Align X-Frame-Options processing with the spec/WebKit/Blink
Categories
(Core :: DOM: Security, defect, P3)
Tracking
()
Tracking | Status | |
---|---|---|
firefox116 | --- | fixed |
People
(Reporter: d, Assigned: jewilde)
References
Details
(Keywords: sec-want, Whiteboard: [domsecurity-backlog1] [adv-main116-])
Attachments
(1 file)
In https://github.com/whatwg/html/pull/5737 we finally specified X-Frame-Options. https://github.com/web-platform-tests/wpt/pull/24618 greatly expanded the tests.
Browsers mostly agree on the behavior of the header. However, Gecko disagrees with the spec/WebKit/Blink in the case of conflicting header values, e.g. DENY,SAMEORIGIN
. In particular the failures are in https://github.com/web-platform-tests/wpt/blob/master/x-frame-options/multiple.html .
The full spec processing model is at https://html.spec.whatwg.org/#the-x-frame-options-header .
Updated•4 years ago
|
Updated•4 years ago
|
Assignee | ||
Updated•1 year ago
|
Assignee | ||
Comment 1•1 year ago
|
||
Pushed by jewilde@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/3fc04d8eb32b Fix failing x-frame-options web platform tests; r=freddyb,necko-reviewers,valentin
Comment 3•11 months ago
|
||
bugherder |
Comment 4•11 months ago
|
||
Backed out for causing crashes with signature [@ mozilla::dom::CanonicalBrowsingContext::Cast]
, e.g. bp-cae7174b-1e32-4748-95f4-f9f9f0230615.
Backout link: https://hg.mozilla.org/mozilla-central/rev/e8bfcd70e6ba5c6b9a6cc94e1a61b46d3f8949f8
Comment 5•11 months ago
|
||
The bug is linked to a topcrash signature, which matches the following criteria:
- Top 10 desktop browser crashes on nightly
- Top 10 AArch64 and ARM crashes on nightly
:jewilde, could you consider increasing the severity of this top-crash bug?
For more information, please visit BugBot documentation.
Comment 6•11 months ago
|
||
Can't be a topcrash if it's backed out...
Assignee | ||
Updated•11 months ago
|
Pushed by jewilde@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/522cce1d0166 Fix failing x-frame-options web platform tests; r=freddyb,necko-reviewers,valentin
Comment 8•11 months ago
|
||
bugherder |
Updated•10 months ago
|
Description
•