Open Bug 1535209 Opened 6 years ago Updated 3 years ago

Verify info.plist app transport security setting is correct for iOS 11+

Categories

(Firefox for iOS :: General, enhancement, P3)

Other
iOS
enhancement

Tracking

()

Tracking Status
fxios + ---

People

(Reporter: garvan, Unassigned)

Details

Firefox iOS has app transport security disabled in Client/info.plist, but I believe there are new ATS settings available, and we should review them:
https://www.nowsecure.com/blog/2017/08/31/security-analysts-guide-nsapptransportsecurity-nsallowsarbitraryloads-app-transport-security-ats-exceptions/

Perhaps we should have our ATS setting as NSAllowsArbitraryLoadsInWebContent

Priority: -- → P3
Severity: normal → S3
You need to log in before you can comment on or make changes to this bug.