Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(30)

Issue 282873003: Handle max-age in HPKP. (Closed)

Created:
6 years, 7 months ago by palmer
Modified:
6 years, 7 months ago
Reviewers:
agl, Ryan Sleevi
CC:
chromium-reviews, cbentzel+watch_chromium.org
Visibility:
Public.

Description

Patch Set 1 #

Total comments: 1

Patch Set 2 : Test the current "exact of a preload wins" policy. #

Total comments: 2

Patch Set 3 : Test bad hashes to force a pin validation failure. #

Total comments: 7

Patch Set 4 : Fix nits. #

Unified diffs Side-by-side diffs Delta from patch set Stats (+79 lines, -2 lines) Patch
M net/http/http_security_headers_unittest.cc View 1 2 3 1 chunk +75 lines, -0 lines 0 comments Download
M net/http/transport_security_state.cc View 2 chunks +4 lines, -2 lines 0 comments Download

Messages

Total messages: 19 (0 generated)
palmer
PTAL. Thanks!
6 years, 7 months ago (2014-05-13 20:10:13 UTC) #1
Ryan Sleevi
https://codereview.chromium.org/282873003/diff/1/net/http/http_security_headers_unittest.cc File net/http/http_security_headers_unittest.cc (right): https://codereview.chromium.org/282873003/diff/1/net/http/http_security_headers_unittest.cc#newcode631 net/http/http_security_headers_unittest.cc:631: } More testing: Good that you test the static/dynamic ...
6 years, 7 months ago (2014-05-13 21:12:23 UTC) #2
palmer
> More testing: Good that you test the static/dynamic state, but what's the > expected ...
6 years, 7 months ago (2014-05-13 21:23:24 UTC) #3
Ryan Sleevi
On 2014/05/13 21:23:24, Chromium Palmer wrote: > > More testing: Good that you test the ...
6 years, 7 months ago (2014-05-13 22:16:22 UTC) #4
palmer
> So then, what is our present policy, and can you add a test to ...
6 years, 7 months ago (2014-05-13 23:22:48 UTC) #5
Ryan Sleevi
https://codereview.chromium.org/282873003/diff/20001/net/http/http_security_headers_unittest.cc File net/http/http_security_headers_unittest.cc (right): https://codereview.chromium.org/282873003/diff/20001/net/http/http_security_headers_unittest.cc#newcode640 net/http/http_security_headers_unittest.cc:640: EXPECT_EQ(0UL, failure_log.length()); So, this doesn't seem like it actually ...
6 years, 7 months ago (2014-05-13 23:51:28 UTC) #6
palmer
https://codereview.chromium.org/282873003/diff/20001/net/http/http_security_headers_unittest.cc File net/http/http_security_headers_unittest.cc (right): https://codereview.chromium.org/282873003/diff/20001/net/http/http_security_headers_unittest.cc#newcode640 net/http/http_security_headers_unittest.cc:640: EXPECT_EQ(0UL, failure_log.length()); > So, this doesn't seem like it ...
6 years, 7 months ago (2014-05-14 00:23:51 UTC) #7
Ryan Sleevi
On 2014/05/14 00:23:51, Chromium Palmer wrote: > https://codereview.chromium.org/282873003/diff/20001/net/http/http_security_headers_unittest.cc > File net/http/http_security_headers_unittest.cc (right): > > https://codereview.chromium.org/282873003/diff/20001/net/http/http_security_headers_unittest.cc#newcode640 ...
6 years, 7 months ago (2014-05-14 01:43:20 UTC) #8
palmer
> What we've said is dynamic max-age=0 should NOT disable static pins. > > The ...
6 years, 7 months ago (2014-05-14 21:03:52 UTC) #9
agl
LGTM https://codereview.chromium.org/282873003/diff/40001/net/http/http_security_headers_unittest.cc File net/http/http_security_headers_unittest.cc (right): https://codereview.chromium.org/282873003/diff/40001/net/http/http_security_headers_unittest.cc#newcode582 net/http/http_security_headers_unittest.cc:582: EXPECT_TRUE( ASSERT_TRUE? (I.e. the test is boned if ...
6 years, 7 months ago (2014-05-15 00:01:53 UTC) #10
palmer
https://codereview.chromium.org/282873003/diff/40001/net/http/http_security_headers_unittest.cc File net/http/http_security_headers_unittest.cc (right): https://codereview.chromium.org/282873003/diff/40001/net/http/http_security_headers_unittest.cc#newcode582 net/http/http_security_headers_unittest.cc:582: EXPECT_TRUE( On 2014/05/15 00:01:53, agl wrote: > ASSERT_TRUE? (I.e. ...
6 years, 7 months ago (2014-05-15 00:22:31 UTC) #11
palmer
The CQ bit was checked by palmer@chromium.org
6 years, 7 months ago (2014-05-15 00:22:38 UTC) #12
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-status.appspot.com/cq/palmer@chromium.org/282873003/60001
6 years, 7 months ago (2014-05-15 00:24:49 UTC) #13
commit-bot: I haz the power
FYI, CQ is re-trying this CL (attempt #1). Please consider checking whether the failures are ...
6 years, 7 months ago (2014-05-15 02:20:39 UTC) #14
commit-bot: I haz the power
The CQ bit was unchecked by commit-bot@chromium.org
6 years, 7 months ago (2014-05-15 02:23:54 UTC) #15
commit-bot: I haz the power
Try jobs failed on following builders: ios_rel_device on tryserver.chromium (http://build.chromium.org/p/tryserver.chromium/builders/ios_rel_device/builds/141843)
6 years, 7 months ago (2014-05-15 02:23:54 UTC) #16
palmer
The CQ bit was checked by palmer@chromium.org
6 years, 7 months ago (2014-05-15 17:10:39 UTC) #17
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-status.appspot.com/cq/palmer@chromium.org/282873003/60001
6 years, 7 months ago (2014-05-15 17:13:39 UTC) #18
commit-bot: I haz the power
6 years, 7 months ago (2014-05-15 17:30:47 UTC) #19
Message was sent while issue was closed.
Change committed as 270716

Powered by Google App Engine
This is Rietveld 408576698