Closed Bug 1568916 Opened 3 years ago Closed 2 years ago

Enterprise-only policies could be disabled by the user

Categories

(Firefox :: Enterprise Policies, defect, P5)

defect

Tracking

()

RESOLVED FIXED
Firefox 78
Tracking Status
firefox78 --- fixed

People

(Reporter: bytesized, Assigned: mkaply)

Details

Attachments

(1 file)

Given that, at the moment, the only enterprise-only policy is for setting search engines, perhaps this is not too big of a deal. But I was noticing when looking through the codebase, that a user could prevent the application of enterprise-only policies by setting the browser.policies.testing.disallowEnterprise pref.

If they were disallowed access to about:config, they could still set the policy in their pref file directly.

Thanks for catching this. I wish we could do away with these.

We should at least make the pref test only.

Priority: -- → P5
Assignee: nobody → mozilla
Status: NEW → ASSIGNED
Pushed by mozilla@kaply.com:
https://hg.mozilla.org/integration/autoland/rev/98097ed0a9a5
Only allow disabling of ESR policy in test. r=bytesized
Status: ASSIGNED → RESOLVED
Closed: 2 years ago
Resolution: --- → FIXED
Target Milestone: --- → Firefox 78
QA Whiteboard: [qa-78b-p2]
You need to log in before you can comment on or make changes to this bug.