Closed Bug 1604058 Opened 1 year ago Closed 1 year ago

Verify IPC messages claiming to come from extension pages

Categories

(WebExtensions :: General, enhancement, P1)

enhancement

Tracking

(firefox73 fixed)

RESOLVED FIXED
mozilla73
Tracking Status
firefox73 --- fixed

People

(Reporter: zombie, Assigned: zombie)

References

(Blocks 1 open bug, Regressed 2 open bugs)

Details

Attachments

(1 file)

Soon most of our IPC will be going throw a few well defined points in code, so we can more easily verify and enforce checks about which messages coming from the child we can trust.

Pushed by tjovanovic@mozilla.com:
https://hg.mozilla.org/integration/autoland/rev/ed6c8bbe42f7
Verify remote conduits coming from extension pages r=robwu,rpl
Status: NEW → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla73
Regressions: 1605544

Hello,

Will this require manual validation? If yes, please provide some steps to reproduce in order to correctly test it and also, please set the "qe-verify+" flag. Otherwise, could the "qe-verify-" flag be added? Thanks!

Flags: needinfo?(tomica)

This has an automatic test, thanks.

Flags: needinfo?(tomica) → qe-verify-
Regressions: 1607859
Regressions: 1641577
Regressions: 1652925
You need to log in before you can comment on or make changes to this bug.