Open Bug 1493026 Opened 7 years ago Updated 3 years ago

Creates Full control DACL for Administrators, System, and current user on new downloads

Categories

(Toolkit :: Downloads API, defect, P5)

62 Branch
defect

Tracking

()

People

(Reporter: mb, Unassigned)

Details

Attachments

(1 file)

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36 Steps to reproduce: 1. Set inheritable permissions on a non-admin download folder to not grant execute access on any files in that folder. 2. Ran Firefox as that non-admin user. 2. Downloaded a file into download folder Actual results: The newly downloaded file has the expected inherited permissions plus three new Full control permissions for System, local administrators group, and current user. Expected results: File should only have inherited permissions, not created any new non-inherited ACLs.
Component: Untriaged → Widget: Win32
Product: Firefox → Core
I think this may be a Widget: Win32 issue due to having to change Win admin settings. Please correct if this is not the right component. Thanks.
The exact code is here: https://dxr.mozilla.org/mozilla-central/source/ipc/mscom/MainThreadRuntime.cpp#209 Note the comment: // Grant access to SYSTEM, Administrators, the user, and when running as the // browser process on Windows 8+, all app containers.
(In reply to mb from comment #2) > The exact code is here: > https://dxr.mozilla.org/mozilla-central/source/ipc/mscom/MainThreadRuntime. > cpp#209 > > Note the comment: > // Grant access to SYSTEM, Administrators, the user, and when running as > the > // browser process on Windows 8+, all app containers. That code is specifically for the DACL applied to incoming COM execution requests. That should not be applied directly to downloaded files.
Component: Widget: Win32 → Downloads API
Product: Core → Toolkit
Status: UNCONFIRMED → NEW
Ever confirmed: true
Priority: -- → P5
Severity: normal → S3
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: