https://hg.mozilla.org/mozilla-central/rev/62903b5a04a7 (Jonas Sicking (:sicking) from Bug 1259871 comment #13) > We mainly created getSimpleCodebasePrincipal so that we could add assertions > to make sure that such principals were never used to look up permissions or > localStorage/IndexedDB data. > > I.e. we did it to try to find code that created principals without passing > in the correct appid when the appid really mattered. > > This was especially important since appid was a FirefoxOS-only thing, so not > something that we expected Gecko engineers to care about or do correctly. > > Since OriginAttributes are used by Firefox, I think we have a much larger > chance of getting them used correctly. > > So yeah, I think we should replace createSimpleCodebasePrincipal with > createCodebasePrincipal using default OriginAttributes. Though we might want > to audit the callers to see if we should pass in a non-default > OriginAttribute. > > Probably good to get Huseby to look at these patches since he's audited a > lot of createCodebasePrincipal callers to see if they need to use > non-default OriginAttributes.
Comment on attachment 8758781 [details] [diff] [review] Proposed fix. Looks good to me r/a=me
Attachment #8758781 - Flags: review?(iann_bugzilla) → review+
Sigh. More bitrot Bug 1233899 (fix the feeds converter to use default user context origin attributes)
Status: ASSIGNED → RESOLVED
Closed: 3 years ago
Resolution: --- → FIXED
Target Milestone: --- → seamonkey2.47
Comment on attachment 8758781 [details] [diff] [review] Proposed fix. [Triage Comment] a=me for c-r, make sure it goes onto the correct branch (SEA_COMM490_20160927_RELBRANCH I think)
Attachment #8758781 - Flags: approval-comm-release+
You need to log in before you can comment on or make changes to this bug.