Closed Bug 1725339 Opened 3 years ago Closed 3 years ago

Restrict systemprincipal from loading type *SUBDOCUMENT* via HTTP, HTTPS and (maybe) data.

Categories

(Core :: DOM: Security, task)

task

Tracking

()

RESOLVED FIXED
93 Branch
Tracking Status
firefox93 --- fixed

People

(Reporter: freddy, Assigned: freddy)

References

(Blocks 1 open bug)

Details

(Whiteboard: [2021-H2][domsecurity-active])

Attachments

(1 file)

This patch will add a pref to blocking type DOCUMENT with scheme HTTP/HTTPS and another pref for scheme DATA.

The http/https is green on try and I propose for landing, as it is early in the cycle.

I'm also adding a patch that enforces this for data URLs, but it's still running on try. This part will only won't land as enabled unless the try run isn't immediately green.

Status: NEW → ASSIGNED
Whiteboard: [2021-H2][domsecurity-active]
Attachment #9235920 - Attachment description: Bug 1725339 - Restrict systemprincipal from loading type *DOCUMENT* via HTTP, HTTPS and data schemes. r?ckerschb! → Bug 1725339 - Restrict systemprincipal from loading type *DOCUMENT* via HTTP, HTTPS and data schemes (data restriction preffed off). r?ckerschb!
Attachment #9235920 - Attachment description: Bug 1725339 - Restrict systemprincipal from loading type *DOCUMENT* via HTTP, HTTPS and data schemes (data restriction preffed off). r?ckerschb! → Bug 1725339 - Restrict systemprincipal from loading type *DOCUMENT* via HTTP, HTTPS and data schemes (data restriction preffed OFF). r?ckerschb!
Pushed by fbraun@mozilla.com:
https://hg.mozilla.org/integration/autoland/rev/ed0cca70a9a5
Restrict systemprincipal from loading type *DOCUMENT* via HTTP, HTTPS and data schemes (data restriction preffed OFF). r=ckerschb

Backed out changeset ed0cca70a9a5 (Bug 1725339) for causing failures on nsContentSecurityManager.
Backout link
Push with failures
Failure Log
Multiple failures found - Failure Log and Failure Log

Flags: needinfo?(fbraun)
Attachment #9235920 - Attachment description: Bug 1725339 - Restrict systemprincipal from loading type *DOCUMENT* via HTTP, HTTPS and data schemes (data restriction preffed OFF). r?ckerschb! → Bug 1725339 - Restrict systemprincipal from loading type *SUBDOCUMENT* via HTTP, HTTPS and data schemes (data restriction preffed OFF). r?ckerschb!

Changed approach, as discussed in meeting with ckerschb.

Flags: needinfo?(fbraun)
Summary: Restrict systemprincipal from loading type *DOCUMENT* via HTTP, HTTPS and (maybe) data. → Restrict systemprincipal from loading type *SUBDOCUMENT* via HTTP, HTTPS and (maybe) data.
Pushed by fbraun@mozilla.com:
https://hg.mozilla.org/integration/autoland/rev/38f039da1eb9
Restrict systemprincipal from loading type *SUBDOCUMENT* via HTTP, HTTPS and data schemes (data restriction preffed OFF). r=ckerschb
Status: ASSIGNED → RESOLVED
Closed: 3 years ago
Resolution: --- → FIXED
Target Milestone: --- → 93 Branch
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: