Closed Bug 1497195 Opened 6 years ago Closed 5 years ago

Apply Meta CSP to about:crashes

Categories

(Core :: DOM: Security, enhancement, P3)

enhancement

Tracking

()

RESOLVED FIXED
mozilla69
Tracking Status
firefox69 --- fixed

People

(Reporter: ckerschb, Assigned: ckerschb)

References

Details

(Whiteboard: [domsecurity-backlog1])

Attachments

(3 files)

      No description provided.
Assignee: nobody → ckerschb
Status: NEW → ASSIGNED
Attachment #9016269 - Flags: review?(gijskruitbosch+bugs)
Attachment #9016269 - Flags: review?(gijskruitbosch+bugs) → review+
(this can't land until bug 965637 lands, but x-ref'ing in bug 1469520 so we can update that if/when this lands)
See Also: → 1469520

There's a r+ patch which didn't land and no activity in this bug for 2 weeks.
:ckerschb, could you have a look please?

Flags: needinfo?(ckerschb)

Before we can apply CSP to system privileged about pages we have to fix Bug 965637, in which we move the CSP from the Principal into the Client. Please note that the Meta Bug 1492063 for applying CSP to system privileged about: pages is blocked by 965637. At the moment we are fixing the last remaining blockers and as soon as we have landed Bug 965637 I'll try to land all the dependencies of Bug 1492063 so we end up having all about: pages secured by a CSP.

Flags: needinfo?(ckerschb)
Status: ASSIGNED → RESOLVED
Closed: 5 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla69

(In reply to Pulsebot from comment #10)

Pushed by mozilla@christophkerschbaumer.com:
https://hg.mozilla.org/integration/autoland/rev/80e58bbe2e88
Apply Meta CSP to about:networking.

Ah boy - this patch has the wrong bug number, it should be Bug 1497201.

Aryx, anything we can do about that or do we have to back it out and land again with the right bug number?

Flags: needinfo?(aryx.bugmail)

Backed out patch which landed with wrong bug number (and relanded it with bug 1497201): https://hg.mozilla.org/integration/autoland/rev/fa2384f76e274d7ce77039d0d2ff68905e03cf5c

Flags: needinfo?(aryx.bugmail)
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: