Closed Bug 1497202 Opened 2 years ago Closed 1 year ago

Apply Meta CSP to about:performance

Categories

(Core :: DOM: Security, enhancement, P3)

enhancement

Tracking

()

RESOLVED FIXED
mozilla69
Tracking Status
firefox69 --- fixed

People

(Reporter: ckerschb, Assigned: ckerschb)

References

Details

(Whiteboard: [domsecurity-backlog1])

Attachments

(2 files)

No description provided.
Assignee: nobody → ckerschb
Status: NEW → ASSIGNED
Attachment #9016272 - Flags: review?(gijskruitbosch+bugs)
Comment on attachment 9016272 [details] [diff] [review]
bug_1497202_csp_about_performance.patch

Review of attachment 9016272 [details] [diff] [review]:
-----------------------------------------------------------------

A bunch of this stuff is in flux at the moment. Florian is probably a better reviewer here than me.
Attachment #9016272 - Flags: review?(gijskruitbosch+bugs) → review?(florian)
Comment on attachment 9016272 [details] [diff] [review]
bug_1497202_csp_about_performance.patch

Review of attachment 9016272 [details] [diff] [review]:
-----------------------------------------------------------------

Looks good to me, thanks. Please land sooner than later, as this will bitrot with the patch I'm preparing for bug 1498185 (I'll rebase it above your patch).
Attachment #9016272 - Flags: review?(florian) → review+
(In reply to Florian Quèze [:florian] from comment #3)
> Looks good to me, thanks. Please land sooner than later, as this will bitrot
> with the patch I'm preparing for bug 1498185 (I'll rebase it above your
> patch).

Thanks for the heads up, but this bug is still blocked by the overall re-architecture work in Bug 965637. Please just go ahead and land your things - I'll rebase this patch one un-blocked.

There's a r+ patch which didn't land and no activity in this bug for 2 weeks.
:ckerschb, could you have a look please?

Flags: needinfo?(ckerschb)

Before we can apply CSP to system privileged about pages we have to fix Bug 965637, in which we move the CSP from the Principal into the Client. Please note that the Meta Bug 1492063 for applying CSP to system privileged about: pages is blocked by 965637. At the moment we are fixing the last remaining blockers and as soon as we have landed Bug 965637 I'll try to land all the dependencies of Bug 1492063 so we end up having all about: pages secured by a CSP.

Flags: needinfo?(ckerschb)
Status: ASSIGNED → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla69
Regressions: 1561257
You need to log in before you can comment on or make changes to this bug.