X-Frame-Options header incorrect for attachments
Categories
(developer.mozilla.org :: Security, defect)
Tracking
(Not tracked)
People
(Reporter: jwhitlock, Unassigned)
References
Details
(Keywords: in-triage, Whiteboard: [specification][type:bug])
Comment 1•9 years ago
|
||
Reporter | ||
Comment 2•9 years ago
|
||
Comment 3•9 years ago
|
||
Comment 4•9 years ago
|
||
Reporter | ||
Updated•9 years ago
|
Reporter | ||
Comment 5•9 years ago
|
||
Comment 6•9 years ago
|
||
Comment 7•9 years ago
|
||
Comment 8•9 years ago
|
||
Comment 9•9 years ago
|
||
Comment 10•9 years ago
|
||
Updated•9 years ago
|
Reporter | ||
Comment 11•9 years ago
|
||
Comment 12•6 years ago
|
||
I'm going to boldly resolve this. https://github.com/mozilla/kuma/commit/eb14ae1342a05bb1b78a40e6dcd01462e52b7ac4
solved the "immediate" problem. 3 years ago.
It was during investigating this we discovered (Hi April!) that we should pivot and instead invest in CSP and if/when doing so we should do it all properly. That's what https://bugzilla.mozilla.org/show_bug.cgi?id=948151 is all about.
The day we tackle https://bugzilla.mozilla.org/show_bug.cgi?id=948151 we must make a mental note to check that iframes work correctly but it feels quite fundamental anyway so it just "should get done".
Also, to say that this blocks #948151 isn't right. Same can be said about https://bugzilla.mozilla.org/show_bug.cgi?id=1287621.
(at the moment, not sure what the difference is between these two bugs)
This bug (about attachments) would most likely automatically resolve itself once CSP is working properly. We'll get there.
Updated•6 years ago
|
Description
•