Closed Bug 1554622 Opened 5 years ago Closed 5 years ago

Disable right-click for manifest view

Categories

(DevTools :: Application Panel, defect, P3)

defect

Tracking

(Not tracked)

RESOLVED WONTFIX

People

(Reporter: ogasidlo, Unassigned)

References

(Blocks 1 open bug)

Details

(Whiteboard: foundation-work)

To minimise the security risk, we should disable right-click for the manifest view page so no content can be injected. Chrome does the same thing out of the same reasons.

Bugbug thinks this bug is a task, but please change it back in case of error.

Type: defect → task
Type: task → enhancement
Type: enhancement → defect

Why do you think it is a defect? Thanks

Flags: needinfo?(balbeza)

Hi :sylvestre, we discussed in our triage: this is a security issue once we implement https://bugzilla.mozilla.org/show_bug.cgi?id=1554620 (the bug this one depends on). If you'd rather us not to set it as a bug until that dependency is met, we can do that as well.

Flags: needinfo?(balbeza)

As our approach changed and we do not load the manifest by the panel, but it will be served by platform we do not need to take security measures and can close this bug.

Status: NEW → RESOLVED
Closed: 5 years ago
Resolution: --- → WONTFIX
You need to log in before you can comment on or make changes to this bug.