Closed Bug 1684432 Opened 5 years ago Closed 5 years ago

Cross-origin resource sharing: arbitrary origin trusted

Categories

(Cloud Services :: Server: Firefox Accounts, defect)

Firefox 84
defect

Tracking

(Not tracked)

RESOLVED DUPLICATE of bug 1272248

People

(Reporter: kashyapvaghani7055, Assigned: jbuck)

Details

Attachments

(1 file)

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0

Steps to reproduce:

Create a new firefox account and log in with that account.

Actual results:

HTTP/1.1 200 OK
Server: openresty/1.15.8.2
Date: Tue, 29 Dec 2020 08:17:06 GMT
Content-Type: application/json
Content-Length: 296
vary: Origin
access-control-allow-origin: null
x-last-modified: 1609229826.00
x-weave-timestamp: 1609229826.00
Access-Control-Allow-Origin: null
Access-Control-Allow-Credentials: true
Access-Control-Allow-Methods: DELETE, GET, POST, PUT, OPTIONS
Access-Control-Max-Age: 1728000
Access-Control-Allow-Headers: DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Authorization,X-Conditions-Accepted
Via: 1.1 google
Alt-Svc: clear
Connection: close

{"modified":1609229826.00,"success":["{c628d5ff-d199-40b8-97a6-5deab241e82c}","{cf68476d-3d84-4849-abaa-72e2d147fbb5}","{43eb80ce-d90b-49ee-bdc9-5a1ebe8334f4}","{ab669e35-db75-4f35-a551-0d4c797a523e}","{ddf9586c-e443-4bb2-85c9-97a2d621a20d}","{d7b4efe6-b3f3-4ef5-a569-e6bb75b375c2}"],"failed":{}}

Expected results:

Rather than using a wildcard or programmatically verifying supplied origins, use a whitelist of trusted domains.

See https://bugzilla.mozilla.org/show_bug.cgi?id=1272248#c5 for an explanation of why this is OK.

Assignee: nobody → jbuckley
Group: firefox-core-security
Status: UNCONFIRMED → RESOLVED
Closed: 5 years ago
Component: Untriaged → Server: Firefox Accounts
Product: Firefox → Cloud Services
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: