Closed
Bug 1492754
Opened 7 years ago
Closed 7 years ago
Security testing for enhancements to Privacy Panel, Cookie Restrictions, and FastBlock
Categories
(Firefox Graveyard :: Security: Review Requests, enhancement, P1)
Firefox Graveyard
Security: Review Requests
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: pauljt, Assigned: arroway)
References
Details
(Whiteboard: testing)
These are three seperate features, so we might be three seperate bugs, but one will do for now while we figure out what needs testing.
Updated•7 years ago
|
Priority: -- → P1
| Reporter | ||
Updated•7 years ago
|
Assignee: nobody → stephouillon
| Assignee | ||
Comment 2•7 years ago
|
||
FastBlock is being delayed, so is out of scope for this testing.
Meta bug for cookie restrictions is bug 1473978
Meta bug for changes of the Privacy Panel is bug 1461743
| Reporter | ||
Comment 3•7 years ago
|
||
Steph - is there any security testing to do here? Looking at the privacy panel, we are just adding some changes to privacy settings in about:preferences. I assume QA will cover off that the feature works as intended.
However for cookie restrictions, I see bugs like bug 1231543, which relates to tracking protection not working on data URIs. Maybe we could perform some testing of edge cases to ensure that cookie restrictions behave as intended. Maybe even develop some kinda of automated/semi-automated tests for this. I'll send an email to folks to see if this would be worthwhile.
| Reporter | ||
Comment 4•7 years ago
|
||
Actually I'll let you email Steph, since it occurs to me that maybe you already asked the question. But basically I was going to email Ehsan, Tanvi & Francois and ask them if they though it was worthwhile to invest time in performing security testing around various edge cases to check that cookie restrictions are working as intended. I was thinking of testing common sources of issues like, redirects, non-http URIs, web extension etc. It doesn't seem high risk to me, and I would think that for the most part automated tests would (should?) cover this, but the presence of bug 1231543 makes me wonder.
Flags: needinfo?(stephouillon)
| Assignee | ||
Updated•7 years ago
|
Status: NEW → RESOLVED
Closed: 7 years ago
Flags: needinfo?(stephouillon)
Resolution: --- → FIXED
Updated•6 years ago
|
Product: Firefox → Firefox Graveyard
You need to log in
before you can comment on or make changes to this bug.
Description
•