Treat 'data:' documents as unique, opaque origins
Categories
(Core :: DOM: Security, defect, P1)
Tracking
()
Tracking | Status | |
---|---|---|
firefox57 | --- | fixed |
People
(Reporter: ckerschb, Assigned: ckerschb)
References
Details
(Keywords: addon-compat, dev-doc-complete, Whiteboard: [domsecurity-active])
Attachments
(1 file)
1.37 KB,
patch
|
smaug
:
review+
|
Details | Diff | Splinter Review |
Comment 1•8 years ago
|
||
Comment 2•8 years ago
|
||
Assignee | ||
Comment 3•8 years ago
|
||
Updated•8 years ago
|
Assignee | ||
Updated•8 years ago
|
Assignee | ||
Comment 4•8 years ago
|
||
![]() |
||
Comment 5•8 years ago
|
||
Comment 6•8 years ago
|
||
![]() |
||
Comment 7•8 years ago
|
||
![]() |
||
Comment 8•8 years ago
|
||
Updated•8 years ago
|
![]() |
||
Comment 12•8 years ago
|
||
![]() |
||
Comment 14•8 years ago
|
||
![]() |
||
Comment 15•8 years ago
|
||
Comment 16•8 years ago
|
||
![]() |
||
Comment 17•8 years ago
|
||
Comment 19•8 years ago
|
||
Comment 20•8 years ago
|
||
Assignee | ||
Comment 21•8 years ago
|
||
Assignee | ||
Comment 22•8 years ago
|
||
Assignee | ||
Comment 23•8 years ago
|
||
Assignee | ||
Updated•8 years ago
|
Assignee | ||
Comment 24•8 years ago
|
||
Assignee | ||
Comment 25•8 years ago
|
||
Assignee | ||
Comment 26•8 years ago
|
||
Assignee | ||
Comment 27•8 years ago
|
||
Assignee | ||
Comment 28•8 years ago
|
||
Assignee | ||
Comment 29•8 years ago
|
||
Assignee | ||
Updated•8 years ago
|
Comment 30•8 years ago
|
||
Comment 31•8 years ago
|
||
Comment 32•8 years ago
|
||
Assignee | ||
Comment 33•8 years ago
|
||
Comment 34•8 years ago
|
||
Assignee | ||
Comment 35•8 years ago
|
||
Comment 36•8 years ago
|
||
Assignee | ||
Comment 37•8 years ago
|
||
Updated•8 years ago
|
Assignee | ||
Comment 38•8 years ago
|
||
Assignee | ||
Comment 39•8 years ago
|
||
Comment 40•8 years ago
|
||
![]() |
||
Comment 41•8 years ago
|
||
Assignee | ||
Comment 42•8 years ago
|
||
Comment 43•8 years ago
|
||
Comment 44•8 years ago
|
||
bugherder |
Comment 45•8 years ago
|
||
Comment 46•8 years ago
|
||
Comment 48•8 years ago
|
||
Comment 49•8 years ago
|
||
Comment 52•4 years ago
|
||
Thus you broke XML-XSL-SVG applications that used a simple JS stub for processing internal requests into xml requests and put them directly to window.location
. And what is more important, those applications worked locally and via a web server using a web browser as an ordinary viewer for local files like Adobe Acrobat Reader. Please see the result of your interpretation of the same origin policy regarding data
protocol in the bug 1676008.
So, why don't just acknowledge that the idea of the same origin policy is completely wrong and just break required things instead of achieving its declared purposes? Why to follow wrong decisions making benefits just for corporations like Google that force users to migrate to their online infrastructure and stop using any local and independent data/applications? Security is useless when there is nothing to defend when security means made the target things impracticable.
Updated•2 years ago
|
Description
•