Closed Bug 1506839 Opened 2 years ago Closed 2 years ago

Implement document-domain featurePolicy

Categories

(Core :: DOM: Security, enhancement)

enhancement
Not set
normal

Tracking

()

RESOLVED FIXED
mozilla65
Tracking Status
firefox65 --- fixed

People

(Reporter: baku, Assigned: baku)

Details

(Keywords: dev-doc-complete, Whiteboard: [domsecurity-backlog1] [domsecurity-active])

Attachments

(1 file)

Status: NEW → ASSIGNED
Whiteboard: [domsecurity-backlog1] [domsecurity-active]
I don't want to write a WPT because it's already implemented here:

https://chromium-review.googlesource.com/c/chromium/src/+/1329791

Let me know if we want to send an intent-to-implement/ship email.
Attachment #9024780 - Flags: review?(ckerschb)
Attachment #9024780 - Flags: review?(annevk)
Comment on attachment 9024780 [details] [diff] [review]
document-domain.patch

Nit: in the standard this check is after the sandbox check. It doesn't matter now since it's the same exception, but if that ever changes it'd be observable. Doing this without intent to ship seems acceptable given how small and easy to remove it is if there are concerns.
Attachment #9024780 - Flags: review?(annevk) → review+
Comment on attachment 9024780 [details] [diff] [review]
document-domain.patch

Review of attachment 9024780 [details] [diff] [review]:
-----------------------------------------------------------------

Yeah, looks feasible to me - thanks!
Attachment #9024780 - Flags: review?(ckerschb) → review+
Pushed by amarchesini@mozilla.com:
https://hg.mozilla.org/integration/mozilla-inbound/rev/3e8db852399a
Implement document-domain feature policy, r=annevk, r=ckerschb
https://hg.mozilla.org/mozilla-central/rev/3e8db852399a
Status: ASSIGNED → RESOLVED
Closed: 2 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla65
Note to MDN writer's team:

IIRC, Feature-Policy is not enabled by default in any version of Firefox yet, so I'm not adding a note to the Fx65 rel notes about this. It could do with adding to the main Feature-Policy documentation however, if it is not there already.
> IIRC, Feature-Policy is not enabled by default in any version of Firefox

It's enabled in nightly. But yes, I agree about not adding a note to the Fx65 rel.
You need to log in before you can comment on or make changes to this bug.