Web pages can add themselves to the "Top Sites" on your New Tab page by abusing window.history
Categories
(Toolkit :: Places, defect, P2)
Tracking
()
People
(Reporter: andrewm.bpi, Unassigned)
References
(Depends on 1 open bug)
Details
(Keywords: csectype-dos, csectype-spoof, sec-low, Whiteboard: [fxsearch][fixed by 1913000, 1915404][adv-main135-])
Updated•7 years ago
|
Comment 1•7 years ago
|
||
Comment 2•7 years ago
|
||
Comment 3•7 years ago
|
||
Comment 4•7 years ago
|
||
Comment 5•7 years ago
|
||
Comment 6•7 years ago
|
||
Updated•7 years ago
|
Updated•4 years ago
|
Updated•3 years ago
|
Comment 8•11 months ago
•
|
||
There is now a protection on session history api, that will fail with "Too many calls to Location or History APIs within a short timeframe.", plus Bug 1891145 implemented an additional protection in global history, though it won't ever be perfect, as the risk of dropping real visits is high if we act too strictly.
The bug as-is is no longer reproducible for me.
Let's continue tracking Bug 661590 for further improvements on the history flooding matter.
Comment 9•11 months ago
|
||
(In reply to Marco Bonardo [:mak] from comment #8)
There is now a protection on session history api, that will fail with "Too many calls to Location or History APIs within a short timeframe."
It looks like you must mean bug 1913000, which was shipped in Firefox 132?
The other one you mention, bug 1891145, is shipping in Firefox 135 via bug 1915404
Updated•11 months ago
|
Updated•11 months ago
|
Comment 10•11 months ago
|
||
(In reply to Daniel Veditz [:dveditz] from comment #9)
It looks like you must mean bug 1913000, which was shipped in Firefox 132?
The other one you mention, bug 1891145, is shipping in Firefox 135 via bug 1915404
yes, that's right.
Updated•7 months ago
|
Description
•