Closed Bug 1811505 Opened 2 years ago Closed 2 years ago

Check for about scheme in ShouldResistFingerprinting might be too broad

Categories

(Core :: Security, defect)

defect

Tracking

()

RESOLVED DUPLICATE of bug 1805101

People

(Reporter: tschuster, Unassigned)

References

(Blocks 1 open bug)

Details

We should investigate if this and this check for aURI->SchemeIs("about") potentially allows all about:blank/about:srcdoc pages to bypass the resist fingerprinting mode.

Group: core-security → dom-core-security

I deon't think we need to keep this hidden.

The conversation I was thinking of was in https://phabricator.services.mozilla.com/D95139

Group: dom-core-security

The severity field is not set for this bug.
:dveditz, could you have a look please?

For more information, please visit auto_nag documentation.

Flags: needinfo?(dveditz)
Severity: -- → S3
Flags: needinfo?(dveditz)
Whiteboard: [fpp:m?]
See Also: → 1830070
Status: NEW → RESOLVED
Closed: 2 years ago
Duplicate of bug: 1805101
Resolution: --- → DUPLICATE
Whiteboard: [fpp:m?]
You need to log in before you can comment on or make changes to this bug.