Remove new Function from autocomplete.xml

ASSIGNED
Assigned to

Status

()

enhancement
P3
normal
ASSIGNED
6 months ago
29 days ago

People

(Reporter: vinoth, Assigned: jallmann)

Tracking

(Blocks 1 bug)

Firefox Tracking Flags

(Not tracked)

Details

(Whiteboard: [domsecurity-backlog1])

(Reporter)

Description

6 months ago
Eval(), new Function() should never execute with system principal.It is being removed everywhere from our codebase as part of Bug 1473549.

The affected code which should be rewritten,
https://dxr.mozilla.org/mozilla-central/rev/c291143e24019097d087f9307e59b49facaf90cb/toolkit/content/widgets/autocomplete.xml#415
(Reporter)

Updated

6 months ago
Component: Autocomplete → DOM: Security
Product: Toolkit → Core
Whiteboard: [domsecurity-backlog1]
(Assignee)

Updated

29 days ago
Assignee: nobody → jallmann
Status: NEW → ASSIGNED
You need to log in before you can comment on or make changes to this bug.