Closed Bug 1768279 Opened 2 years ago Closed 2 years ago

[wpt-sync] Sync PR 33976 - [FedCM] Only compare origins, not paths, for CSP checks

Categories

(Core :: DOM: Security, task, P4)

task

Tracking

()

RESOLVED FIXED
102 Branch
Tracking Status
firefox102 --- fixed

People

(Reporter: mozilla.org, Unassigned)

References

()

Details

(Whiteboard: [wptsync downstream][domsecurity-backlog])

Sync web-platform-tests PR 33976 into mozilla-central (this bug is closed when the sync is complete).

PR: https://github.com/web-platform-tests/wpt/pull/33976
Details from upstream follow.

Christian Biesinger <cbiesinger@chromium.org> wrote:

[FedCM] Only compare origins, not paths, for CSP checks

For compatibility with existing deployments, only compare origins.

This has been discussed and agreed with Chrome Security.

Bug: 1320724
Change-Id: I2758727149757cef835cd10b4c4d04897f234098
Reviewed-on: https://chromium-review.googlesource.com/3630577
WPT-Export-Revision: a61ed7b72a5ddec63ee1eadb9e0a42cb7cf6e51d

Component: web-platform-tests → DOM: Security
Product: Testing → Core
Whiteboard: [wptsync downstream] → [wptsync downstream][domsecurity-backlog]
Whiteboard: [wptsync downstream][domsecurity-backlog] → [wptsync downstream]
Whiteboard: [wptsync downstream] → [wptsync downstream][domsecurity-backlog]
Pushed by wptsync@mozilla.com:
https://hg.mozilla.org/integration/autoland/rev/4666c8fc501a
[wpt PR 33976] - [FedCM] Only compare origins, not paths, for CSP checks, a=testonly
Test result changes from PR not available.
Status: NEW → RESOLVED
Closed: 2 years ago
Resolution: --- → FIXED
Target Milestone: --- → 102 Branch
You need to log in before you can comment on or make changes to this bug.