You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Dec 11, 2019. It is now read-only.
open the same page in a regular tab and observe mixed content is still allowed
Expected behavior:
site-specific settings should never leak from private browsing to regular browsing because this opens up ways for a malicious page to figure out what sites have been visited in private browsing mode. leaks in the other direction (from regular into private) are less serious.
this was accidentally auto-closed; i'll edit the title to be the issue that was actually closed and move the rest to 0.12.2
diracdeltas
changed the title
site settings from private mode should not apply in regular browsing mode
mixed content site setting from private mode should not apply in regular browsing mode
Sep 9, 2016
Sorry, I forgot to mention for QA's sake that it was decided that private tabs should not be able to allow mixed content in the first place. But mixed content settings from regular mode should not apply in private mode.
Sign up for freeto subscribe to this conversation on GitHub.
Already have an account?
Sign in.
site-specific settings should never leak from private browsing to regular browsing because this opens up ways for a malicious page to figure out what sites have been visited in private browsing mode. leaks in the other direction (from regular into private) are less serious.
Allow per site Bravery settings in private tabs #1824
cc @bridiver
The text was updated successfully, but these errors were encountered: