CSP policy does not work in fetch() in dedicated worker.

RESOLVED DUPLICATE of bug 959388

Status

()

Core
DOM: Security
RESOLVED DUPLICATE of bug 959388
2 years ago
2 years ago

People

(Reporter: tnguyen, Unassigned)

Tracking

Firefox Tracking Flags

(Not tracked)

Details

(Whiteboard: [domsecurity-backlog])

(Reporter)

Description

2 years ago
This test hits this issue: <https://dxr.mozilla.org/mozilla-central/source/testing/web-platform/tests/fetch/api/policies/csp-blocked-worker.html>

What happens is the document is served with a CSP that sets "connect-src 'none'", 
Interestingly, nsCSPContext does not add any policy to mPolicies. There's no csp policy checks running and the test case fails.
(Reporter)

Updated

2 years ago
Summary: CSP policy does not work in fetch in dedicated worker. → CSP policy does not work in fetch() in dedicated worker.
(Reporter)

Updated

2 years ago
Blocks: 1251378
(Reporter)

Updated

2 years ago
No longer blocks: 1251378
(Reporter)

Updated

2 years ago
Blocks: 1251378
Whiteboard: [domsecurity-backlog]
(Reporter)

Updated

2 years ago
Status: NEW → RESOLVED
Last Resolved: 2 years ago
Resolution: --- → DUPLICATE
Duplicate of bug: 959388
You need to log in before you can comment on or make changes to this bug.