Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Disables suggested top sites from upstream on initial start #24511

Merged
merged 1 commit into from
Jul 5, 2024

Conversation

SergeyZhukovsky
Copy link
Member

@SergeyZhukovsky SergeyZhukovsky commented Jul 4, 2024

Security review https://github.com/brave/reviews/issues/1678

Resolves brave/brave-browser#39541
There is a follow up created brave/brave-browser#39574 to make network audit tests for Android.

Submitter Checklist:

  • I confirm that no security/privacy review is needed and no other type of reviews are needed, or that I have requested them
  • There is a ticket for my issue
  • Used Github auto-closing keywords in the PR description above
  • Wrote a good PR/commit description
  • Squashed any review feedback or "fixup" commits before merge, so that history is a record of what happened in the repo, not your PR
  • Added appropriate labels (QA/Yes or QA/No; release-notes/include or release-notes/exclude; OS/...) to the associated issue
  • Checked the PR locally:
    • npm run test -- brave_browser_tests, npm run test -- brave_unit_tests wiki
    • npm run presubmit wiki, npm run gn_check, npm run tslint
  • Ran git rebase master (if needed)

Reviewer Checklist:

  • A security review is not needed, or a link to one is included in the PR description
  • New files have MPL-2.0 license header
  • Adequate test coverage exists to prevent regressions
  • Major classes, functions and non-trivial code blocks are well-commented
  • Changes in component dependencies are properly reflected in gn
  • Code follows the style guide
  • Test plan is specified in PR before merging

After-merge Checklist:

Test Plan:

  1. Install Brave and open it.
  2. Make sure there are no icons on NTP.
  3. Open a few more NTP and make sure there are no icons.
@SergeyZhukovsky SergeyZhukovsky self-assigned this Jul 4, 2024
@SergeyZhukovsky SergeyZhukovsky requested a review from a team as a code owner July 4, 2024 17:54
@github-actions github-actions bot added CI/run-network-audit Run network-audit CI/run-upstream-tests Run upstream unit and browser tests on Linux and Windows (otherwise only on Linux) labels Jul 4, 2024
@SergeyZhukovsky SergeyZhukovsky merged commit 22d1277 into master Jul 5, 2024
20 checks passed
@SergeyZhukovsky SergeyZhukovsky deleted the disable_pre_defined_top_sites branch July 5, 2024 13:10
@github-actions github-actions bot added this to the 1.69.x - Nightly milestone Jul 5, 2024
brave-builds added a commit that referenced this pull request Jul 8, 2024
@kjozwiak
Copy link
Member

Verification PASSED on Pixel 6 Pro running Android 15 using the following build(s):

Brave | 1.69.111 Chromium: 127.0.6533.43 (Official Build) canary (64-bit)
--- | ---
Revision | 4d39f6a867ca388981fcb24fb2bf4007ae913651
OS | Android 15; Build/AP31.240517.031; 35; REL

Using 1.69.83 Chromium: 127.0.6533.26, reproduced the original issue where the NTP page is populated with pre-determined websites for a specific region. In doing so, it contacts these websites without user consent to download/retrieve the needed icons as per the following:

Example Example
Screenshot 2024-07-16 at 5 22 35 PM Screenshot_20240716-172155

Using 1.69.111 Chromium: 127.0.6533.43, ensured that we're not pulling/populating website via NTP as per the following:

Example Example Example
Screenshot 2024-07-16 at 5 26 50 PM Screenshot_20240716-172615 Screenshot_20240716-172900
  • ensured that the pre-determined websites based on region are not being populated via NTP on first launch
  • ensured that there's no websites being displayed/being loaded when opening several NTP
  • ensured that there's no connections to websites like bestbuy.com, facebook.com & amazon.com via Proxyman
  • ensured that once you start visiting several websites, the most popular/visited ones get loaded into Favorites
kjozwiak pushed a commit that referenced this pull request Jul 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
CI/run-network-audit Run network-audit CI/run-upstream-tests Run upstream unit and browser tests on Linux and Windows (otherwise only on Linux)
3 participants