Closed Bug 1329065 Opened 4 years ago Closed 4 years ago

Leak referrer information if the referrer policy is set to UnSet

Categories

(Core :: DOM: Security, defect)

defect
Not set
normal

Tracking

()

RESOLVED FIXED
mozilla53
Tracking Status
firefox53 --- fixed

People

(Reporter: tnguyen, Assigned: tnguyen)

References

Details

Attachments

(1 file, 1 obsolete file)

Follow Bug 1304623 comment 36, if the referrer policy is set to unset, it passed all the checks and leak unsafe referrer information.
Blocks: 1304623
MozReview-Commit-ID: JG5DVBqGczS
Assignee: nobody → tnguyen
Status: NEW → ASSIGNED
MozReview-Commit-ID: JG5DVBqGczS
Attachment #8824310 - Attachment is obsolete: true
Comment on attachment 8824311 [details] [diff] [review]
Check the correct policy when setting referrer header

Hi Patrick
I have to change the flow of set referrer policy and add some missing tests for the case Unset.
Could you please take a look?
Attachment #8824311 - Flags: review?(mcmanus)
Attachment #8824311 - Flags: review?(mcmanus) → review+
Keywords: checkin-needed
Pushed by ryanvm@gmail.com:
https://hg.mozilla.org/integration/mozilla-inbound/rev/9835378fead4
Check the correct policy when setting referrer header. r=mcmanus
Keywords: checkin-needed
https://hg.mozilla.org/mozilla-central/rev/9835378fead4
Status: ASSIGNED → RESOLVED
Closed: 4 years ago
Flags: in-testsuite+
Resolution: --- → FIXED
Target Milestone: --- → mozilla53
You need to log in before you can comment on or make changes to this bug.