After enabling protection on a mixed content site the site is displayed as secure when X-Frame-Options is used
Categories
(Core :: DOM: Security, defect, P3)
Tracking
()
People
(Reporter: VarCat, Unassigned)
References
(Blocks 1 open bug)
Details
(Whiteboard: [domsecurity-backlog2])
![]() |
Reporter | |
Updated•10 years ago
|
![]() |
||
Comment 1•10 years ago
|
||
![]() |
||
Comment 2•10 years ago
|
||
![]() |
||
Comment 3•10 years ago
|
||
Updated•10 years ago
|
Comment 4•10 years ago
|
||
Updated•10 years ago
|
Comment 5•10 years ago
|
||
Comment 6•9 years ago
|
||
Comment 7•6 years ago
|
||
Tanvi, Jonathan, do either of you have context on this 4-year-old bug that blocks MCB? Is it still relevant?
Comment 8•6 years ago
|
||
Given Comment 4, it sounds like there isn't cache invalidation happening when the user disables protection and re-enables it. That to me sounds like a bigger issue that should be probably be investigated.
Perhaps the MCB should enforce that all loads get revalidated over the network when protection is enabled.
Shouldn't this be in Firefox:Security or DOM:Security? Perhaps even Necko? I think at best this is a P3 though but requires further investigation.
Comment 9•6 years ago
|
||
Also we should probably write a test as the pmo site has gone, but the comments describe how this worked.
Comment 10•6 years ago
|
||
Since this does not seem to be a frontend issue, moving this to Core :: DOM: Security as suggested in comment 8.
Updated•6 years ago
|
Updated•3 years ago
|
Description
•