Closed Bug 1247464 Opened 9 years ago Closed 9 years ago

CSP report URIs are not run through the URL classifier

Categories

(Toolkit :: Safe Browsing, defect)

defect
Not set
normal

Tracking

()

RESOLVED FIXED
mozilla47
Tracking Status
firefox47 --- fixed

People

(Reporter: francois, Assigned: francois)

References

(Blocks 1 open bug)

Details

Attachments

(2 files)

Attached file csp-reporturi.html
Steps: 1. Host the attached test page on a web server. 2. Serve it with this CSP header: img-src 'none'; report-uri https://itisatracker.com/csp-report 3. Open that test page in Private Browsing. Expected: The report is not sent because the reporting endpoint is on the TP list. Actual: The report is sent.
Component: DOM: Security → Safe Browsing
Product: Core → Toolkit
Attachment #8718651 - Flags: review?(mozilla) → review+
Comment on attachment 8718651 [details] MozReview Request: Bug 1247464 - Run CSP report URIs through the URL classifier. r?ckerschb https://reviewboard.mozilla.org/r/34667/#review31347 Looks good to me - thanks!
Status: ASSIGNED → RESOLVED
Closed: 9 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla47
Blocks: 1207775
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: