Closed
Bug 1217236
Opened 9 years ago
Closed 9 years ago
Tracking protection: Resources on blocklist not blocked when accessed via Flash movies
Categories
(Toolkit :: Safe Browsing, defect)
Tracking
()
VERIFIED
FIXED
mozilla45
Tracking | Status | |
---|---|---|
firefox45 | --- | verified |
People
(Reporter: mwobensmith, Assigned: francois)
References
(Blocks 1 open bug)
Details
Attachments
(1 file)
1.19 KB,
patch
|
gcp
:
review+
|
Details | Diff | Splinter Review |
A SWF that loads a resource that is on our Tracking Protection blocklist is currently able to do so. This is wrong. This issue may affect the NPAPI in general.
Note:
Please contact me for bug files. Reproducing this requires a custom blocklist, an emulated local shavar server and a custom Flash movie. I'm happy to stage something when we get around to looking at it.
Reporter | ||
Comment 1•9 years ago
|
||
This SWF loads the blocked URL "http://www.adjuggler.com/images/logo-ad-juggler.png":
http://people.mozilla.org/~mwobensmith/tracking_protection/flash.html
Assignee | ||
Comment 2•9 years ago
|
||
Attachment #8696304 -
Flags: review?(gpascutto)
Assignee | ||
Updated•9 years ago
|
Status: NEW → ASSIGNED
Updated•9 years ago
|
Attachment #8696304 -
Flags: review?(gpascutto) → review+
Comment 4•9 years ago
|
||
bugherder |
Status: ASSIGNED → RESOLVED
Closed: 9 years ago
status-firefox45:
--- → fixed
Resolution: --- → FIXED
Target Milestone: --- → mozilla45
Reporter | ||
Comment 5•9 years ago
|
||
Looks to be fixed in latest Nightly 45, but the shield icon does not appear, despite having a blocked resource. Are we tracking that in another bug, or should I file a new one?
Flags: needinfo?(francois)
Assignee | ||
Comment 6•9 years ago
|
||
You're right, it also looks like the devtool console message isn't there. This needs a new bug.
Flags: needinfo?(francois)
Reporter | ||
Comment 7•9 years ago
|
||
Marking verified, and filed new bug 1232487 to track the lack of shield icon and console message.
Reporter | ||
Updated•9 years ago
|
Status: RESOLVED → VERIFIED
Assignee | ||
Updated•9 years ago
|
You need to log in
before you can comment on or make changes to this bug.
Description
•