<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>247197</bug_id>
          
          <creation_ts>2022-10-28 08:08:31 -0700</creation_ts>
          <short_desc>Upgrade requests in mixed content settings</short_desc>
          <delta_ts>2024-09-07 12:01:51 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Page Loading</component>
          <version>Safari Technology Preview</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <see_also>https://bugs.webkit.org/show_bug.cgi?id=269172</see_also>
    
    <see_also>https://bugs.webkit.org/show_bug.cgi?id=279249</see_also>
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          <blocked>140625</blocked>
    
    <blocked>219396</blocked>
          <everconfirmed>1</everconfirmed>
          <reporter name="Matthew Finkel">m_finkel</reporter>
          <assigned_to name="Matthew Finkel">m_finkel</assigned_to>
          <cc>beidson</cc>
    
    <cc>fbraun</cc>
    
    <cc>fujii</cc>
    
    <cc>mcatanzaro</cc>
    
    <cc>webkit-bug-importer</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1909021</commentid>
    <comment_count>0</comment_count>
    <who name="Matthew Finkel">m_finkel</who>
    <bug_when>2022-10-28 08:08:31 -0700</bug_when>
    <thetext>Upgrading inactive/passive subresource requests and fetches in would-be mixed security contexts is the new standard: https://www.w3.org/TR/mixed-content/#category-upgradeable</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1909022</commentid>
    <comment_count>1</comment_count>
    <who name="Radar WebKit Bug Importer">webkit-bug-importer</who>
    <bug_when>2022-10-28 08:08:44 -0700</bug_when>
    <thetext>&lt;rdar://problem/101678657&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1914047</commentid>
    <comment_count>2</comment_count>
    <who name="Frederik Braun (Mozilla)">fbraun</who>
    <bug_when>2022-11-22 04:31:16 -0800</bug_when>
    <thetext>Drive-by comment, is this the same as bug 219396 (though the other seems to have more details)?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1914079</commentid>
    <comment_count>3</comment_count>
    <who name="Michael Catanzaro">mcatanzaro</who>
    <bug_when>2022-11-22 06:58:22 -0800</bug_when>
    <thetext>More or less the same, yes. I was tempted to mark this as a duplicate, but there is a slight difference in scope: bug #219396 additionally envisions removing internal settings and deprecating public settings, and that requires some Linux-specific changes that Apple engineers might not be comfortable with making, but would be very easy for me to do in a follow-up patch in that bug if the main work were to be handled in this bug. So I&apos;ll leave it for Matthew to decide whether to leave them both open or mark this one as a duplicate.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1914989</commentid>
    <comment_count>4</comment_count>
    <who name="Matthew Finkel">m_finkel</who>
    <bug_when>2022-11-28 08:34:24 -0800</bug_when>
    <thetext>(In reply to Frederik Braun (Mozilla) from comment #2)
&gt; Drive-by comment, is this the same as bug 219396 (though the other seems to
&gt; have more details)?

Oh, indeed! My apologies for missing that bug 219396 already includes this.

(In reply to Michael Catanzaro from comment #3)
&gt; More or less the same, yes. I was tempted to mark this as a duplicate, but
&gt; there is a slight difference in scope: bug #219396 additionally envisions
&gt; removing internal settings and deprecating public settings, and that
&gt; requires some Linux-specific changes that Apple engineers might not be
&gt; comfortable with making, but would be very easy for me to do in a follow-up
&gt; patch in that bug if the main work were to be handled in this bug. So I&apos;ll
&gt; leave it for Matthew to decide whether to leave them both open or mark this
&gt; one as a duplicate.

I like that plan. Let&apos;s focus on only upgrading http requests here, and then bug 219396 can track the remaining pieces (possibly as a meta bug).</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1930730</commentid>
    <comment_count>5</comment_count>
    <who name="Matthew Finkel">m_finkel</who>
    <bug_when>2023-02-02 18:55:35 -0800</bug_when>
    <thetext>Pull request: https://github.com/webkit/WebKit/pull/9577</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1938391</commentid>
    <comment_count>6</comment_count>
    <who name="Matthew Finkel">m_finkel</who>
    <bug_when>2023-03-02 19:22:33 -0800</bug_when>
    <thetext>Pull request: https://github.com/WebKit/WebKit/pull/9577</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2012432</commentid>
    <comment_count>7</comment_count>
    <who name="EWS">ews-feeder</who>
    <bug_when>2024-02-09 21:12:11 -0800</bug_when>
    <thetext>Committed 274409@main (8a3335648a55): &lt;https://commits.webkit.org/274409@main&gt;

Reviewed commits have been landed. Closing PR #9577 and removing active labels.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2012834</commentid>
    <comment_count>8</comment_count>
    <who name="Fujii Hironori">fujii</who>
    <bug_when>2024-02-12 12:21:29 -0800</bug_when>
    <thetext>http/tests/navigation/ping-attribute/area-cross-origin-from-https-UpgradeMixedContent.html is a flaky failure. bug#269223 tracks the bug.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>