FxA navigator.mozID API: move access check from child process (nsDOMIdentity.js) to parent process(DOMIdentity.jsm)

RESOLVED DUPLICATE of bug 1028398

Status

RESOLVED DUPLICATE of bug 1028398
4 years ago
4 years ago

People

(Reporter: spenrose, Assigned: jedp)

Tracking

Firefox Tracking Flags

(Not tracked)

Details

(Reporter)

Description

4 years ago
Currently nsDOMIdentity.request() checks whether the calling app has permissions to access Firefox Accounts:

  https://github.com/mozilla/gecko-dev/blob/master/dom/identity/nsDOMIdentity.js#L178

To deepen defense against a client which has comprised this routine, move the check to DOMIdentity.jsm.
Blocks: 997361
Assignee: nobody → jparsons
Status: NEW → ASSIGNED
Oh sweet - :ferjm is already doing this as part of Bug 1028398.  Thanks, Fernando.
Status: ASSIGNED → RESOLVED
Last Resolved: 4 years ago
Resolution: --- → DUPLICATE
Duplicate of bug: 1028398
You need to log in before you can comment on or make changes to this bug.