Closed Bug 1579373 Opened 6 years ago Closed 6 years ago

Disabling geolocation permissions by default in cross-origin iframes

Categories

(Core :: DOM: Geolocation, enhancement)

enhancement
Not set
normal

Tracking

()

RESOLVED FIXED
mozilla71
Tracking Status
firefox71 --- fixed

People

(Reporter: tnguyen, Assigned: tnguyen)

References

(Blocks 1 open bug)

Details

Attachments

(1 file)

The new model relationship between Feature policy and permission depends on disabling permissions by default in cross-origin iframes. That change will require websites to explicitly allow permissions for cross-origin iframes, otherwise those iframes will have permission requests denied
I am going to fix Geolocation permission denied by default here.

Pushed by tnguyen@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/a396b80f331f Disabled geolocation permission for crossorigin iframe by default and add tests r=baku
Status: NEW → RESOLVED
Closed: 6 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla71
Assignee: nobody → tnguyen
Regressions: 1580183
Regressions: 1580074

:tnguyen, this test is failing when fission is enabled (bug 1580074). Could you please look into this so we can enable it for Fission?

Flags: needinfo?(tnguyen)

I still don't know the reason why Feature Policy does not work in a new process of cross origin iframe, but I will take a look. I file a bug for that, bug 1580462

Flags: needinfo?(tnguyen)

This bug was discussed today at TPAC 2019 at the Devices & Sensors WG, tracking issue: https://github.com/w3c/geolocation-api/issues/10

You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: