Closed Bug 1892011 Opened 7 months ago Closed 7 months ago

RFC1918 exceptions for HTTP download blocking missing

Categories

(Core :: DOM: Security, defect, P1)

defect

Tracking

()

RESOLVED DUPLICATE of bug 1877195
Tracking Status
firefox-esr115 --- unaffected
firefox125 --- disabled
firefox126 --- disabled
firefox127 --- disabled

People

(Reporter: simonf, Assigned: ckerschb)

References

(Regression)

Details

(Keywords: regression)

Set release status flags based on info from the regressing bug 1877195

:ckerschb, since you are the author of the regressor, bug 1877195, could you take a look? Also, could you set the severity field?

For more information, please visit BugBot documentation.

FWIW, I am not sure this is really a regression because the previous code went through the Mixed Content Blocker and now we are calling functions explicitly. Anyway, I think we should add an exception and fix this.

Assignee: nobody → ckerschb
Severity: -- → S3
Status: NEW → ASSIGNED
Flags: needinfo?(ckerschb)
Priority: -- → P1

Setting Fx126 as disabled, the regressor was backed out of beta

Bug 1877195 was backed out from Release for Desktop 125.0.2 / Android 125.2.0 going out early next week. Additionally, a remote pref-flip hotfix (visible in about:studies as "HTTP download configuration") has been deployed to users of Desktop 125.0.1 to disable the new functionality to mitigate this issue until the dot release goes out.

Setting Fx127 as disabled, the regressor was backed out of central

Please note that we backed out Bug 1877195. Whenever we are going to-reland Bug 1877195 we'll make sure this incorporate the RFC1918 exceptions mentioned in this bug before-relanding.

Status: ASSIGNED → RESOLVED
Closed: 7 months ago
Duplicate of bug: 1877195
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.