Closed Bug 1612061 Opened 5 years ago Closed 4 years ago

Audit DocumentChannel for cross-origin network leaks we can avoid

Categories

(Core :: Networking, task, P3)

task

Tracking

()

RESOLVED FIXED
Fission Milestone M8

People

(Reporter: tjr, Assigned: tjr)

References

(Blocks 2 open bugs)

Details

(Keywords: sec-audit, Whiteboard: [necko-triaged][sp3])

After DocumentChannel completes and removes itself in favor of a real channel (HttpChannelChild probably), there may be data accessible from that real channel that we don't need to expose to the content process. (e.g. referer, original uri)

Priority: -- → P3
Whiteboard: [necko-triaged]

Does this DocumentChannel bug need to block shipping Fission MVP?

Fission Milestone: --- → ?

We should do this sometime in M7 but should not block Nightly

Fission Milestone: ? → M7

Tom, will you be doing this code audit?

Flags: needinfo?(tom)

This doesn't necessarily block Fission MVP but we can revisit this later to prioritize appropriately.

Fission Milestone: M7 → MVP
Assignee: nobody → tom
Status: NEW → ASSIGNED
Fission Milestone: MVP → M8
Depends on: 1713203
Blocks: 1707955
Flags: needinfo?(tom)
Depends on: 1715785

At this point I think we can consider this done.

Status: ASSIGNED → RESOLVED
Closed: 4 years ago
Resolution: --- → FIXED
Whiteboard: [necko-triaged] → [necko-triaged][sp3]
You need to log in before you can comment on or make changes to this bug.