Whitelist what's new "moments" pages
Categories
(Firefox :: Messaging System, enhancement, P1)
Tracking
()
People
(Reporter: k88hudson, Assigned: Mardak)
References
Details
Attachments
(1 file)
47 bytes,
text/x-phabricator-request
|
RyanVM
:
approval-mozilla-beta+
|
Details | Review |
In Bug 1568692 we landed some code to trigger a moments page based on a pref value. We might want to consider whitelisting the domains that are allowed to be shown if we think that's necessary.
Comment 2•5 years ago
|
||
If its easy to whitelist mozilla.org, firefox.com etc. domains, I'd recommend just doing that. Alternatively, I suggest you ask for a security review meeting with Dan Veditz and team using the secreview@mozilla.com email address.
Assignee | ||
Comment 3•5 years ago
|
||
I'll have it allow https: mozilla.org and firefox.com base domains
Assignee | ||
Comment 4•5 years ago
|
||
Use URL to parse and eTLD to extract allowed domains
Pushed by elee@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/d95d741d5b75 Whitelist what's new "moments" pages r=k88hudson
Comment 6•5 years ago
|
||
bugherder |
Assignee | ||
Comment 7•5 years ago
|
||
Comment on attachment 9083866 [details]
Bug 1570062 - Whitelist what's new "moments" pages
Beta/Release Uplift Approval Request
- User impact if declined: Undesired urls could be shown at startup
- Is this code covered by automated tests?: Yes
- Has the fix been verified in Nightly?: No
- Needs manual test from QE?: Yes
- If yes, steps to reproduce: 1) create new string pref
browser.startup.homepage_override.once
set to{"url":"https://example.com/|https://www.mozilla.org/%LOCALE%/etc/firefox/retention/thank-you-a/"}
- restart firefox
- see both a thank you page (https://www.mozilla.org/en-US/etc/firefox/retention/thank-you-a/) and home page tabs but not https://example.com/
- List of other uplifts needed: Bug 1568692
- Risk to taking this patch: Low
- Why is the change risky/not risky? (and alternatives if risky): Slight modification to the behavior from bug 1568692 which is default off.
- String changes made/needed: none
Assignee | ||
Updated•5 years ago
|
Updated•5 years ago
|
Comment 8•5 years ago
|
||
Comment on attachment 9083866 [details]
Bug 1570062 - Whitelist what's new "moments" pages
Work in support of the approved relationship scoping projects targeting Fx69. Approved for 69.0b14.
Comment 9•5 years ago
|
||
bugherder uplift |
Updated•4 years ago
|
Description
•