WICG / WICG/webpackage

Prevent fallback loop when publisher publishes invalid SXG

Open
#432 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Go
Stars
1.3k
Forks
125
PR merge metrics
No merged PRs in 30d

Description

https://crbug.com/939684 handles this by removing application/signed-exchange from the Accept header on fallback, but @gregable mentions the possibility of not-checking the signature for a same-origin signed exchange.

This interacts with #397 in that we'll want to make sure the loop prevention works for every reason we might use the fallback URL.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading crbug.com/939684 and issue #397, then trace how fallback URLs are selected when a publisher provides an invalid signed exchange. Done means fallback cannot loop for each reason identified in #397, including the invalid-SXG case.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
web-dev
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.