Commit ed65b0f7 authored by Simon Friedberger's avatar Simon Friedberger Committed by sfriedberger@mozilla.com
Browse files

Bug 1897136 - Fix HTTPS first downgrades for proxies r=maltejur,valentin,extension-reviewers,robwu

For HTTPS first we want to treat NS_ERROR_UNKNOWN_HOST as an HTTPS
related error because it might be a 404 returned by a proxy (see
HttpProxyResponseToErrorCode). For the HTTPS-only case we don't want
that because it almost always is an unrelated error and the users would
have to confirm the interstitial every time to find out.

Differential Revision: https://phabricator.services.mozilla.com/D209247
parent 475fbb58
Loading
Loading
Loading
Loading
+16 −2
Changes for dom/security/nsHTTPSOnlyUtils.cpp: 16 added lines, 2 removed lines.
Original line number Diff line number Diff line
@@ -494,12 +494,26 @@ nsHTTPSOnlyUtils::PotentiallyDowngradeHttpsFirstRequest(

  // We're only downgrading if it's possible that the error was
  // caused by the upgrade.
  if (HttpsUpgradeUnrelatedErrorCode(status)) {
  nsCOMPtr<nsIHttpChannelInternal> httpChannelInternal(
      do_QueryInterface(channel));
  if (!httpChannelInternal) {
    return nullptr;
  }
  bool proxyUsed = false;
  nsresult rv = httpChannelInternal->GetIsProxyUsed(&proxyUsed);
  MOZ_ASSERT(NS_SUCCEEDED(rv));
  if (!(proxyUsed && status == nsresult::NS_ERROR_UNKNOWN_HOST)
      // When a proxy returns an error code it is converted by
      // HttpProxyResponseToErrorCode. We do want to downgrade in
      // that case. If the host is actually unreachable this will
      // show the same error page, but technically for the HTTP
      // site not the HTTPS site.
      && HttpsUpgradeUnrelatedErrorCode(status)) {
    return nullptr;
  }

  nsCOMPtr<nsIURI> uri;
  nsresult rv = channel->GetURI(getter_AddRefs(uri));
  rv = channel->GetURI(getter_AddRefs(uri));
  NS_ENSURE_SUCCESS(rv, nullptr);

  nsAutoCString spec;
+1 −0
Changes for toolkit/components/extensions/test/xpcshell/xpcshell-common.toml: 1 added line, 0 removed lines.
Original line number Diff line number Diff line
@@ -229,6 +229,7 @@ skip-if = ["os == 'android'"] # Android: downloads.download goes through the emb
["test_ext_dnr_modifyHeaders.js"]

["test_ext_dnr_private_browsing.js"]
https_first_disabled = true # Bug 1897075

["test_ext_dnr_redirect_main_frame.js"]

+1 −1
Changes for uriloader/exthandler/tests/mochitest/browser.toml: 1 added line, 1 removed line.
Original line number Diff line number Diff line
@@ -25,7 +25,7 @@ support-files = ["download.bin"]

["browser_download_idn_blocklist.js"]
support-files = ["download.bin"]
https_first_disabled = true
https_first_disabled = true # Bug 1897075

["browser_download_open_with_internal_handler.js"]
support-files = [