Whitelist what's new "moments" pages
Categories
(Firefox :: Messaging System, enhancement, P1)
Tracking
()
People
(Reporter: k88hudson, Assigned: Mardak)
References
Details
Attachments
(1 file)
|
47 bytes,
text/x-phabricator-request
|
RyanVM
:
approval-mozilla-beta+
|
Details | Review |
In Bug 1568692 we landed some code to trigger a moments page based on a pref value. We might want to consider whitelisting the domains that are allowed to be shown if we think that's necessary.
Comment 2•6 years ago
|
||
If its easy to whitelist mozilla.org, firefox.com etc. domains, I'd recommend just doing that. Alternatively, I suggest you ask for a security review meeting with Dan Veditz and team using the secreview@mozilla.com email address.
| Assignee | ||
Comment 3•6 years ago
|
||
I'll have it allow https: mozilla.org and firefox.com base domains
| Assignee | ||
Comment 4•6 years ago
|
||
Use URL to parse and eTLD to extract allowed domains
Comment 6•6 years ago
|
||
| bugherder | ||
| Assignee | ||
Comment 7•6 years ago
|
||
Comment on attachment 9083866 [details]
Bug 1570062 - Whitelist what's new "moments" pages
Beta/Release Uplift Approval Request
- User impact if declined: Undesired urls could be shown at startup
- Is this code covered by automated tests?: Yes
- Has the fix been verified in Nightly?: No
- Needs manual test from QE?: Yes
- If yes, steps to reproduce: 1) create new string pref
browser.startup.homepage_override.onceset to{"url":"https://example.com/|https://www.mozilla.org/%LOCALE%/etc/firefox/retention/thank-you-a/"}
- restart firefox
- see both a thank you page (https://www.mozilla.org/en-US/etc/firefox/retention/thank-you-a/) and home page tabs but not https://example.com/
- List of other uplifts needed: Bug 1568692
- Risk to taking this patch: Low
- Why is the change risky/not risky? (and alternatives if risky): Slight modification to the behavior from bug 1568692 which is default off.
- String changes made/needed: none
| Assignee | ||
Updated•6 years ago
|
Updated•6 years ago
|
Comment 8•6 years ago
|
||
Comment on attachment 9083866 [details]
Bug 1570062 - Whitelist what's new "moments" pages
Work in support of the approved relationship scoping projects targeting Fx69. Approved for 69.0b14.
Comment 9•6 years ago
|
||
| bugherder uplift | ||
Updated•5 years ago
|
Description
•