Closed Bug 1555043 Opened 6 years ago Closed 5 years ago

Sort out interaction of CSP and javascript: URLs

Categories

(Core :: DOM: Security, defect, P1)

defect

Tracking

()

RESOLVED FIXED
mozilla70
Tracking Status
firefox-esr60 --- unaffected
firefox67 --- unaffected
firefox68 --- unaffected
firefox69 + unaffected
firefox70 --- fixed

People

(Reporter: bzbarsky, Assigned: ckerschb)

References

(Regression)

Details

(Keywords: regression, Whiteboard: [domsecurity-active])

Attachments

(1 file)

[Tracking Requested - why for this release]: Web-observable behavior change that we apparently didn't mean to make.

See https://github.com/whatwg/html/issues/4651

In particular, we changed our behavior here in bug 965637, which I am told was not purposeful. We need to decide whether we actually want that behavior change before we ship it accidentally.

Blocks: 1550414
Status: NEW → ASSIGNED
Priority: -- → P1
Whiteboard: [domsecurity-active]

Is this being worked on for 69?

Flags: needinfo?(ckerschb)

(In reply to Kate Hudson :k88hudson from comment #1)

Is this being worked on for 69?

I am trying, yes.

Flags: needinfo?(ckerschb)
Blocks: 1567058
Blocks: 1567059

The web-visible change from bug 965637 was reverted in bug 1478037. So there's no need to track this anymore.

(In reply to Boris Zbarsky [:bzbarsky, bz on IRC] from comment #4)

The web-visible change from bug 965637 was reverted in bug 1478037. So there's no need to track this anymore.

In turn, this makes this bug a task. Thanks for your help here Boris.

Type: defect → task
Pushed by mozilla@christophkerschbaumer.com: https://hg.mozilla.org/integration/autoland/rev/880fa3109604 Perform CSP check against target document's CSP for javascript: URIs. r=bzbarsky
Type: task → defect
Status: ASSIGNED → RESOLVED
Closed: 5 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla70
See Also: → CVE-2019-17001
Has Regression Range: --- → yes
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: