Open Bug 1571346 Opened 5 years ago Updated 2 years ago

Remove 'unsafe-inline' from style-src within about:addons

Categories

(Toolkit :: Add-ons Manager, task, P3)

task

Tracking

()

People

(Reporter: ckerschb, Unassigned)

References

Details

Attachments

(1 obsolete file)

Within Bug 1497189 we are adding a CSP to about:addons. Most importantly is to block any inline script that runs but as a follow up we should also eliminate all usages of inline styles. After the removals of inline styles, e.g:

we should be able to remove 'unsafe-inline' from style-src for about:addons.

Priority: -- → P3

It seems the originally problematic code is no longer existing.

Assignee: nobody → fbraun
Status: NEW → ASSIGNED
Attachment #9248592 - Attachment is obsolete: true

Looks like there are still some files that are a bit harder to nail down. The reporting just says "chrome" without further URL info. Meh.

Assignee: fbraun → nobody
Status: ASSIGNED → NEW
Severity: normal → S3
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: