Request a security review of Glean-iOS custom URL handling.
Categories
(Data Platform and Tools :: Glean: SDK, task, P1)
Tracking
(Not tracked)
People
(Reporter: travis_, Assigned: travis_)
References
Details
(Whiteboard: [telemetry:glean-rs:m12])
Glean is shipped with the capability to handle custom URL schemes for iOS in the release version of the library to help with QA and problem diagnosis. This mean that other applications could manually start this activity and this might be a potential security problem.
This bug is for discussing any potential issue with this feature and, if required, take the appropriate actions to mitigate risks.
This functionality is identical to the functionality that was reviewed in Bug 1532926, but due to platform differences, the implementation is entirely different, which is why we considered it good practice to request security review again.
Assignee | ||
Updated•5 years ago
|
Assignee | ||
Comment 1•5 years ago
|
||
Linking to the filled Security Review Request Form
Assignee | ||
Updated•5 years ago
|
Assignee | ||
Comment 2•5 years ago
|
||
Email to secreview@mozilla.com sent
Assignee | ||
Updated•5 years ago
|
Assignee | ||
Comment 3•5 years ago
|
||
I noticed I failed to add a link to secreview request form in the bug:
https://docs.google.com/document/d/1pNqWi50zQfdG5HAw0lA7rJIRYmLD_qYq2SUTXnk3-WQ/edit
Assignee | ||
Comment 4•5 years ago
|
||
Updated doc from security:
https://docs.google.com/document/d/1AST_TqCuqM-e3ydut7oEtt-EY-NoF-cq1KPxLD8RWEg/edit#
Closing as fixed with secreview+
Description
•