incorrect hsts handling with http

Bug #1130395 reported by Kevin Fenzi
10
This bug affects 2 people
Affects Status Importance Assigned to Milestone
Midori Web Browser
Expired
Undecided
Unassigned

Bug Description

Midori doesn't seem to behave right handling HSTS sites.

Go to:

http://nathaniel.themccallums.org/2013/02/18/migrating-the-blog-to-openshift/

This will have:

Strict-Transport-Security:

header.

However, since it's over http, it SHOULD NOT honor it.
See:
http://tools.ietf.org/html/rfc6797
section 8.1

Instead it does honor it and loads the https site.

Gtklauncher, arora and epiphany all show the http site, so this looks like a bug in midori and not webkitgtk.

Tags: hsts
Revision history for this message
Kevin Fenzi (kevin-launchpad) wrote :

To clarify, it MUST NOT honor the header. (not a SHOULD NOT, but a MUST NOT).

Revision history for this message
gue5t gue5t (gue5t) wrote :

Do you know of a site on which to reproduce this? I can't do so at the given address but curl does not show the header you mention. If this is reproducible it should definitely be fixed.

tags: added: hsts
Cris Dywan (kalikiana)
Changed in midori:
status: New → Incomplete
summary: - incorrect hsts handling
+ incorrect hsts handling with http
Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for Midori because there has been no activity for 60 days.]

Changed in midori:
status: Incomplete → Expired
Revision history for this message
Kevin Fenzi (kevin-launchpad) wrote :

Sorry, I didn't see your query for another domain...

How about:

http://kojipkgs.fedoraproject.org//work/tasks/7090/9447090/

That sends: "Strict-Transport-Security: max-age=15768000; includeSubDomains; preload"

With firefox or another browser that supports HSTS correctly, all further access to that site uses https.
Midori doesn't.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.