| Who | When | What | Removed | Added |
|---|---|---|---|---|
| gavin.sharp | 2005-08-02 19:30:41 PDT | CC | gavin.sharp | |
| jruderman | 2005-08-02 19:37:19 PDT | Whiteboard | [sg:fix] | |
| jruderman | 2005-08-02 19:39:55 PDT | Product | Toolkit | Firefox |
| jruderman | 2005-08-02 19:40:14 PDT | Group | security | |
| jruderman | 2005-08-02 19:40:32 PDT | Product | Firefox | Toolkit |
| Group | security | |||
| jaime.bugzilla | 2005-08-02 19:41:10 PDT | CC | bugzilla | |
| jruderman | 2005-08-02 19:41:54 PDT | Product | Toolkit | Firefox |
| jruderman | 2005-08-02 19:42:09 PDT | Group | security | |
| jruderman | 2005-08-02 19:42:25 PDT | Product | Firefox | Toolkit |
| Group | security | |||
| jruderman | 2005-08-02 19:57:13 PDT | Product | Toolkit | Firefox |
| jruderman | 2005-08-02 19:57:31 PDT | Group | security | |
| jruderman | 2005-08-02 22:50:56 PDT | Product | Firefox | Toolkit |
| jruderman | 2005-08-03 16:20:14 PDT | URL | http://lxr.mozilla.org/mozilla/source/toolkit/content/contentAreaUtils.js | |
| Summary | Checking focusedWindow in urlSecurityCheck is sketchy | urlSecurityCheck and getReferrer incorrectly use focusedWindow | ||
| jruderman | 2005-08-05 00:05:26 PDT | Blocks | 284868 | |
| jruderman | 2005-08-05 00:12:26 PDT | Blocks | 249747 | |
| jruderman | 2005-08-06 00:18:26 PDT | CC | majken | |
| jruderman | 2005-08-06 01:24:19 PDT | Attachment #191779 Attachment is obsolete | 0 | 1 |
| jruderman | 2005-08-06 02:56:39 PDT | Flags | blocking1.8b4? | |
| jruderman | 2005-08-08 12:39:52 PDT | Attachment #191538 Attachment description | Testcase: Cmd+click the link in this demo to see a spoofed referrer | Testcase: Cmd+click the link in this demo to see a spoofed referrer. (Load from a local server because Bugzilla is https.) |
| dveditz | 2005-08-10 12:13:25 PDT | CC | mconnor, benjamin, neil.parkwaycc.co.uk | |
| jruderman | 2005-08-11 05:02:44 PDT | Attachment #191782 Attachment is obsolete | 0 | 1 |
| jruderman | 2005-08-11 05:02:45 PDT | Attachment #192358 Flags | first-review?(mconnor) | |
| jruderman | 2005-08-11 05:17:28 PDT | Attachment #192358 Attachment is obsolete | 0 | 1 |
| Attachment #192359 Flags | first-review?(mconnor) | |||
| jruderman | 2005-08-11 05:17:54 PDT | Attachment #192358 Flags | first-review?(mconnor) | |
| jruderman | 2005-08-11 09:25:12 PDT | Attachment #191538 Attachment description | Testcase: Cmd+click the link in this demo to see a spoofed referrer. (Load from a local server because Bugzilla is https.) | Testcase: Cmd+click the link in this demo to see a spoofed referrer. (Load from a local server because Bugzilla is https, and make sure "Allow scripts to raise and lower windows" is checked.) |
| mike.shaver | 2005-08-11 11:36:50 PDT | Flags | blocking1.8b4? | blocking1.8b4+ |
| jruderman | 2005-08-11 17:58:20 PDT | Attachment #192359 Attachment is obsolete | 0 | 1 |
| Attachment #192451 Flags | first-review?(mconnor) | |||
| jruderman | 2005-08-11 17:58:39 PDT | Attachment #192359 Flags | first-review?(mconnor) | |
| jruderman | 2005-08-11 17:59:48 PDT | Blocks | 302022 | |
| mconnor | 2005-08-11 23:21:29 PDT | Attachment #192451 Flags | first-review?(mconnor) | first-review+, approval1.8b4+ |
| majken | 2005-08-11 23:37:23 PDT | CC | majken | |
| jruderman | 2005-08-11 23:40:31 PDT | Attachment #192451 Attachment is obsolete | 0 | 1 |
| jruderman | 2005-08-11 23:57:10 PDT | Status | NEW | RESOLVED |
| Resolution | --- | FIXED | ||
| Closed | 2005-08-12 06:57:10 | |||
| jruderman | 2005-08-20 01:08:47 PDT | Blocks | 226548 | |
| jruderman | 2005-08-20 14:32:21 PDT | Depends on | 304418 | |
| dveditz | 2005-11-14 10:57:54 PST | CC | lloyd | |
| Flags | blocking-aviary1.0.8? | |||
| bob | 2006-01-16 18:29:51 PST | Flags | testcase+ | |
| dveditz | 2006-01-30 12:24:00 PST | Flags | blocking-aviary1.0.8? | blocking-aviary1.0.8+ |
| dveditz | 2006-02-10 16:32:22 PST | Whiteboard | [sg:fix] | [sg:low spoof] |
| Flags | blocking-aviary1.0.8+ | blocking-aviary1.0.8- | ||
| dveditz | 2007-03-20 23:17:33 PDT | Group | security | |
| bob | 2007-04-01 15:14:13 PDT | CC | bclary | |
| Flags | in-testsuite+ | in-testsuite? | ||
| dveditz | 2007-12-21 14:50:44 PST | Keywords | fixed1.8 | |
| jruderman | 2013-06-09 18:59:39 PDT | Keywords | csec-spoof, sec-low | |
| Whiteboard | [sg:low spoof] | |||
| nobody | 2016-06-29 13:03:03 PDT | Product | Toolkit | Toolkit Graveyard |