Closed Bug 1725390 Opened 4 years ago Closed 7 months ago

Ensure https-first handles downloads correctly

Categories

(Core :: DOM: Security, task, P1)

task

Tracking

()

RESOLVED FIXED
Tracking Status
firefox-esr102 --- affected
firefox110 --- affected
firefox111 --- affected

People

(Reporter: ckerschb, Assigned: simonf)

References

(Blocks 1 open bug)

Details

(Whiteboard: [domsecurity-active])

Attachments

(1 file)

Downloads are treated as TYPE_DOCUMENT which means that https-first tries to upgrade those. What happens if the download is not available over https?

We should write an automated test and investigate how we can handle that.

Flags: needinfo?(ckerschb)
Flags: needinfo?(ckerschb)
Depends on: 1745146
Depends on: 1745186
Depends on: 1745650
Depends on: 1739113
Depends on: 1746173
Depends on: 1749953
No longer depends on: 1739113
Duplicate of this bug: 1802640
Assignee: t.yavor → nobody
Status: ASSIGNED → NEW
Severity: S4 → S3

We should make sure this is in our HTTPS-First release.

Severity: S3 → S2
No longer blocks: https-first-release
Assignee: nobody → sfriedberger
Status: NEW → ASSIGNED
Status: ASSIGNED → RESOLVED
Closed: 7 months ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: