Do we really need to strip URI schemes other than http and https?
Categories
(Firefox :: Address Bar, task, P3)
Tracking
()
People
(Reporter: scunnane, Unassigned)
References
Details
(Whiteboard: [sng])
Address bar code should only be stripping out the http and https URI schemes before running the appropriate providers. However, over the years, additional schemes also came to be stripped out. With this bug, we want to discover why the additional schemes besides http and https came to be stripped out.
I did a fair amount of code archeology to trace how we’ve historically handled stripping the scheme from the URI. This gets at the "what", but a lot of the "why" is still missing.
- Back in 2014, Marco added this code to strip out just http, https and ftp.
- Then in 2018, as part of a series of patches to improve autofill, Drew changed Marco's
stripPrefixfunction to strip out all schemes - see the diff here - In 2020, Harry added the
stripURLPrefixmethod to theUrlbarUtilsobject. It does the exact same things as Drew’sstripPrefixfunction, but Harry slightly refactored theREGEXP_STRIP_PREFIXand scoped it to the method - see diff here - At some point,
stripPrefixwas renamedstripAnyPrefix- I couldn’t find where, but only the function name changed, nothing in the comments or code itself. Then, in 2021, Harry removed thestripAnyPrefixfunction as part of cleaning up the code inUrlbarProviderPlaces- see the diff here - Finally, James landed a patch this past May that introduces a
UrlbarUtils.PROTOCOLS_WITHOUT_AUTHORITYconstant. Here’s the associated bug, and here’s the diff. His patch strips the prefix when the scheme ends in:(not://) and the scheme is NOT on a safelist. That safelist includesabout:,data:,file:,javascript:andview-source:.
It seems like investigating number 2 above is the best place to start.
I've landed a patch so that about: is no longer stripped. To ensure that this patch and any future patches handling non-http(s) URIs don't trample over previous reasoning, we need to determine why the additional schemes besides http and https came to be stripped out.
Comment 1•4 years ago
|
||
We should really understand whether we need that complication or not, and in case we don't, just revert to only strip http and https.
Updated•2 years ago
|
Updated•2 years ago
|
Description
•