You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Anuj Goyal, securi...@chromium.org, Julian Pastarmov, Owen Min, Yann Dago
I made some comments in the flag expiry design doc suggesting that a good mitigation for this case would be to add a policy to replace the functionality of the flag. We should do that if we believe there's a real need for enterprises to switch on this behavior
Christopher Thompson
unread,
Aug 26, 2019, 12:38:33 PM8/26/19
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Brandon Heenan, Anuj Goyal, securi...@chromium.org, Julian Pastarmov, Owen Min, Yann Dago
Hi all --
I've uploaded a CL to bump the expiration on the allow-insecure-localhost and unsafely-treat-insecure-origin-as-secure, so these will still be available from chrome://flags in M-78+. We may revisit these flags in the future, but we don't currently have plans to remove them.
If there are specific enterprise use cases for the allow-insecure-localhost flag, that might be good to know as well for making longer term plans (the linked Enterprise forum thread doesn't have any useful information in it).
- Chris
Brandon Heenan
unread,
Sep 3, 2019, 12:51:32 PM9/3/19
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Christopher Thompson, Anuj Goyal, securi...@chromium.org, Julian Pastarmov, Owen Min, Yann Dago
I think it's a development use case, to allow people to run/test https sites they're building locally. Is there a better / another way of accomplishing that use case?