create new channel id else it will create a new channel id. What steps will reproduce the problem? 1.Go to about settings/clearbrowserdata and clear all browsing data. 2.Go to about:settings/cookies and you will find it empty. Browse https://google.com 3.Go to/refresh about:settings/cookies and you will see channel id created for google.com and gstatic.com 4.Repeat steps 1, 2, 3 What is the expected output? What do you see instead? Clear browsing data used to clear the channel ids too and on Step 4 you will see channel ids getting created. What happens instead is clear browsing data is not deleting channel ids and thus a new connection is not found and you do not see channel ids created in about:settings/cookies. This used to work fine before.",Chrome,Yes,1,0,0,0,0,0,0 266,165903,1993 should fall back to offline mode when suggestions are off,"UserAgent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/25.0.1354.0 Safari/537.21 Steps to reproduce the problem: 1. Use a Chrome dev version with the latest new tab page, which puts the google search box in the middle of the New Tab page. 2. Make sure the following boxes in the Settings menu are turned off: ""Enable Instant for faster searching"" and ""Use a prediction service to help complete searches and URLs typed in the address bar."" 3. Start typing keywords into the omnibox. What is the expected behavior? Autocomplete only using previously used keywords and URLs from the local database, without going out over the network to get new words to autocomplete with. What went wrong? The omnibox is now autocompleting using Google search results over the network, rather than respecting my settings and searching the local browsing history only. Did this work before? Yes Yesterday Chrome version: 25.0.1354.0 Channel: dev OS Version: Windows 7 x64 I realize that this is a trial run of the new Embedded Search API, as noted on the Chromium blog yesterday: http://blog.chromium.org/2012/12/faster-simpler-search-in-chrome.html But this new behavior clearly breaks user expectations for the two Settings listed. If the intent is to back out the new Embedded Search functionality soon after a short trial run, no big deal, but if it's here to stay it needs to respect the settings that disallowed autocomplete using Google services over the internet before. Also, it's a bit disconcerting that my New Tab page was changed today, even though I did not update the browser. I'm pretty sure the update to 25.0.1354 kept my old New Tab page, only for it to change today without warning or a browser update.",Chrome,Yes,0,0,0,1,0,0,0 267,168996,Allow deleting cookies from the Collected cookies dialog,The collected Cookies dialog should allow users to delete individual cookies.,Chrome,Yes,1,0,0,0,0,0,0 268,170638,All buttons Chrome that open the clear-browsing-data dialog should use the same label,"All buttons in Chrome that open the clear-browsing-data dialog should use the same label: ""Clear browsing data ..."" On the history page (chrome://history) the button uses the label ""Clear all browsing data ..."", while on the settings page (chrome://settings/) in the section ""Privacy"" the button uses the label ""Clear browsing data ..."".",Chrome,Yes,0,1,0,0,0,0,0 269,170644,"On the ""Clear browsing data"" dialog swap the position of the ""Emtpy the cache"" and ""Delete cookie"" checkboxes","On the ""Clear browsing data"" dialog swap the position of the ""Emtpy the cache"" and ""Delete cookie"" checkboxes.",Chrome,Yes,0,1,1,0,0,0,0 270,171236,Prompt enterprise users to create a new profile at signin time,"As a privacy enhancement, enterprise users will be prompted to create a new profile at signin time, to give them the option to keep their existing private data from being synced to their enterprise acct. This also allows enterprise admins to prohibit signout (only allow deleting enterprise profiles) to help avoid accidental leakage of enterprise data through syncing with different accounts. Shooting for M26, if time allows.",Chrome,Yes,0,1,1,0,0,0,0 271,171974,Incognito windows should clear clipboard upon destruction,"PRIVACY ISSUE What steps will reproduce the problem? 1. Open incognito window 2. Copy something from it 3. Close the last incognito window Clipboard should be empty. Implementation: We save a pointer to OffTheRecordProfile in the clipboard whenever user copies something from incognito window. OffTheRecordProfile's destructor tries to read this pointer from the clipboard. If it equals |this|, clipboard is to be erased. Places where Clipboard::Write should be tweaked: 1) clipboard_message_filter.cc 2) omnibox 3) render_view_context_menu.cc (when user clicks 'copy link address')",Chrome,Yes,0,0,0,1,0,0,0 272,172228,Security: POST data sent to the wrong page after a refresh on a 500 Internal Server Error redirection target page,"VULNERABILITY DETAILS Scenario: a web page receives user's input using POST, then redirects the user to another URL. page_a.php INPUT form => POST to page_b.php => redirect to page_c.php If the redirection target page (page_c.php) raises a 500 Internal Server Error and the user hits the Refresh button, the browser displays the ""Confirm form resubmission"", afterwards sends user input data to page_c.php. I could reproduce this behaviour even if pages were on different domains. IMHO this behaviour could lead to personal data and credentials disclosure, for example on OAuth2 single sign-on processes, where authentication is performed by content provider and then user is redirected to another website. VERSION Chrome Version: 24.0.1312.56 m Stable Operating System: Windows XP Professional Service Pack 3 REPRODUCTION CASE 3 server side PHP scripts (attached also): page_a.php (user input form)
page_b.php (data processing and user redirection) page_c.php (redirection target) ",Chrome,Yes,0,0,0,0,0,0,1 273,174816,Do not import dummy file:// history entires from IE on first run,"UserAgent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.57 Safari/537.17 Steps to reproduce the problem: 1. Clear all bookmarks, history, and stored data on Chrome 2. Start Chrome with the flag --user-data-dir= , where is an empty folder other than the one Chrome normally uses. Click past Issue 174590. 3. Close Chrome 4. Navigate to /Default/ 5. View with SQLite Browser or text editor the files ""History Index YYYY-MM."" where YYYY-MM represents last month and this month 6. Notice URLs and URL-formatted local filenames (file://) in the history indexes What is the expected behavior? If I create a new user directory from scratch and immediately examine it, I expect any history files within it to be empty of URLs. I especially expect it to be empty of local filenames from last month. What went wrong? Starting Chrome with a blank User Data directory causes it to create a Default profile containing History Index files for this month and last month. The History Index files contain URLs and local filenames accessed on the computer during those months. Did this work before? N/A Chrome version: 24.0.1312.57 Channel: stable OS Version: 5.1 (Windows XP) Some of the saved filenames were recently downloaded with Chrome while others were not. I'm quite certain that at least a few of these were never downloaded or typed into the omnibox. I have no idea where the information for these newly-created files is coming from. It isn't coming from the History Index of my usual Chrome user directory, as that doesn't even have a History Index for last month, nor does the History Index it does have contain any of these file names. In any case, all of these filenames were last accessed *before* the new user directory was ever created. Their presence in the index is definitely not ""expected behavior"". While I'm sure this behavior is a boon for forensic investigators in criminal cases, it would also be helpful to the security agency of an authoritarian country. I expect Chrome to be fully transparent about what information it collects and stores.",Chrome,Yes,0,0,0,1,0,0,0 274,175385,Searches in incognito are accessible in normal tab,"Steps to reproduce the problem: 1. Open incognito-tab 2. Search for something (hello world) by entering it in address space 3. Close the incognito-tab 4. Open a normal tab 5. Go to the google.com 6. Place the cursor on the searchbox of the google-website. What is the expected behavior? I shouldn't get the incognito search-query in the historylist of the google-website in the normal tab. What went wrong? I'm getting the incognito search-query in the historylist of the google-website. Did this work before? N/A Chrome version: 23.0.1271.100 Channel: stable OS Version: 6.1 (10B144)",Chrome,Yes,0,0,0,1,0,0,0 275,175419,Add preference and policy to disable clearing browser history,"Add a preference and policy to disable clearing browsing history and download history. Other browser data types (cache, password, etc.) should not be affected. The history extension API, browsingData extension API, and item removal from the history page should all be controlled by this, as well as the Clear Browsing Data UI itself.",Chrome,Yes,0,0,1,0,0,0,0 276,175447,Chrome Push Messaging Documentation regarding Privacy,"Hi Mark, In https://code.google.com/p/chromium/issues/detail?id=144185#c10 you mentioned that you intend to write into the API documentation that Chrome Push Messaging should not contain PII. Could you please do that? Thanks, Dominic",Chrome,Yes,0,0,0,0,0,0,1 277,177490,"If you pin a profile shortcut to the taskbar, it won't get deleted on profile deletion","Per discussion with gab@ on https://codereview.chromium.org/12319020/ and with some investigation, it seems like there's no good solution here. The (undocumented) API we currently use to unpin taskbar shortcuts (which is ShellExecute(""taskbarunpin"") in shortcut.cc), is not able to differentiate between profile and non-profile shortcuts, even if we set an appid on the shortcut. For example, if a non-profile shortcut gets pinned and we call the API on a profile shortcut, then the non-profile shortcut also gets deleted. With the change in https://codereview.chromium.org/12330026/, we don't unpin anything from the taskbar anymore on profile shortcut deletion, which fixes the above issue, but makes it so that if you had manually pinned a profile shortcut from the desktop, it will not get removed from the taskbar when the profile is deleted. Setting different AppIds on the shortcuts does not help, so unfortunately there doesn't seem to be a good way to solve this other than: a) manually pinning/unpinning things instead of using ShellExecute(""taskbarunpin""), which apparently causes other problems according to gab b) inspecting what was what pinned before, then unpinning all the shortcuts using the API and then pinning-back the ones that should have been kept d) having proxy exe targets for each profile, so that ShellExecute(""taskbarunpin"") can distinguish them, that just redirect to the main chrome exe (eww) c) finding a different API that does what we need None of these options seem particularly attractive. :\",Chrome,Yes,1,0,0,1,0,0,0 278,179056,Removing data for hosted apps in chrome://settings/cookies doesn't update display,"Steps to reproduce: * Install the GMail app * Go to chrome://cookies * Select mail.google.com in the host list * Select an individual item, like file system * Click on remove Note that nothing happens. If you collapse and expand the item, it updates though.",Chrome,Yes,0,1,0,0,0,0,0 279,179901,,"We should add a: if (CommandLine::ForCurrentProcess()->HasSwitch(switches::kDisableBackgroundNetworking)) { return; } guard around the calls made by the PluginsResourceService",Chrome,Yes,0,0,0,0,0,0,1 280,180181,Search is not working fine in Search Cookies,"Version: 27.0.1429.0 (Official Build 185827) OS: MAC What steps will reproduce the problem? 1. Open Chrome://settings > Advanced Settings > Content Settings > All Cookies and site data 2. Type a letter (Ex:l) in Search cookies -- Cookies search results are adjusted as per the search critera 3. Type the whole word (Ex: login) -- corresponding cookies are displayed 4. Delete the cookies and click on Done 5. Again click on All Cookies and Site data and Type the Whole word (Ex: login) used in Steps 3 & enter 6. Observe the Cookies results What is the expected output? What do you see instead? Expected: No Cookies should be displayed on screen since deleted the cookies. Actual: Seems to be search is not happening, all cookies are displayed. This is a non- Regression issue. Give a space after the search word in Step5, search is working. But not with Enter Please use labels and text to provide additional information.",Chrome,Yes,1,0,1,0,0,0,0 281,207522,FR: Smart third-party cookies (3rd Party blocked from setting cookies unless it already has cookies),"Chrome Version : Google Chrome 27.0.1438.8 (Official Build 187776) dev I'd like to see enabled by default the smart way of dealing with third-party cookies that Mozilla proposed at https://blog.mozilla.org/privacy/2013/02/25/firefox-getting-smarter-about-third-party-cookies/ Patch is available at https://bugzilla.mozilla.org/show_bug.cgi?id=818340 and can be summarized with: 1) if an origin is first-party, it has ordinary cookie permissions 2) if an origin is third-party a) if the origin already has cookies, it has ordinary cookie permissions b) otherwise, the origin gets no cookie permissions",Chrome,Yes,0,1,0,0,0,0,0 282,215520,ibus-mozc: no way to delete input history,"Chrome Version : tot (M22) OS Version : tot (M22) The Japanese IME does not have a way to delete input history data from the local disk. Would it be possible to add a menu for IME in 'Wrench - Privacy - Clear browsing data' ? The Chinese Pinyin IME probably has the same problem, but I'm not 100% sure.",Chrome,Yes,1,0,0,0,0,0,0 283,225672,"Unable to login to Google Apps if ""Block sites from setting any data"" is set and google is added to exceptions","Version: 28.0.1458.0 OS: ALL Precondition: Clear all the history What steps will reproduce the problem? 1. Launch Chrome and navigate to chrome://settings/content, select ""Block sites from setting any data"" and click on Done 2. Login to gmail.com to see a prompt asking to turn on cookies funtionality. 3. In omnibox click on cookies exception icon and select ""Always allow accounts.google.com to set cookies"", then click on reload button. 4. In the pop-up, click on continue. It prompts to login to gmail again and entering the password doesn't login, instead login screen becomes a loop.",Chrome,Yes,1,0,0,0,0,0,0 284,225758,Instant Extended doesn't work when JS & Images are blocked,"Chrome Version : 28.0.1459.0 (Official Build 191575) canary What steps will reproduce the problem? 1. enable ""Instant extended API"" from about:flags 2. open chrome://settings/content#content 3. select ""Do not show any images"" under the Image field. 4. open New Tab page, chrome://newtab What is the expected result? Chrome's internal chrome://* page shouldn't be affected by content settings What happens instead? Images are blocked on the NTP. Image doesn't appear. Please provide any additional information below. Attach a screenshot if possible.",Chrome,Yes,0,1,0,0,0,0,0 285,232378,Provide a sample content settings pattern in the content settings exceptions dialog,"On Content Settings exceptions dialogs: Replace the placeholder text (""Add a new hostname pattern"") of the input field used for adding new exceptions with a string containing a sample pattern (""[*.]example.com"") to show users an example of a content settings pattern.",Chrome,Yes,1,1,0,0,0,0,0 286,234181,"Tab running in Incognito shows just as ""Tab"" in Task Manager","Version: 27.0.1453.46 dev OS: ChromeOS What steps will reproduce the problem? 1. Open Incognito window. 2. Navigate to a site. 3. Open Task Manager and find the entry for the site. What is the expected output? What do you see instead? Expect that the site's Task Manager entry is clearly marked as Incognito. Instead, the tab is displayed as ""Tab: "".",Chrome,Yes,0,1,0,0,0,0,0 287,236244,"Removing profiles can lead to local data remaining, despite message saying the reverse","Seen on OS X 10.8.3 Chrome consumer channel version 26.0.1410.65 Removing a profile in chrome://settings/ displays this message ""Are you sure you want to delete ""Chromium.org"" and all the data associated with it from this computer? This cannot be undone!"" Users may imply from this that their profile data will definitely be deleted from the computer. However on my Mac under ""/Users/jimblackler/Library/Application Support/Google"" I can see folders for profiles that have certainly been removed. The data contained within is unencrypted SQLite databases so any user with access to the files could presumably read the data (I looked at Most Visited to confirm this was available). I ran a test and saw that in my test at least, these folders are sometimes deleted for removed users at the point Chrome is closed. However a proliferation of leftover test profile folders on my machine suggests to me that this doesn't always happen; perhaps if Chrome crashes rather than shutting down normally they remain?",Chrome,Yes,1,0,0,0,0,0,0 288,238123,"The French chrome privacy page is broken, when navigated from Arabic page","Chrome Version : 28.0.1500.0 (Developer Build 198362) URLs (if applicable) : http://www.google.com/chrome/intl/ar/privacy.html What steps will reproduce the problem? 1. Open chrome browser and navigate to the http://www.google.com/chrome/intl/ar/privacy.html url 2. Wait for page to load. Observe that Arabic Google Privacy is displayed 3. Now from the language dropdown, select francais (French) to view the content in French language. Actual result: After selecting french from the dropdown, page is redirected to HTTP 404 page. (Since the url shows Arabic text)",Chrome,Yes,0,1,1,0,0,0,0 289,242767,Bring back old incognito clipboard behavior,"crbug.com/171974 introduced some clipboard-clearing behavior; we tried it out and didn't like it, so let's revert.",Chrome,Yes,1,0,0,0,0,0,0 290,244176,DCHECK when creating an allow exception for popups on the about:blank,"DCHECK when creating an allow exception for popups on the about:blank via the blocked popups bubble. Steps to reproduce the issue: 1) Navigate to about:blank in a tab. 2) Open the JS console and do ""var w = window.open();"". 3) Attempt to allow ""about:blank"" via the content settings bubble for blocked popups 4) Hit a DCHECK Stacktrace: [3591:3591:0523/154442:FATAL:content_settings_origin_identifier_value_map.cc(152)] Check failed: primary_pattern.IsValid(). [0x7fd45858693e] base::debug::StackTrace::StackTrace() [0x7fd4585d36cf] logging::LogMessage::~LogMessage() [0x7fd45ba220f4] content_settings::OriginIdentifierValueMap::SetValue() [0x7fd45b5befd2] content_settings::PrefProvider::SetWebsiteSetting() [0x7fd45b373d13] HostContentSettingsMap::SetWebsiteSetting() [0x7fd45b373f16] HostContentSettingsMap::SetContentSetting() [0x7fd45b374115] HostContentSettingsMap::AddExceptionForURL() [0x7fd45c8cc72d] ContentSettingSingleRadioGroup::AddException() [0x7fd45c8cc5b5] ContentSettingSingleRadioGroup::~ContentSettingSingleRadioGroup() [0x7fd45c8d23c5] ContentSettingPopupBubbleModel::~ContentSettingPopupBubbleModel() [0x7fd45c8d0625] ContentSettingPopupBubbleModel::~ContentSettingPopupBubbleModel() [0x7fd45c8d0649] ContentSettingPopupBubbleModel::~ContentSettingPopupBubbleModel() [0x7fd45c910662] base::DefaultDeleter<>::operator()() [0x7fd45c910624] base::internal::scoped_ptr_impl<>::~scoped_ptr_impl() [0x7fd45c9105e5] base::internal::scoped_ptr_impl<>::~scoped_ptr_impl() [0x7fd45c9105c5] scoped_ptr<>::~scoped_ptr() [0x7fd45c90c795] scoped_ptr<>::~scoped_ptr() [0x7fd45c90baab] ContentSettingBubbleGtk::~ContentSettingBubbleGtk() [0x7fd45c90b9d9] ContentSettingBubbleGtk::~ContentSettingBubbleGtk() [0x7fd45c90bd38] ContentSettingBubbleGtk::BubbleClosing() [0x7fd45c903ee7] BubbleGtk::~BubbleGtk() [0x7fd45c903e69] BubbleGtk::~BubbleGtk() [0x7fd45c9059e2] BubbleGtk::OnDestroy() [0x7fd45c905e18] BubbleGtk::OnDestroyThunk() [0x7fd44aed2ca2] g_closure_invoke [0x7fd44aee3d71] [0x7fd44aeec069] g_signal_emit_valist [0x7fd44aeec212] g_signal_emit [0x7fd44c8e82c0] [0x7fd44aed9000] g_object_run_dispose [0x7fd45c905a09] BubbleGtk::OnHide() [0x7fd45c905e48] BubbleGtk::OnHideThunk() [0x7fd44aed2ca2] g_closure_invoke [0x7fd44aee3d71] [0x7fd44aeec069] g_signal_emit_valist [0x7fd44aeec212] g_signal_emit [0x7fd44c9e1a7e] gtk_widget_hide [0x7fd44c9e1b8c] [0x7fd44aed9000] g_object_run_dispose [0x7fd45c9054f8] BubbleGtk::Close() [0x7fd45c90bb6a] ContentSettingBubbleGtk::Close() [0x7fd45c90c459] ContentSettingBubbleGtk::OnCloseButtonClicked() [0x7fd45c90d0e8] ContentSettingBubbleGtk::OnCloseButtonClickedThunk() [0x7fd44aed2eca] [0x7fd44aeeb711] g_signal_emit_valist [0x7fd44aeec212] g_signal_emit [0x7fd44c817845] [0x7fd44aed2ca2] g_closure_invoke [0x7fd44aee4179] [0x7fd44aeec069] g_signal_emit_valist [0x7fd44aeec212] g_signal_emit [0x7fd44c81666d] [0x7fd44c8bfdd8] [0x7fd44aed2ca2] g_closure_invoke [0x7fd44aee4339] [0x7fd44aeebd4e] g_signal_emit_valist [0x7fd44aeec212] g_signal_emit [0x7fd44c9da191] [0x7fd44c8bdf63] gtk_propagate_event [0x7fd44c8be2c3] gtk_main_do_event [0x7fd45855b18b] base::MessagePumpGtk::DispatchEvents() [0x7fd45855b075] base::MessagePumpGtk::EventDispatcher()",Chrome,Yes,1,0,0,0,0,0,0 291,248562,ChromeÕs condescending and accusatory messages should be removed,"UserAgent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.31 (KHTML, like Gecko) Chrome/26.0.1410.64 Safari/537.31 Steps to reproduce the problem: Method A: 1. Open the Clear Browser Data dialog (e.g., Ctrl+Shift+Del) 2. Repeat step 1 within 24 hours Method B: 1. Open the History page (e.g., Ctrl+H) 2. Check the box next to an item 3. Click the Remove Selected Items button What is the expected behavior? Chrome should display the Clear Browsing Data or History Item Removal dialogs in a neutral, professional manner. What went wrong? Chrome displays condescending messages that talk down to users and practically accuse them of illicit behavior. Did this work before? Yes Older versions (donÕt know the exact version). Chrome version: 26.0.1410.64 Channel: n/a OS Version: 6.1 (Windows 7, Windows Server 2008 R2) In the past, Chrome would behave like a professional when users request the Clear Browser Data dialog or remove items from the History page. Unfortunately more recent versions (twenty-something and up) throw a demeaning and accusatory message in your face when you open the dialogs: > Psst! Incognito mode (Ctrl+Shift+N) may come in handy next time. In addition to presuming that users are novices and donÕt know how to use Chrome, in this context, the suggestion that users use Incognito mode implies that the user has summoned the dialog in order to cover their tracks and erase evidence of their illicit browsing activities such as visiting unsavory sites. This is absurd because there are plenty of reasons that a user may open the dialog, such as flushing the cache or cookies in order to get a misbehaving page to work correctly. I can only imagine how many web-developers are faced with this message countless times each and every day! Even erasing an item from the history is not necessarily due to misdeeds on the userÕs part. For example, many users have Googled some topic and opened the first several pages in the search results, then later noticed that one of them was at a site that they would prefer not to have listed in their history. (Anybody who is snooping through the history is unlikely to view the other sites surrounding a site visit and will instead just use keywords, which indicate the mere existence of the visit rather that than the context.) So it is ridiculous to assume that a user always plans visits to undesirable sites ahead of time in order to use Incognito mode. It is one thing for Chrome to have personality and be a little quirky (e.g., Sad Chrome pages), but this message goes too far. At the *very least*, this message should be displayed only once, not every day and certainly not EVERY TIME the dialogs are opened each day. It would be even better to remove it altogether because there are better and less insulting ways to educate users about Incognito mode if that was the goal of the message.",Chrome,Yes,0,1,0,0,0,0,0 292,249246,Open in incognito window doesn't work in panel,"VULNERABILITY DETAILS User is tricked into opening a link in a regular window that they meant for an incognito window. VERSION Asking user. REPRODUCTION CASE 1. Run the hangouts extension 2. Get a message with a link 3. Right click and open in an incognito window. The link opens in the primary profile.",Chrome,Yes,0,0,1,0,0,0,0 293,251024,"Plug-in settings: ""Click to play"" vs. ""Block all"" confusion","In the Content Settings, under Plug-ins, you have the options ""Click to play"" (CTP) and ""Block all"" (BA). CTP really means ""left-click to play"", and BA really means ""right-click to play"". BA is a stronger guarantee, because it uses native UI (a native context menu) to show the user the options. But I suspect many users shy away from it because it sounds like Flash will never work if you use this option; really, you can still have Flash just as much as with CTP. We'd like for users to realize that, so I suggest changes to the strings: CTP: Stays the same: ""Click to play"" BA: Becomes ""Right-click to play"" (Or whatever the relevant local platform gesture is for ""right-click"": ""long press"", ""context menu"", ""three-finger press"", et c.)",Chrome,Yes,0,1,0,0,0,0,0 294,251742,ExtensionBrowsingDataTest.BrowsingDataRemovalMask is flaky,"This test is failing frequently since early Tue Jun 18. Primarily but not exclusively on Linux and Linux Chromium OS: http://test-results.appspot.com/dashboards/flakiness_dashboard.html#group=%40ToT%20Chromium&testType=browser_tests&tests=ExtensionBrowsingDataTest.BrowsingDataRemovalMask http://test-results.appspot.com/dashboards/flakiness_dashboard.html#group=%40ToT%20ChromeOS&testType=browser_tests&tests=ExtensionBrowsingDataTest.BrowsingDataRemovalMask There are two related changes in the preceding day: http://crrev.com/206917 http://crrev.com/206903 I suspect 206917. Sample failure output: http://build.chromium.org/p/chromium.linux/builders/Linux%20Tests%20(dbg)(1)/builds/26492 [3072/3084] 6571.66s ExtensionBrowsingDataTest.BrowsingDataRemovalMask (4.44s) - retry #1 Note: Google Test filter = ExtensionBrowsingDataTest.BrowsingDataRemovalMask [==========] Running 1 test from 1 test case. [----------] Global test environment set-up. [----------] 1 test from ExtensionBrowsingDataTest, where TypeParam = [ RUN ] ExtensionBrowsingDataTest.BrowsingDataRemovalMask [14580:14580:0618/060701:9179869563:INFO:chrome_browser_main_chromeos.cc(420)] Running as stub user with profile dir: test-user [14580:14580:0618/060702:9180645791:WARNING:chrome_browser_main_chromeos.cc(442)] Using new connection change notifier. [14580:14580:0618/060702:9180689397:ERROR:nss_util.cc(444)] Error initializing NSS with a persistent database (sql:/etc/fake_root_ca/nssdb): NSS error code: -8174 [14580:14580:0618/060702:9180837938:INFO:profile_helper.cc(161)] Switching to profile path: /tmp/.org.chromium.Chromium.NCkWRn/u-test-user [14580:14580:0618/060702:9180840131:ERROR:logging_chrome.cc(182)] Unable to create symlink /tmp/.org.chromium.Chromium.NCkWRn/test-user/chrome_debug.log pointing at /tmp/.org.chromium.Chromium.NCkWRn/test-user/chrome_debug_20130618-060702.log: No such file or directory Xlib: extension ""RANDR"" missing on display "":9"". [14580:14580:0618/060702:9181068360:ERROR:component_loader.cc(108)] Failed to parse extension manifest. [14620:14620:0618/060703:ERROR:nss_util.cc(444)] Error initializing NSS with a persistent database (sql:/etc/fake_root_ca/nssdb): NSS error code: -8174 [7:7:0618/060703:WARNING:sandbox_linux.cc(36)] Activated seccomp-bpf sandbox for process type: renderer. [14620:14620:0618/060703:ERROR:gl_surface_glx.cc(327)] glxQueryVersion failed [14620:14620:0618/060703:ERROR:gl_surface_x11.cc(58)] GLSurfaceGLX::InitializeOneOff failed. [14620:14620:0618/060703:WARNING:sandbox_linux.cc(36)] Activated seccomp-bpf sandbox for process type: gpu-process. [14580:14580:0618/060703:9181446645:WARNING:user_cloud_policy_store_chromeos.cc(139)] Failed to load legacy policy cache: 1 [14580:14580:0618/060703:9181520016:WARNING:proxy_config_service_impl.cc(149)] Unknown profile_path [14580:14580:0618/060703:9181521308:WARNING:proxy_config_service_impl.cc(149)] Unknown profile_path [14664:14664:0618/060703:ERROR:nss_util.cc(444)] Error initializing NSS with a persistent database (sql:/etc/fake_root_ca/nssdb): NSS error code: -8174 [14664:14664:0618/060703:ERROR:gl_surface_glx.cc(327)] glxQueryVersion failed [14664:14664:0618/060703:ERROR:gl_surface_x11.cc(58)] GLSurfaceGLX::InitializeOneOff failed. [14664:14664:0618/060703:WARNING:sandbox_linux.cc(36)] Activated seccomp-bpf sandbox for process type: gpu-process. [14580:14612:0618/060704:9182644907:FATAL:shader_disk_cache.cc(366)] Check failed: BrowserThread::CurrentlyOn(BrowserThread::IO). [0x7f951b089eb0] base::debug::StackTrace::StackTrace() [0x7f951b0c6f13] logging::LogMessage::~LogMessage() [0x7f9510878086] content::ShaderClearHelper::~ShaderClearHelper() [0x7f951087acf1] base::RefCounted<>::Release() [0x7f9510882a26] base::internal::MaybeRefcount<>::Release() [0x7f9510882846] base::internal::BindState<>::~BindState() [0x7f9510882884] base::internal::BindState<>::~BindState() [0x7f951b081b02] base::RefCountedThreadSafe<>::DeleteInternal() [0x7f951b081ad6] base::DefaultRefCountedThreadSafeTraits<>::Destruct() [0x7f951b081abc] base::RefCountedThreadSafe<>::Release() [0x7f951b081a4d] scoped_refptr<>::~scoped_refptr() [0x7f951b08198a] base::internal::CallbackBase::~CallbackBase() [0x7f951a7a5b4a] base::Callback<>::~Callback() [0x7f951a89c744] disk_cache::BackendIO::~BackendIO() [0x7f951a89c782] disk_cache::BackendIO::~BackendIO() [0x7f951a89b79e] base::RefCountedThreadSafe<>::DeleteInternal() [0x7f951a89b772] base::DefaultRefCountedThreadSafeTraits<>::Destruct() [0x7f951a89b758] base::RefCountedThreadSafe<>::Release() [0x7f951a89ec6e] base::internal::MaybeRefcount<>::Release() [0x7f951a89eb90] base::internal::BindState<>::~BindState() [0x7f951a89ebce] base::internal::BindState<>::~BindState() [0x7f951b081b02] base::RefCountedThreadSafe<>::DeleteInternal() [0x7f951b081ad6] base::DefaultRefCountedThreadSafeTraits<>::Destruct() [0x7f951b081abc] base::RefCountedThreadSafe<>::Release() [0x7f951b081a4d] scoped_refptr<>::~scoped_refptr() [0x7f951b08198a] base::internal::CallbackBase::~CallbackBase() [0x7f951b06d5c0] base::Callback<>::~Callback() [0x7f951b0f4f16] base::PendingTask::~PendingTask() [0x7f951b0d2858] base::MessageLoop::DoWork() [0x7f951b0680ab] base::MessagePumpLibevent::Run() [0x7f951b0d1a57] base::MessageLoop::RunInternal() [0x7f951b0d1912] base::MessageLoop::RunHandler() [0x7f951b10adc0] base::RunLoop::Run() [0x7f951b0d124a] base::MessageLoop::Run() [0x7f951b143798] base::Thread::Run() [0x7f95107414fb] content::BrowserThreadImpl::CacheThreadRun() [0x7f9510741741] content::BrowserThreadImpl::Run() [0x7f951b143923] base::Thread::ThreadMain() [0x7f951b136495] base::(anonymous namespace)::ThreadFunc() [0x7f950df0fe9a] start_thread [0x7f950cd16ccd] clone [14580:14612:0618/060704:9182644907:FATAL:shader_disk_cache.cc(366)] Check failed: BrowserThread::CurrentlyOn(BrowserThread::IO). [0x7f951b089eb0] base::debug::StackTrace::StackTrace() [0x7f951b0c6f13] logging::LogMessage::~LogMessage() [0x7f9510878086] content::ShaderClearHelper::~ShaderClearHelper() [0x7f951087acf1] base::RefCounted<>::Release() [0x7f9510882a26] base::internal::MaybeRefcount<>::Release() [0x7f9510882846] base::internal::BindState<>::~BindState() [0x7f9510882884] base::internal::BindState<>::~BindState() [0x7f951b081b02] base::RefCountedThreadSafe<>::DeleteInternal() [0x7f951b081ad6] base::DefaultRefCountedThreadSafeTraits<>::Destruct() [0x7f951b081abc] base::RefCountedThreadSafe<>::Release() [0x7f951b081a4d] scoped_refptr<>::~scoped_refptr() [0x7f951b08198a] base::internal::CallbackBase::~CallbackBase() [0x7f951a7a5b4a] base::Callback<>::~Callback() [0x7f951a89c744] disk_cache::BackendIO::~BackendIO() [0x7f951a89c782] disk_cache::BackendIO::~BackendIO() [0x7f951a89b79e] base::RefCountedThreadSafe<>::DeleteInternal() [0x7f951a89b772] base::DefaultRefCountedThreadSafeTraits<>::Destruct() [0x7f951a89b758] base::RefCountedThreadSafe<>::Release() [0x7f951a89ec6e] base::internal::MaybeRefcount<>::Release() [0x7f951a89eb90] base::internal::BindState<>::~BindState() [0x7f951a89ebce] base::internal::BindState<>::~BindState() [0x7f951b081b02] base::RefCountedThreadSafe<>::DeleteInternal() [0x7f951b081ad6] base::DefaultRefCountedThreadSafeTraits<>::Destruct() [0x7f951b081abc] base::RefCountedThreadSafe<>::Release() [0x7f951b081a4d] scoped_refptr<>::~scoped_refptr() [0x7f951b08198a] base::internal::CallbackBase::~CallbackBase() [0x7f951b06d5c0] base::Callback<>::~Callback() [0x7f951b0f4f16] base::PendingTask::~PendingTask() [0x7f951b0d2858] base::MessageLoop::DoWork() [0x7f951b0680ab] base::MessagePumpLibevent::Run() [0x7f951b0d1a57] base::MessageLoop::RunInternal() [0x7f951b0d1912] base::MessageLoop::RunHandler() [0x7f951b10adc0] base::RunLoop::Run() [0x7f951b0d124a] base::MessageLoop::Run() [0x7f951b143798] base::Thread::Run() [0x7f95107414fb] content::BrowserThreadImpl::CacheThreadRun() [0x7f9510741741] content::BrowserThreadImpl::Run() [0x7f951b143923] base::Thread::ThreadMain() [0x7f951b136495] base::(anonymous namespace)::ThreadFunc() [0x7f950df0fe9a] start_thread [0x7f950cd16ccd] clone [0618/060704:ERROR:process_util_posix.cc(366)] Unable to terminate process group 14580: No such process ... 1 test run 1 test failed (0 ignored) Failing tests: ExtensionBrowsingDataTest.BrowsingDataRemovalMask",Chrome,Yes,1,0,0,0,0,0,0 295,252025,Autofill data comes back from dead after local clear,"Version: 27.0.1453.116 OS: Windows What steps will reproduce the problem? 1. Sync a bunch of autofill data 2. From settings, clear autofill 3. Wait 2-3 hours What is the expected output? What do you see instead? Expected: deletion propagates to other clients and server. Actual: autofill entries come back down after a few hours Details from ConOps: 1) Clearing cache, cookies and autofill doesn't help - all data comes back after restart. 2) Selecting autofill data and pressing Shift+Delete deletes data permanently. 3) If autofill is NOT synced, the problem is not observed.",Chrome,Yes,1,0,0,1,0,0,0 296,252217,Cookie deletion on behalf of user request shouldn't return until deletion has been sync'd to on-disk cookie store,"Steps to reproduce the problem: While investigating an Opera (for Android) cookie bug I found that CookieMonster::InternalDeleteCookie() doesn't seem to do what it claims to do. There's a bool sync_to_store which will cause store_->DeleteCookie(*cc) to be called, but the implementation (SQLitePersistentCookieStore::Backend::DeleteCookie) isn't synchronous, it just batches operations for later. However, CookieMonster::DeleteAllCreatedBetweenTask, which uses InternalDeleteCookie, doesn't wait for the sync to disk, it just calls the ""done"" callback. Given that BrowsingDataRemover uses these code paths, the result is that it can report being done even though the cookies are still on disk. What is the expected behavior? If BrowsingDataRemover reports being done, the data should really be gone, even if the browser isn't shut down properly. What went wrong? If the browser crashes or is forcefully killed at that point, the cookies will remain on restart. Did this work before? N/A Chrome version: master Channel: n/a OS Version: I'd be happy to write a patch, if it is confirmed that the current behavior is not intentional.",Chrome,Yes,1,0,0,0,0,0,0 297,260823,History: Day headers are displayed after history entries are removed,"Chrome Version: 28.0.1500.14 Device Type: iPad 2, iPhone Steps to reproduce: 1. Browse to some sites 2. Remove some/all history entries Expected result: No history entries found should be displayed Actual result: Dates of History entries are displayed",Chrome,Yes,1,0,0,0,0,0,0 298,262860,Update first party for cookie URL during redirect chains for main resource loads in all code paths,"Currently, ResourceLoader and URLFetcher have a bug, where some of their code paths do not handle first party URLs consistently. Specifically, during redirects, the first party might not change, which makes Chrome handle some of the cookies during redirects as if they were third party cookies. This bug is intended as a meta bug for clean up work to fix ResourceLoader and URLFetcher to always take: - the current top level frame URL as the first party and - B as the first party in redirects A-->B.",Chrome,Yes,0,1,0,0,0,0,0 299,268932,Safari import dialog needs a gray bar explaining the keychain,"From http://blog.elliottkember.com/chromes-insane-password-security-strategy ""This struck me as particularly odd. Why is ÒSaved passwordsÓ greyed out, and mandatory? Why have a check-box? This is the illusion of choice. I think itÕs deeply misleading"" Is there a reason we don't make this optional?",Chrome,Yes,0,1,0,0,0,0,0 300,269050,Session exceptions for default blocked cookies,"UserAgent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/30.0.1577.0 Safari/537.36 Steps to reproduce the problem: 1. Block saving cookies by browser default. 2. Enter some site 3. Add site to cookie exceptions, but to save only for session time! What is the expected behavior? What went wrong? There is only a way to add exception for store cookies pernamently. Did this work before? No Chrome version: 30.0.1577.0 Channel: n/a OS Version: 6.1 (Windows 7, Windows Server 2008 R2) Flash Version: Shockwave Flash 11.8 r800",Chrome,Yes,1,0,0,0,0,0,0 301,275508,Client certificate selections in Android not preserved on browser restart,"Example URL: All sites with Client Certificate required Steps to reproduce the problem: 1. Visit a site requiring Client Certificate authentication 2. Select a certificate 3. Quit Chrome (make sure not running in background) 4. Visit the same site as in point 1 5. Certificate selection is again requested What is the expected behavior? We don't expect the user to approve the selection of a certificate every time he visit the same site. If he agrees once, he shouldn't be required to select again the certificate once he visit the site. Single Sign On shouldn't require user interaction. What went wrong? Certificate Selection is requested each time we visit a web site requesting Client Certificate after Chrome restart. Did this work before? No Chrome version: 28.0.1500.94 Channel: stable OS Version: 6.1 (Windows 7, Windows Server 2008 R2) Flash Version: Shockwave Flash 11.8 r800",Chrome,Yes,0,0,1,0,0,0,1 302,290423,Correctly handle incognito mode checkbox for proxy extension API,"Bug 253596 changed it so that the ""Allow in incognito"" checkbox is always enabled for proxy extensions. We shouldn't do this. (We made this change because I thought proxy settings always applied to incognito, but that's not the case.) Instead, proxy settings should only apply to regular mode unless the extension is allowed in incognito. We should also revert r210766.",Chrome,Yes,0,0,1,0,0,0,0 303,292121,Chrome shows logged in content even after logging out,"UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/29.0.1547.65 Safari/537.36 Steps to reproduce the problem: 1. Start typing an address in the address bar (e.g ""facebook.com""). 2. Once a request is sent by the prediction service (e.g after typing ""fa""), and BEFORE its response is returned to the browser, use the first suggestion from the omnibox autocompletion by hitting enter. This step is a bit tricky and difficult to reproduce since it has to be done fast enough (links of videos demonstrating slow and fast enough executions are specified below). 3. Go to the address bar, start typing the same URL as in the previous step and select the same suggestion as before. What is the expected behavior? Let T1 be the time in which a response held by the prediction service was returned. Such response should only be used to satisfy a request that was sent in time T2 if T2 > T1 (otherwise, a new request must be sent). What went wrong? Consider this two use cases demonstrated by the following short videos: https://www.dropbox.com/s/6asbmz53zjbigo8/UC1.mov https://www.dropbox.com/s/vw5g7kkk5iqo2jc/UC2.mov In the first one, the user is slow enough and hits enter only after the request that is sent by the prediction service is satisfied. Such use case leads to the desired behaviour and everything works great. However, as seen in the second video, the user might be fast enough to initiate a request before the one sent by the prediction service is satisfied. In such use case, expired content might be displayed to the user, such as in the example which shows how the content of a logged-in user is show to an unauthenticated one. Did this work before? N/A Chrome version: 29.0.1547.65 Channel: stable OS Version: OS X 10.8.5 Flash Version: Shockwave Flash 11.8 r800 This is the first time I'm opening an issue for this project. I tried pretty hard to make sure that this isn't a duplicate, I'm sorry in advance in case I missed an issue and it is.",Chrome,Yes,0,0,0,1,0,0,0 304,292976,"""Never save browser history"" policy is not taking effect","Version: 31.0.1628.1 OS: Win,Linux and Mac What steps will reproduce the problem? 1. Install and launch chrome 2. Sign in to Chrome as a domain user. 3. From Admin prompt cpanel set the policy ""Browser History"" to ""Never save browser history"" 4. From Domain user open Chrome:policy and check ""browser history is disabled : true"" What is the expected output? Browser History shouldn't get saved when ""Browser History"" to ""Never save browser history"" is set. What do you see instead? Entire browser history is getting saved. Please use labels and text to provide additional information.",Chrome,Yes,0,0,1,0,0,0,0 305,303948,Client platform information is sent unencrypted to Google update service,"UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/30.0.1599.66 Safari/537.36 Steps to reproduce the problem: 1. run wireshark 2. start chrome 3. search for a post request to google update service (in my case destination ip 64.15.113.20 path /service/update2) What is the expected behavior? operating system and kernel version should be treated like sensitive data and therefore send encrypted. What went wrong? my os and kernel version was send to google over an unsecured layer. Did this work before? N/A Chrome version: 30.0.1599.66 Channel: beta OS Version: Flash Version: Shockwave Flash 11.8 r800",Chrome,Yes,0,0,0,0,0,0,1 306,307785,Flash webcam capture does not activate tab recording indicator,"Version: Observed on: Chrome 29.0.1547.76 (Linux), Chrome 32.0.1670.5 (Mac canary), and tip-of-trunk build on desktop (r228798) What steps will reproduce the problem? 1. Start Flash webcam capture from a website. Example: http://www.kirupa.com/flash/example/webcam_tutorial.swf 2. Flash prompts for webcam access. Click ""Allow."" 3. You now see your webcam video in the Flash widget. What is the expected output? What do you see instead? Expected: To see tab recording indicator. Observed: No tab recording indicator. ------------- This got broken some time around M29, and needs to be fixed ASAP. Previous user privacy reviews require the indicator.",Chrome,Yes,0,1,0,0,0,0,1 307,311180,IME should not learn when typing into an incognito mode window,"Chrome Version : 32.0.1678.0 OS Version: 4856.0.0 What steps will reproduce the problem? 1. Sign in 2. Press Ctrl+Shift+N to open an incognito window 3. Enable Japanese (or Chinese or whatever) IME 4. Click Omnibox 5. Type a sensitive or embarrassing word several times. 6. Switch back to a normal Chrome window. 7. Click Omnibox 8. Type a word whose prefix is the same as the sensitive word typed in 5. What is the expected result? In step 8, the word entered in 5 should never be suggested. What happens instead of that? It is suggested. Please provide any additional information below. Attach a screenshot if possible. Please turn off the ""learning"" feature by default when in Incognito window. I feel like this is a privacy issue. UserAgentString: Mozilla/5.0 (X11; CrOS x86_64 4856.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1678.0 Safari/537.36",Chrome,Yes,0,0,1,1,0,0,0 308,316638,Clearing browser data for last hour doesn't nuke corresponding local search history terms,"Chrome Version : 30.0.1599.101 OS Version: OS X 10.8.5 URLs (if applicable) : Other browsers tested: Add OK or FAIL after other browsers where you have tested this issue: Safari 5: n/a Firefox 4.x: n/a IE 7/8/9: n/a What steps will reproduce the problem? 1. mistype a word into the omnibox and hit enter (eg ""bbanana"") 2. now typing ""bb"" will bring up a Google Search ""bbanana"" suggestion, instead of, say, a search shortcut you were using for ""bb""+tab 3. try highlighting the suggestion in the dropdown and using Fn+Delete or Fn+Shift+Delete to remove it (as suggested on some websites) 4. try clearing all browsing history for the past hour, then day, then week (as nothing seems to work) 5. open a new tab 6. type ""bb"" What is the expected result? the search shortcut should activate (or at the very least, ""bbanana"" should be absent) What happens instead of that? ""bbanana"" appears as a search suggestion. Please provide any additional information below. Attach a screenshot if possible. Only restarting Chrome (after clearing history) was able to effect the removal of the incorrect term from the dropdown. UserAgentString: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/30.0.1599.101 Safari/537.36",Chrome,Yes,1,0,0,0,0,0,0 309,318859,New inline Sign in : Cross account sync detection failed,"ENVIRONMENT OS : Win7 & Mac OSX Chrome : 33.0.1707.0 Pre-condition : Enable inline sign in using the flag --enable-inline-signin REPRO STEPS 1. Create a fresh profile , Sign in to sync. 2. Go to settings page & Disconnect the account from sync. 3. Sign-in with a different account ACTUAL RESULTS Signed in to a different account without any alert message. EXPECTED RESULTS An alert message ""You were previously signed in with a different account, signing in will merge your data."" is displayed in the sign-in page.",Chrome,Yes,0,1,0,0,0,0,0 310,321534,RulesRegistry: Make sure that has_declarative_rules gets cleaned after an extension is uninstalled,"Revisions r202065 and r228352 introduced a new flag has_declarative_rules in the extensions state store to mark whether any declarative rules for a given extensions are stored or not. It looks like the following happens: After a user removes an extension using a declarative API, all the preferences associated with that extension are gone, except for has_declarative_rules. This is a privacy concern, because it leaves a trail of removed extensions. This bug tracks verifying and fixing this issue.",Chrome,Yes,1,0,0,0,0,0,0 311,322527,Incognito cookies make their way into non-incognito cookie space when using HTTPS Everywhere extension,"UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.19 Safari/537.36 Steps to reproduce the problem: 1. Install HTTPS Everywhere 2. Clear cookies across browser 2. Log into reddit in incognito window, confirm you are logged in 3. Switch to non-incognito window, you'll be logged in as user from incognito session What is the expected behavior? Expected behavior is to have each cookie space completely exclusive. What went wrong? From HTTPS Everywhere: WeÕre getting the onCookieChanged event, and the cookie we get in that event has a storeId of 0 regardless of where it comes from (Incognito or not). We then turn right around and set the secure flag on the cookie and issue a cookies.set(cookie). Since the storeId is still the default store, the cookie leaks to normal mode. More here: http://blog.innerlogics.com/2013/07/16/security-risk-in-chrome-with-https-everywhere-combined-with-incognito/ Did this work before? N/A Chrome version: 31 Channel: stable OS Version: Windows 8.1 Flash Version: Shockwave Flash 11.9 r900",Chrome,Yes,0,0,0,1,0,0,0 312,323873,Deleting individual items from chrome://history UI fails if items are in archived history file,"UserAgent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.57 Safari/537.36 Steps to reproduce the problem: 1. go chrome://history/ 2. search history with ""keyword"" 3. select what you find (you can not SELECT ALL - why to make it slower?) 4. ""Remove selected items"" 5. Search history ""keyword"" again 6. Result nothing is delete - still sensitive data exists What is the expected behavior? Wipe should work ""Remove selected items"" and search again ""keyword"" should result with zero results What went wrong? Always! Did this work before? N/A Chrome version: 31.0.1650.57 Channel: stable OS Version: 5.1 (Windows XP) Flash Version: Shockwave Flash 11.9 r900",Chrome,Yes,1,0,0,0,0,0,0 313,326549,Delete precache history when browsing history is deleted,"See https://code.google.com/p/chromium/codesearch#chromium/src/components/precache The precache component keeps track of URLs that have been precached in order to identify fetches where precaching was useful. This precache history should be deleted if the user clears their history.",Chrome,Yes,1,0,0,0,0,0,0 314,327783,SDCH support may be used to track user,"This template is ONLY for reporting privacy issues. Please use a different template for other types of bug reports. Please see http://www.chromium.org/Home/chromium-privacy for further information. PRIVACY ISSUE Please provide a brief summary of the privacy issue. VERSION: Chrome Version: [32] Operating System: all REPRODUCTION STEPS This is based on http://www.blogs.zeenor.com/wp-content/uploads/2011/01/Shared_Dictionary_Compression_over_HTTP.pdf The SDCH protocol uses unique ID (split into agent id and server id) to identify the compression dictionary. The agent id is sent from client to server as Avail-Dictionary header: Avail-Dictionary: GVhc3V48,TWFuIGlz Server could send unique dictionaries to each client and use those ids to identify client requests similar to tracking cookies. SDCH logic on the client should probably be changed to follow cookie policy and either don't get or not advertise available dictionary.",Chrome,Yes,0,0,1,0,0,0,0 315,328855,Website settings popup doesn't appear,"1. open https://google.com 2. click the green padlock icon on the omnibox Expected: see the website settings popup Actual: nothing happens This is happening on chromeos=1 Linux builds and on a ChromeOS VM image at revision 240862 (chrome/VERSION at 33.0.1739.0). Did not repro on the dev channel at 33.0.1734.6. Doesn't repro on linux desktop build, nor on the Mac canary.",Chrome,Yes,0,1,0,0,0,0,0 316,329658,Files App open QuickOffice files in normal profile instead of incognito,"Start Guest session, open any office document from Files app. It will be opened in normal windows instead of incognito (you can check it by opening NTP in the same window it will be blank instead of ""You're browsing as a Guest""). It seems like regression after Issue 322682. The only CL in related in Files https://codereview.chromium.org/110913003 but it could be unrelated. I see it on TOT but we need to check M33 too.",Chrome,Yes,0,0,1,0,0,0,0 317,330139,"Feedback app' window couldn't be scrolled to see all options, when 'Page Zoom' is set to maximum.","Chrome Version : 34.0.1752.0 (Official Build 241752) m OS : All What steps will reproduce the problem? 1.Launch Chrome and open ""chrome://settings"" 2.Goto Web content, and set 'Page Zoom' to 500% 3.Click on wrench and select 'Report an issue' to open feedback app and observe. The Feedback app window appears broken with options missing and cannot be scrolled even. We should be able to scroll and all options should be visible. It is non-regression issue seen from 31.0.1605.0 as Feedback app was introduced from 31.0.1605.0",Chrome,Yes,0,0,1,0,0,0,0 318,331291,Online spellchecking information prompt,The online spellchecker shows an information prompt that tells the user that what they type is sent to Google for spell checking. If you toggle the setting on chrome://settings the prompt is shown only the first time you activate it. This should be shown every time the setting is switched on.,Chrome,Yes,0,0,1,0,0,0,0 319,331508,logging out of Google Chrome browser,"This template is ONLY for reporting privacy issues. Please use a different template for other types of bug reports. Please see http://www.chromium.org/Home/chromium-privacy for further information. PRIVACY ISSUE Please provide a brief summary of the privacy issue. It is unbelievable that to perform such a basic operation as logging out from the Chrome browser - which has become my one and only browser for a few years now - you have to go to a forum and read dozens of pages. Plus, many of the moderators give bogus (and obvious) advice - like ""just disconnect your google account."" Chrome developers, shake it up! This goes against any principle of transparency, privacy, and security. Hope we all hear from you. VERSION: Chrome Version: 31.0.1650.63 m + [stable, beta, or dev] Operating System: [Please indicate OS, version, and service pack level] it doesn't matter - use many of them REPRODUCTION STEPS Please provide detailed reproduction steps, and any additional information below. Include an URL demonstrating the issue and attach a screenshot if applicable. Be sure to include in your description how this issue affects your privacy.",Chrome,Yes,1,0,0,0,0,0,0 320,332481,Requests from within Flash (NPAPI) aren't handled by chrome.webRequest.onBeforeRequest anymore,"UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36 Steps to reproduce the problem: 1. Go to chrome://plugins, expand Details, and make sure Adobe Flash Player (PPAPI) is disabled. 2. Install the extension from the attachment. 3. Go to youtube.com, and play any video. 4. Inspect the background page of the extension and go to ""Console"". What is the expected behavior? The sample extension logs all web requests of the type ""object"". So I would expect to see all requests issued by the Flash video, like it does on Chrome <= 22 or when Flash (PPAPI) is enabled. What went wrong? Starting with Chrome 23, requests issued from NPAPI plugins aren't handled by chrome.webRequest.onBeforeRequest anymore. WebStore page: Did this work before? Yes Chrome 22 and before Chrome version: 32.0.1700.72 Channel: beta OS Version: Flash Version: Shockwave Flash 12.0 r0 This breaks extensions like Adblock Plus, on sites that use Flash, if the user uses the NPAPI instead of the PPAPI Flash plugin.",Chrome,Yes,0,0,1,0,0,0,0 321,333752,Google Chrome WebRTC IP Address Leakage,"Vulnerability Details: Chrome has a vulnerability whereby internal IP addresses of users can be leaked using Javascript alone without notifying the user. Affected Versions: Chrome Version: Version 31.0.1650.63 m + Version 32.0.1700.72 beta-m Stable + Version 34.0.1781.0 Canary Operating System: Windows 7 Service Pack 1 Reproduction Case: The following can be executed in the Chrome console to reproduce the test case. A self-contained HTML file has also been attached. // create a new peer connection - dont need any stun servers for this attack to work // adding a stun server provides the external ip address of the user as well (see HTML example) var peer = new webkitRTCPeerConnection(null); // create an offer object before any streams are added // this is important because getUserMedia() requires explicit user permission peer.createOffer(function(sdp) { peer.setLocalDescription(sdp, function() { // there seems to be a bug in the async call where the callback is called before the localDescription property has been set // setTimeout provides some time for the async call to finish setTimeout(function() { var sdp = peer.localDescription.sdp; console.log(sdp); }, 100); }); }, function(err) { console.error(err); }, {}); Possible Remediation Approach: One possible approach to resolve this issue is to take the approach used by Mozilla Firefox. Firefox blocks offer creation if no streams have been added to the RTCPeerConnection object. It also does not permit the MediaStream constructors to be called directly and currently it seems that the only way to get a MediaStream is to call getUserMedia(). Currently in the case of Chrome, even if the above fix was used, an empty stream can be added using: peer.addStream(new webkitMediaStream()); Reported By: Jaap Karan Singh and Colin Wong, BAE Systems Detica",Chrome,Yes,0,0,0,0,0,0,1 322,334602,Combine predictive technologies under a single option,"The user needs simple control over the usage of the various predictive technologies (dns preresolve, tcp preconnect, prefetch, and prerender). Combine them under a single option.",Chrome,Yes,0,0,1,0,0,0,0 323,335902,Security: PSL does not prevent wildcard cookies,"VULNERABILITY DETAILS The public suffix list should be used to prevent wildcard cookies from being set on public suffixes (for example *.github.io). All documentation I've seen indicates that Chromium is supposed to do this (example: http://www.chromium.org/developers/design-documents/network-stack/cookiemonster). VERSION Chrome Version: 34.0.1788.0 dev Operating System: OS X 10.9.1 REPRODUCTION CASE 1) Visit http://titanous.github.io/cookies/ and note the number 2) Visit http://butterscotch.github.io/cookies/ and note that the number is the same and a cookie is set on .github.io which is on the PSL.",Chrome,Yes,1,0,0,0,0,0,0 324,337802,Remove' button is still enabled after removing all cookies entries on 'cookies and site data' window,"Chrome Version : 34.0.1802.0 (Official Build 246590) dev OS-Mac What steps will reproduce the problem? 1.Launch chrome , open www.google.com and Click on green pad lock (near 'Reload' button) 2.Click on 'Show cookies and site data' button ,Remove all cooked entries by clicking on 'Remove' button and Observe. 'Remove' button is enabled. 'Remove' button should get disabled instantly after removing all entries. This is Regression issue,broken in M34. Narrow bisect URL: http://build.chromium.org/f/chromium/perf/dashboard/ui/changelog.html?url=/trunk/src&range=243629%3A243637 Suspecting : r243633 Note:Issue not reproducible on OS-Windows,Linux i.e 'Remove' button gets disabled.",Chrome,Yes,0,1,0,0,0,0,0 325,338036,Review permission messages for chrome.bluetooth API,See discussion started on https://codereview.chromium.org/145663004/.,Chrome,Yes,0,1,0,0,0,0,0 326,339588,Collect per-device frequency of kernel crashes,"We (intentionally) don't include any device-specific information for kernel crashes. Therefore, given a certain frequency of crashes, we don't know their distribution across devices, i.e. the crashes may be concentrated on a few devices, or spread evenly across all of them. The UMA logs may have enough information to extract this distribution, but this information is difficult or impossible to obtain because of privacy safeguards. However, the distribution itself has no privacy implications, so we can try to obtain it in other ways.",Chrome,Yes,0,1,1,0,0,0,1 327,340246,Original 'Incognito window' spy avatar gets replaced by user profile avatar,"Chrome Version : 34.0.1819.0 (Official Build 248414) canary OS-Mac What steps will reproduce the problem? 1.Launch chrome,open 'Incognito window' , Create new user from first user. 2.Observe the avatar of above 'Incognito window'. Original incognito avatar not seen ,instead gets replaced by profile avatar of first user Original(default) profile avatar of incognito window should be seen. This is Regression issue,broken in M34. Narrow bisect URL: http://build.chromium.org/f/chromium/perf/dashboard/ui/changelog.html?url=/trunk/src&range=246697%3A246712 Suspecting: r246700 Note:Issue not reproducible on OS-Windows,Linux",Chrome,Yes,0,1,0,0,0,0,0 328,343891,Passwords associated with a profile aren't deleted when you delete that profile,"1. Create a profile on MacOS. 2. Sign in to that profile and have your passwords synced down. 3. Delete the profile. 4. Look in the system password store. Expected: Passwords are removed. Actual: Passwords are not removed. I suspect this impacts all profiles on Mac (including ephemeral mode profiles?)",Chrome,Yes,1,0,0,0,0,0,0 329,345741,"""Connect from incognito"" dialog is confusing","Version: 33 OS: All What steps will reproduce the problem? 1. Have Hangouts extension installed (https://chrome.google.com/webstore/detail/hangouts/nckgahadagoaajjgafhacjanaoiihapd) 2. Open gmail.com in incognito 3. A dialog without title shows up asking to allow mail.google.com to communicate with ""Hangouts"" There are a couple of problems with the dialog: - It's unintuitive. Doesn't have a title and doesn't have context for the user to make an informed decision. - It's not clear what ""No"" will do (is it going to break the extension?) - It's a modal dialog. It blocks other pages from loading, and causes a crash if you try to open new tabs. The code shows a modal dialog: https://code.google.com/p/chromium/codesearch#chromium/src/chrome/browser/extensions/api/messaging/incognito_connectability.cc&q=IDS_EXTENSION_PROMPT_EXTENSION_CONNECT_FROM_INCOGNITO&sq=package:chromium&type=cs&l=78",Chrome,Yes,0,1,0,0,0,0,0 330,346816,Deleting URLs from history page should ensure Shortcuts DB is updated,"UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.117 Safari/537.36 Steps to reproduce the problem: 1. go to chrome://history 2. Search for a site 3. Mark a couple of checkboxes 4. Click ""Remove selected items"" What is the expected behavior? It should remove the items. What went wrong? The items are not removed from history. Did this work before? N/A Chrome version: 33.0.1750.117 Channel: beta OS Version: OS X 10.9.2 Flash Version: Shockwave Flash 12.0 r0 If instead of using checkboxes I click on the arrow located on the right side of an entry and choose ""Remove from history"" the item disappears from the list but it's only a UI feature - re-searching for the domain brings the entry back.",Chrome,Yes,1,0,0,0,0,0,0 331,346850,Content settings: use whitelist not blacklist for allow-all cases,"As demonstrated by issue 345485, it is easy to miss adding a new content setting to the allow-all blacklist. It seems better to have a whitelist so new settings are enforced by default.",Chrome,Yes,0,0,1,0,0,0,0 332,348444,"""the page cannot be loaded via the chrome data compression proxy"" on 10.x.x.x page","Version: 33.0.1750.132 OS: android klp What steps will reproduce the problem? 1. Opt in to data compression proxy. 2. open URL http://10.1.2.18/ What is the expected output? What do you see instead? Expected output: I see my page in my local network Instead: I see ""the page cannot be loaded via the chrome data compression proxy"" Please use labels and text to provide additional information. Android Chrome Beta flywheel.",Chrome,Yes,1,0,0,0,0,0,0 333,348641,Change text for warning about Open application from Incognito,"The current string (attached) makes no sense. Here's a recommendation. We are suggesting using the same one in Bling. Title: ""Open application?"" ""This link is attempting to open an application outside of Incognito."" [Cancel] [Continue]",Chrome,Yes,0,1,0,0,0,0,0 334,349002,"Verified access ""Learn more"" link broken","Version: 33.0.1750.124 (stable) Under Settings > Privacy > Enable Verified Access service clicking the ""Learn more"" link leads to page https://support.google.com/chromebook/?p=verified_access#topic=3399709 which is the generic help page and provides no information about verified access.",Chrome,Yes,0,1,0,0,0,0,0 335,349110,"Unable to disable ""Automatically send usage statistics & crash to Google"" for the 1st time sign in","Google Chrome : 35.0.1870.0 (Official Build 254603) dev Platform : 5579.0.0 (Official Build) dev-channel Devices: all What steps will reproduce the problem? 1. Recover devices 2. Sign in ( for the first time ever ) 3. Go to chrome://settings/search#pri What is the expected output? Allow to disable ""Automatically send usage statistics and crash reports to Google"" What do you see instead? Not allow to disable ""Automatically send usage statistics and crash reports to Google"" Always Feedback log with a screenshot https://feedback.corp.google.com/#/MyReports/1977126194?context=mr Note: Sign out and sign in again, the option is allow to deselect to disable.",Chrome,Yes,0,0,1,0,0,0,0 336,349502,chrome://net-export can't strip private data,"Apparently I never filed a bug for this. chrome://net-export doesn't have a way to strip cookies and HTTP credentials, like net-internals does. We should make this possible so we don't have to ask our users to send us their cookies.",Chrome,Yes,0,0,0,0,0,0,1 337,349504,Settings>Privacy: Introductory text implies all options concern web services,"Version: 34.0.1847.38 (beta) OS: Chrome OS Under Chrome OS > Settings > Privacy, the text ""Google Chrome may use web services to improve your browsing experience. You may optionally disable these services."" seems to imply that all the following options refer to web services, however this is not the case. The text should be adapted accordingly.",Chrome,Yes,0,1,0,0,0,0,0 338,349826,"Settings>Privacy: UI flow less than optimal, information hidden in popups","Version: 34.0.1847.38 (beta) OS: Chrome OS Under Chrome OS > Settings > Privacy, the ""Enable Verified Access"" item has a ""Learn more"" link displayed after it. Several of the other items have ""Learn more"" links, too, but those are only displayed in the popup that shows up when clicking the checkbox. This is inconsistent, and many users will not even discover these hidden ""Learn more"" links because they don't understand the description of a certain checkbox thus never click it. Or, to put it into a slightly different perspective: Some of the checkboxes will toggle immediately while other checkboxes will show a popup with an explanation -- yet there are no visual cues to the user to discern these two types of checkboxes. Most people don't expect that clicking on a checkbox will do anything but toggling that box, thus many people will never be aware of the availability of the additional information. Bottom line: I'd suggest to change the UI in a way that makes it clear to the user which checkboxes have additional information available without having to ""explore"" the boxes by clicking on them one-by-one.",Chrome,Yes,0,1,0,0,0,0,0 339,350460,Not obvious how to disable exceptions to notification policy for e.g. Google origins; inconsistent permissions UX,"Steps to reproduce the problem: 1. Open Settings 2. Go to Content settings 3. Click ""Manage exceptions"" under notifications What is the expected behavior? I should be able to remove the exception for *://mail.google.com/mail/ca* What went wrong? There is no way to remove that exception Did this work before? N/A Chrome version: 33.0.1750.146 Channel: n/a OS Version: OS X 10.9.2 Flash Version:",Chrome,Yes,1,1,0,0,0,0,0 340,352001,Autofill (and autocomplete) popup should only be displayed after a usergesture,"JavaScript can force the display of previously saved autofill values. Here's how it works: 1. Specify a form field with a name like ""Name"" or ""Contact"" 2. Populate the form field with 'A', 'B', 'C' etc. Demo: http://ha.ckers.org/weird/safari_autofill.html This is NOT currently a vulnerability because JavaScript can't get access to the entries (they're displayed in native UI). However, with screen capture this becomes a problem: the website could force the display of these and then grab them. So, it seems like we might as well gate this behind a usergesture.",Chrome,Yes,0,0,0,0,0,0,1 341,352079,Consider clearing the cache when clearing cookies,"etags are used by shifty sorts of sites to track users without setting cookies. One way of reducing the effectiveness of such tracking would be to clear etagged resources from the cache when a user clears cookies and site data. I'm going to look into doing that as a proof of concept to take to the network folks.",Chrome,Yes,1,0,0,0,0,0,0 342,352101,Data doesn't get save in 'manage autofill settings' section in 'Guest mode' of the browser,"Chrome Version: 35.0.1887.0 (Official Build 256692) canary OS:All,Win 7(Aero enabled) What steps will reproduce the problem? 1.Launch chrome, navigate to 'chrome://flags' and enable New Profile Management flag, relaunch the browser. 2.Click on the user/profile name on the right side & select 'Browse as Guest'. 3.In Guest mode navigate to chrome://settings click on 'Manage autofill settings' under password and forms, click on add new street address and save data, observe. Actual: Data doesn't get save in 'manage autofill settings section. Expected: Data should get save in 'manage autofill settings section. This is a regression issue broken in 'M34' will update bisect info soon.",Chrome,Yes,1,0,1,0,0,0,0 343,352380,Geolocation permission is remembered on an HTTP site,"Version: Linux 35.0.1883.0 (Official Build 256105) dev aura and Mac 35.0.1888.0 (Official Build 256779) canary What steps will reproduce the problem? 1. Visit http://diveintohtml5.info/geolocation.html#putting-it-all-together 2. ""Click to look up your location."" and allow the geolocation prompt on this HTTP site 3. Restart Chrome 4. Return to http://diveintohtml5.info/geolocation.html#putting-it-all-together and ""Click to look up your location."" What is the expected output? What do you see instead? Chrome should show another geolocation infobar because this is an HTTP site, but does not. I have ""Continue where you left off"" enabled, so maybe that's inappropriately continuing this session.",Chrome,Yes,0,0,1,0,0,0,1 344,353640,no place to see component extensions,"There's no UI in chrome to see which component extensions are loaded. You can see them in the task manager if you know to look for them, but even then they're not displayed differently. It seems reasonable that there be some place in our UI that people can go to see what's there, even if we don't list them in chrome://extensions.",Chrome,Yes,0,1,0,0,0,0,0 345,354931,Security: UAF in NotifyAndDeleteIfDone/browser process crash related to WebSQL transactions in a Web Worker,"VULNERABILITY DETAILS A browser process NotifyAndDeleteIfDone UAF/crash occurs when Chrome is closed after history (Cookies and other site and plug-in data) has been erased twice (stalls) while WebSQL transactions are reloading in the background triggered by a Web Worker. The debug version crashes/breaks with: [2622:2622:0321/001428:FATAL:clear_browser_data_handler.cc(151)] Check failed: !remover_. when history is erased (2nd time). VERSION Chrome Version: all (stable 33.0.1750.152 - ToT 258508) Operating System: Windows 8.1 (x86), Ubuntu 13.10 (x64) REPRODUCTION CASE 1. Load the attached repro, or use the script below 2. Add a new tab and erase history (stalls) 3. Press Ctrl-H and erase history again (debug version crash/check failed) 4. Close the browser (Crash/UAF with release version) FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION Type of crash: browser Crash State: see added trace files",Chrome,Yes,1,0,0,0,0,0,0 346,355541,GUID-like string added to `navigator.userAgent` on iOS,"See https://twitter.com/thijs/status/448064463498133504, https://twitter.com/thijs/status/448069488052027392. Confirmed locally. CCing some relevant folks for detail.",Chrome,Yes,0,0,0,0,0,0,1 347,356569,IME API should support password field for on-screen keyboard scenario,"Version: R35 OS: Chrome OS To make on-screen keyboard works for password field, the IME API needs: 1) In InputContext, add a type for password field 2) onFocus event should be fired when focus is into/out of password field. 3) sendKeyEvent() should be able to work on password field. P.S. for now, onKeyEvent() doesn't need to work on password field.",Chrome,Yes,1,0,1,0,0,0,0 348,356623,Page Cookies Window Size and Editability,"UserAgent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.154 Safari/537.36 Steps to reproduce the problem: View Cookie and Site Data What is the expected behavior? Window is resizable, cookies are deletable What went wrong? It's not resizable, cookies are not deletable Did this work before? N/A Chrome version: 33.0.1750.154 Channel: stable OS Version: 6.1 (Windows 7, Windows Server 2008 R2) Flash Version: Shockwave Flash 12.0 r0 Could it show the cookie value and perhaps other attributes in the list view?",Chrome,Yes,0,1,0,0,0,0,0 349,359377,Eliminate the archived history database,"Peering through the history archiving code, it seems that while we archive URLs periodically, we never do anything with the archived DB. AFAICT we do not display it on the history page, or search through it for history or omnibox searches. It seems like we should either hook up the archived DB to do useful things, or get rid of it entirely and delete all related code and all archive files on disk.",Chrome,Yes,0,0,0,1,0,0,0 350,359418,Drive is missing in the file open/save dialog in Incognito mode,"Which is intentional. However, I had an awkward conversation with a high profile colleague: : So your team built this thing? me: Yes. As you can see, Drive is integrated. : But Drive is missing in the file open dialog. me: Oops. : That's the thing I'm talking about! Turned out he was just opening it from Incognito window. We should do either of 1) Get Drive working in Incognito mode 2) Keep Drive label but gray it out with mouse-hover text like ""Drive is disabled in Incognito mode"". Josh, what do you think?",Chrome,Yes,0,1,0,0,0,0,0 351,360448,Eavesdrop on the user speech - abusing the old speech API,"UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.152 Safari/537.36 Steps to reproduce the problem: Info is here: http://blog.guya.net/2014/04/07/to-listen-without-consent-abusing-the-html5-speech/ POC: http://guya.net/security/speech/ What is the expected behavior? What went wrong? The old speech API -x-webkit-speech has some flaws which enable it to be obfuscated. More info here: http://blog.guya.net/2014/04/07/to-listen-without-consent-abusing-the-html5-speech/ Did this work before? No Chrome version: 33.0.1750.152 Channel: stable OS Version: OS X 10.9.2 Flash Version: Shockwave Flash 12.0 r0",Chrome,Yes,0,0,0,0,0,0,1 352,362794,Cleanup extension permission strings,"A couple of ideas to improve the permission warnings: - Make the wording consistent. Some warnings say ""Access your data"" while others say ""Read a list of <...>"". - Combine similar warnings into a single warning that covers all. - Remove warnings that are too subtle and don't have privacy or security impact. The exhaustive list of permission warnings and comments from security team's audit is here: https://docs.google.com/a/chromium.org/spreadsheet/ccc?key=0Atq2eN9gDoUIdHR4Z29VeVN4Skhrb0tRNlRTeWVVVFE&usp=sharing",Chrome,Yes,0,1,1,0,0,0,0 353,363268,"""Remove all"" cookie button ambiguous","UserAgent: Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.152 Safari/537.36 Steps to reproduce the problem: 1. Visit chrome://settings/cookies 2. enter a search string What is the expected behavior? What went wrong? In chrome://settings/cookies please change the ""Remove all"" button to say ""Remove all shown"", else the user worries that indeed you will ""Remove all"" his cookies anyway! (No, users do not trust that indeed it will only remove those shown even though that is luckily indeed what it does.) Did this work before? N/A Chrome version: 33.0.1750.152 Channel: n/a OS Version: Flash Version: Shockwave Flash 11.2 r202",Chrome,Yes,0,1,0,0,0,0,0 354,364115,Show permission warning for chrome://favicon less frequently,"The warning for chrome://favicon is ""Access the icons of websites you visit"". Sites may change their favicons depending on auth status etc. but we should explain that privacy concern rather than stating this permission as is. I don't think it's showing this warning is helping the user make a decision. I propose either of the following: - Remove this warning altogether and use the favicon lookup service: google.com/s2/favicons?domain=www.google.com Pros: No privacy concern, less warning text. Cons: Some extensions might actually want the customized favicons. - Suppress this warning when tabs or history permissions are already requested. Pros: Less warning text but not always, though I believe few extensions would request ""chrome://favicons"" without ""tabs"". There is also bug 104102 which is about creating an API permission for favicons.",Chrome,Yes,0,1,0,0,0,0,0 355,367915,Do not offer to sign-in using a Google profile when opening a Google property in Incognito mode on Android,"1) Sign-in to Chrome for Android 34.0.1847.114 2) Open a new Incognito tab 3) Load YouTube.com Expected: YouTube loads without prompting to sign-in Actual: Chrome displays an infobar in the content area, prompting the user to sign-in using their sync'd profile. If the user consents, this leaks state from the main profile (signed in user) into the Incognito session. If I load a page in Incognito, I expect that existing state - such as sign-in state and cookies - are not provided in the Incognito profile.",Chrome,Yes,0,0,0,1,0,0,1 356,369251,Need unittest for BrowsingDataRemover networking history clear,There's no test case in the BrowsingDataRemover unittest that exercises how networking history is cleared (through ClearNetworkingHistorySince).,Chrome,Yes,1,0,0,0,0,0,0 357,369604,Do not show hotword optin bubble in incognito,Hotwording does not work in incognito mode so we should not show the optin bubble for it.,Chrome,Yes,0,0,0,1,0,0,1 358,374173,Profile avatar icon with grey background seen on chrome taskbar icon,"Chrome Version :36.0.1985.12 (Official Build 270866) m OS-Windows(Aero enabled) What steps will reproduce the problem? 1.Start Chrome with --new-profile-management,Open 'Incognito' window and Observe the 'chrome ' taskbar icon. Profile avatar with grey background seen on chrome taskbar icon. No grey background icon should be seen. This is Regression issue,Broken in M36. Narrow bisect URL: http://build.chromium.org/f/chromium/perf/dashboard/ui/changelog.html?url=/trunk/src&range=267516:267693&mode=html Suspecting : r267529 Note:Issue not reproducible on OS-Mac,Linux Please review attached screenshot and screencast for reference.",Chrome,Yes,0,1,0,0,0,0,0 359,374393,No infobar prompt for https after clearing media exceptions,"Version: M36.0.1985.2 OS: so far seen on Linux, Win7 What steps will reproduce the problem? 1. Open the https version of single-video.html and click allow 2. Open Chrome Settings -> Show advanced settings -> Content settings button -> Media section -> Manage exceptions button, and remove the entry for https://webrtc.googlecode.com 3. Open the https version of single-video.html What is the expected output? Infobar prompt appear What do you see instead? No infobar with Allow and Deny Additional info: - If I open another tab and goto https version of single-video.html then I see the infobar prompt with Allow and Deny. - This is issue might be cause by CL: https://src.chromium.org/viewvc/chrome?revision=268187&view=revision",Chrome,Yes,0,1,0,0,0,0,0 360,374914,Make SDCH dictionaries per-profile,"Currently, there is a single SDCH manager global that is shared by all uses of SDCH. It's fetcher uses the SystemURLRequestContext. Making SDCH per-profile will both improve privacy (there won't be any information leak between profiles as to what dictionaries have been loaded by other profiles) and improve performance (SDCH will then be able to use profile-associated URLRequestContexts, and hence load dictionaries from cache).",Chrome,Yes,0,0,0,0,0,0,1 361,377541,Chrome sends user credentials with preflighed CORS request,"UserAgent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.114 Safari/537.36 Example URL: Steps to reproduce the problem: 1. Send a CORS request that requires a preflight, to a domain which has cookies 2. Note that the preflight request includes cookies 3. Note that this violates https://dvcs.w3.org/hg/cors/raw-file/tip/Overview.html#preflight-request What is the expected behavior? Preflight requests should not include cookies What went wrong? Preflight request included cookies Did this work before? N/A Chrome version: 35.0.1916.114 Channel: stable OS Version: 6.1 (Windows 7, Windows Server 2008 R2) Flash Version: Shockwave Flash 13.0 r0 This was originally filed here: https://code.google.com/p/chromium/issues/detail?id=121904 But was closed as bug is in WebKit. (filed against WebKit here: https://bugs.webkit.org/show_bug.cgi?id=83333 and here https://bugs.webkit.org/show_bug.cgi?id=37676) Since the fork of WebKit to Blink, I assume you are no longer tracking WebKit bugs. This bug should be fixed in Blink.",Chrome,Yes,0,0,0,0,0,0,1 362,380700,"When we turn crash reporting on/off by checking/unchecking ""Automatically send usage statistics and crash reports to Google"" doesn't take immediate effect it needs browser exit and relaunch","Version: 35.0.1916.150, 36.0.1985.32 OS: Win7/8/8.1 What steps will reproduce the problem? 1. Install and launch chrome 2. Navigate to ""Chrome:settings"" --> Advance settings --> make sure ""Automatically send usage statistics and crash reports to Google"" is checked(Test on non-corp machines since corp machines are managed by GPO) 3. now crash chrome using ""about:crash"" or ""about://inducebrowsercrashforrealz"" 4. Navigate to ""about:crashes"" and look for recent crashes(Make sure GoogleCrashHandler.exe and GoogleCrashHandler64.exe were always running) 5. Navigate back to ""Chrome:settings"" --> Advance settings --> make sure ""Automatically send usage statistics and crash reports to Google"" is unchecked(Don't exit chrome) 6. Repeat Step3 7. Open ""about:crashes"" What is the expected output? Latest crash's shouldn't get updated since crash reporting is off. What do you see instead? Crash's are still getting reported. Note : When we restart the browser everything works fine.",Chrome,Yes,0,0,1,0,0,0,0 363,381588,chrome.history API: search() is the sole method that returns results from the archived database,"The method chrome.history.search() will return matches from the archived database, however: (1) The IDs for these HistoryItems can clash with those of non-archived results, because they are the row IDs from the ArchivedDatabase, which assigns IDs unrelated to the main database. (2) Other API methods -- e.g., getVisits(), deleteUrl() -- will not work / have no effect when called with URLs that only exist in the archived database, because these method operate solely on the main database.",Chrome,Yes,1,0,0,0,0,0,0 364,381808,JavaScript can detect visited links via CSS nested