为facebook.com删除Chrome HSTS无效 [英] Deleting Chrome HSTS for facebook.com not working

查看:580
本文介绍了为facebook.com删除Chrome HSTS无效的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧!

问题描述

我目前正在我的网站上进行一些调试,包括调用Facebook API。



我已经安装了dnsmasq来与我的mac os X一起将所有请求重定向到facebook.com到127.0.0.1



我有一个回显服务器,它将在笔记本电脑的端口80上打印出所有原始http请求标头。



现在出现我的问题。当我访问facebook.com时,我意识到chrome会自动将http://转发到https:// for facebook.com。

我使用Google搜索并找到了删除此方法的方法HSTS问题。我访问 chrome:// net-internals#hsts 查看如下内容:



facebook.com ,其中一些子域名包含在Chrome的预加载列表


I am currently doing some debugging on my website which involves calling the facebook API.

I've installed dnsmasq to work with my mac os X to redirect all request to facebook.com to 127.0.0.1

I have a echo server which will print out all the raw http request header on port 80 on my laptop.

Now comes my problem. When I access facebook.com, I realize chrome will automatically forward http:// to https:// for facebook.com

I googled and found the way of deleting this HSTS issue. I visit chrome://net-internals#hsts to see something like this:

HSTS chrome image

After entering "facebook.com" under "Delete domain", I can still query "facebook.com" in the input box below.

I tried clearing all user data on chrome, closing and reopening chrome and even using incognito mode.

  • Why is chrome still redirecting all request to facebook.com to https?

  • How can I disable this if chrome://net-internals#hsts is not reliable?

解决方案

The text next to the Delete domain box on chrome://net-internals/#hsts clearly states that preloaded entries cannot be deleted. This feature request was closed as WontFix in the Chrome bug tracker.

facebook.com and quite a few of its subdomains are included in Chrome's preload list.

这篇关于为facebook.com删除Chrome HSTS无效的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持IT屋!

查看全文
登录 关闭
扫码关注1秒登录
发送“验证码”获取 | 15天全站免登陆