Closed Bug 1412561 Opened 2 years ago Closed 4 months ago

Add-on installation should be blocked when in full-screen mode

Categories

(Toolkit :: Add-ons Manager, enhancement, P2)

56 Branch
enhancement

Tracking

()

RESOLVED FIXED
mozilla68
Tracking Status
firefox57 --- wontfix
firefox68 --- fixed

People

(Reporter: andreasjunghw, Assigned: pbz)

References

(Blocks 2 open bugs)

Details

Attachments

(1 file)

The page mentioned in bug 1412559 (if it sometimes decides not to make the browser instantly unusable / locked up) switches the browser into fullscreen mode and then pops up the add-on installation doorhanger notification.[1]

Allowing the add-on installation doorhanger notification to appear in fullscreen mode is bad for two reasons:
- It is possibly easier for a malicious website to try to trick the user by showing fake browser or operating system UI
- It is much more intimidating so the user is more likely to allow the installation.

I think an attempt to install add-ons should (silently?) fail when in fullscreen mode. I can't see any reason why a legitimate website would require to initiate add-on installation in full-screen mode.

(The .xpi the page attempts to install should probably be blacklisted if this isn't the case already. I have no idea how / where to report this.)

[1] This is probably the wrong name: It's not asking "Do you want to install the following add-on" but the "Firefox prevented the site from asking you to install an add-on" message, but that's not much better as it's just one more click.
Component: General → Add-ons Manager
Product: Firefox → Toolkit
Agreed, I think we should prevent installation because it's no longer clear this isn't content creating those popups.

Could you please file a bug in Bugzilla under Toolkit > Blocklisting outlining why you think the add-on should be blocked.
Flags: needinfo?(andreasjunghw)
Priority: -- → P2
See Also: → 1413665
(In reply to Andy McKay [:andym] from comment #1)
> Agreed, I think we should prevent installation because it's no longer clear
> this isn't content creating those popups.
> 
> Could you please file a bug in Bugzilla under Toolkit > Blocklisting
> outlining why you think the add-on should be blocked.

Filed Bug 1413665.
Flags: needinfo?(andreasjunghw)
Duplicate of this bug: 1476550
Blocks: eviltraps
Status: UNCONFIRMED → NEW
Ever confirmed: true
Assignee: nobody → pzuhlcke
Attachment #9058654 - Flags: checkin+
Keywords: checkin-needed
Attachment #9058654 - Flags: checkin+

We should send out a short notice about this to dev-addons once the current storm has calmed.

Pushed by csabou@mozilla.com:
https://hg.mozilla.org/integration/autoland/rev/2268e6a9359e
Block addon installation prompts in fullscreen mode. r=johannh,aswan

Keywords: checkin-needed
Status: NEW → RESOLVED
Closed: 4 months ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla68
Blocks: 1558439
You need to log in before you can comment on or make changes to this bug.