Closed Bug 1547713 Opened 2 years ago Closed 2 years ago

Remove chrometask_chromescript from eval()-whitelist

Categories

(Core :: DOM: Security, enhancement, P3)

enhancement

Tracking

()

RESOLVED FIXED
mozilla68
Tracking Status
firefox68 --- fixed

People

(Reporter: jallmann, Assigned: jallmann)

References

(Blocks 1 open bug)

Details

(Whiteboard: [domsecurity-backlog1])

Attachments

(1 file)

This occurence of eval() in a file used only for testing (and only for a single test, as it seems) triggers our eval()-Assertion:

https://searchfox.org/mozilla-central/source/testing/mochitest/tests/SimpleTest/ChromeTask.js#62

Under the given circumstances, it seems easiest to flip the eval-exception pref for this case.

Flip pref to allow the use of eval() in this purely test-related case.

Keywords: checkin-needed

Pushed by nbeleuzu@mozilla.com:
https://hg.mozilla.org/integration/autoland/rev/45cb80d21409
Remove chrometask_chromescript from eval()-whitelist, r=ckerschb

Keywords: checkin-needed
Status: ASSIGNED → RESOLVED
Closed: 2 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla68
You need to log in before you can comment on or make changes to this bug.