Closed
Bug 1465602
Opened 6 years ago
Closed 6 years ago
Exposure checks in toJSON implementations aren't quite right
Categories
(Core :: DOM: Bindings (WebIDL), enhancement)
Core
DOM: Bindings (WebIDL)
Tracking
()
RESOLVED
FIXED
mozilla62
Tracking | Status | |
---|---|---|
firefox62 | --- | fixed |
People
(Reporter: bzbarsky, Assigned: bzbarsky)
References
Details
Attachments
(2 files, 1 obsolete file)
3.33 KB,
patch
|
qdot
:
review+
|
Details | Diff | Splinter Review |
11.88 KB,
patch
|
qdot
:
review+
|
Details | Diff | Splinter Review |
They pass the "this" value of the toJSON call to Prefable::isEnabled. That's wrong when that value is a cross-compartment wrapper, especially an Xray. We should be passing the unwrapped version instead.
Assignee | ||
Updated•6 years ago
|
Assignee: nobody → bzbarsky
Assignee | ||
Updated•6 years ago
|
Flags: needinfo?(bzbarsky)
Assignee | ||
Comment 1•6 years ago
|
||
I will write a patch for this in a bit. I need to write a bunch of tests first.
Assignee | ||
Comment 2•6 years ago
|
||
The spec says:
The return type of the default toJSON operation must be object.
Attachment #8982116 -
Flags: review?(kyle)
Assignee | ||
Comment 3•6 years ago
|
||
Attachment #8982117 -
Flags: review?(kyle)
Assignee | ||
Updated•6 years ago
|
Flags: needinfo?(bzbarsky)
Assignee | ||
Comment 4•6 years ago
|
||
Attachment #8982214 -
Flags: review?(kyle)
Assignee | ||
Updated•6 years ago
|
Attachment #8982117 -
Attachment is obsolete: true
Attachment #8982117 -
Flags: review?(kyle)
Updated•6 years ago
|
Attachment #8982116 -
Flags: review?(kyle) → review+
Updated•6 years ago
|
Attachment #8982214 -
Flags: review?(kyle) → review+
Assignee | ||
Updated•6 years ago
|
Component: DOM → DOM: Bindings (WebIDL)
Pushed by bzbarsky@mozilla.com:
https://hg.mozilla.org/integration/mozilla-inbound/rev/916e5914d84a
part 1. Enforce that the default toJSON can only return 'object'. r=qdot
https://hg.mozilla.org/integration/mozilla-inbound/rev/7c76daa75842
part 2. Fix the interaction of default toJSON with Func-controlled exposure that examines the object's global. r=qdot
Comment 6•6 years ago
|
||
bugherder |
https://hg.mozilla.org/mozilla-central/rev/916e5914d84a
https://hg.mozilla.org/mozilla-central/rev/7c76daa75842
Status: NEW → RESOLVED
Closed: 6 years ago
status-firefox62:
--- → fixed
Resolution: --- → FIXED
Target Milestone: --- → mozilla62
You need to log in
before you can comment on or make changes to this bug.
Description
•