* SUMMARY H&R Block's tax website will not load in WebKit nightly builds that contain r112217. * STEPS TO REPRODUCE 1. Go to http://taxes.hrblock.com 2. Under 'New User', click 'Start Without an Account'. 3. Accept the license agreement and privacy policy and click 'Next'. * RESULTS Expected: A secure connection should be established and the site's main menu should be displayed. Actual: Nothing happens after step #3. * REGRESSION Caused by <http://trac.webkit.org/changeset/112217>.
<rdar://problem/11167741>
I am looking at it right now.
Created attachment 135229 [details] Proposed Patch
Comment on attachment 135229 [details] Proposed Patch I see. Maybe try setting a custom header and having a same-origin redirect. That will probably fail the CORS check but be allowed because it's same-origin.
Created attachment 135241 [details] Proposed Patch Added a test case for this. I manually verified that the code change fixes the website. I still need to verify the test.
Comment on attachment 135241 [details] Proposed Patch Attachment 135241 [details] did not pass chromium-ews (chromium-xvfb): Output: http://queues.webkit.org/results/12310822 New failing tests: http/tests/xmlhttprequest/access-control-and-redirects-async.html
Created attachment 135259 [details] Archive of layout-test-results from ec2-cr-linux-03 The attached test failures were seen while running run-webkit-tests on the chromium-ews. Bot: ec2-cr-linux-03 Port: <class 'webkitpy.common.config.ports.ChromiumXVFBPort'> Platform: Linux-2.6.35-28-virtual-x86_64-with-Ubuntu-10.10-maverick
Created attachment 135276 [details] Proposed Patch I had to do fairly extensive reworking of this patch, both code and tests. If you prefer to revert the change, don't forget the later change I made to AssociatedURLLoader and tests. http://trac.webkit.org/changeset/112485
The problem with 57600 is that it breaks same-origin redirects when using access control. This patch rearranges things so that same origin requests (and loaders with universal access) can proceed as before. Only if that fails do we check using access control. I tested this with the replication steps above and the website now loads.
Comment on attachment 135276 [details] Proposed Patch Thanks Bill!
Comment on attachment 135276 [details] Proposed Patch Clearing flags on attachment: 135276 Committed r112997: <http://trac.webkit.org/changeset/112997>
This bug is still open, can it be closed now?
Yes. The bot didn't close it because the 2nd patch was still marked for review.