[Webkit-unassigned] [Bug 250776] Content-Security-Policy upgrade-insecure-requests should not be applied to localhost

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Thu Jan 19 23:44:42 PST 2023


https://bugs.webkit.org/show_bug.cgi?id=250776

Anne van Kesteren <annevk at annevk.nl> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
         Depends on|                            |171934

--- Comment #7 from Anne van Kesteren <annevk at annevk.nl> ---
Until we have a path toward fixing bug 171934, I'm not sure it makes a lot of sense to put effort into this. We could address it now, but it would still result in localhost not being accessible.


Referenced Bugs:

https://bugs.webkit.org/show_bug.cgi?id=171934
[Bug 171934] Don't treat loopback addresses (127.0.0.0/8, ::1/128, localhost, .localhost) as mixed content
-- 
You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.webkit.org/pipermail/webkit-unassigned/attachments/20230120/349c3ae0/attachment.htm>


More information about the webkit-unassigned mailing list