Closed Bug 1943360 Opened 1 year ago Closed 1 year ago

Add a CSP to devtools documents

Categories

(DevTools :: General, task)

task

Tracking

(firefox137 fixed)

RESOLVED FIXED
137 Branch
Tracking Status
firefox137 --- fixed

People

(Reporter: tschuster, Assigned: tschuster)

References

(Blocks 1 open bug)

Details

Attachments

(10 files, 1 obsolete file)

48 bytes, text/x-phabricator-request
Details | Review
48 bytes, text/x-phabricator-request
Details | Review
48 bytes, text/x-phabricator-request
Details | Review
48 bytes, text/x-phabricator-request
Details | Review
48 bytes, text/x-phabricator-request
Details | Review
48 bytes, text/x-phabricator-request
Details | Review
48 bytes, text/x-phabricator-request
Details | Review
48 bytes, text/x-phabricator-request
Details | Review
48 bytes, text/x-phabricator-request
Details | Review
48 bytes, text/x-phabricator-request
Details | Review

I think some devtools documents already have a Content-Security-Policy, but the following don't seem to have any:

chrome://devtools/content/accessibility/index.html
chrome://devtools/content/debugger/index.html
chrome://devtools/content/dom/index.html
chrome://devtools/content/framework/browser-toolbox/window.html
chrome://devtools/content/framework/toolbox-window.xhtml
chrome://devtools/content/inspector/index.xhtml
chrome://devtools/content/inspector/markup/markup.xhtml
chrome://devtools/content/memory/index.xhtml
chrome://devtools/content/netmonitor/index.html
chrome://devtools/content/performance-new/panel/index.xhtml
chrome://devtools/content/responsive/toolbar.xhtml
chrome://devtools/content/shared/sourceeditor/codemirror/cmiframe.html
chrome://devtools/content/storage/index.xhtml
chrome://devtools/content/styleeditor/index.xhtml
chrome://devtools/content/webconsole/index.html
chrome://devtools/content/shared/webextension-fallback.html

This list is probably incomplete, because I am still collecting data.

The Bugbug bot thinks this bug should belong to the 'DevTools::Debugger' component, and is moving the bug to that component. Please correct in case you think the bot is wrong.

Component: General → Debugger
Component: Debugger → General
Assignee: nobody → tschuster
Keywords: leave-open
Pushed by tschuster@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/e1554e515f01 Add a CSP to the devtool's Debugger. r=devtools-reviewers,ochameau
Depends on: 1945493
Attachment #9465670 - Attachment is obsolete: true
Pushed by tschuster@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/bf1e410e174f Add a CSP to the devtool's Accessibility tab. r=devtools-reviewers,nchevobbe
Pushed by tschuster@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/5fe5ab69c5c9 Add a CSP to the devtool's Console. r=devtools-reviewers,bomsy https://hg.mozilla.org/integration/autoland/rev/b93d5e9313de Add a CSP to the devtool's Inspector. r=devtools-reviewers,bomsy https://hg.mozilla.org/integration/autoland/rev/387203fc61b0 Add a CSP to the devtool's Netmonitor. r=devtools-reviewers,bomsy https://hg.mozilla.org/integration/autoland/rev/c631343be068 Add a CSP to the devtool's Storage tab. r=devtools-reviewers,bomsy https://hg.mozilla.org/integration/autoland/rev/9362682258fe Add a CSP to the devtool's Style Editor. r=devtools-reviewers,bomsy
Pushed by tschuster@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/1e300692756d Add a CSP to the devtool's Memory tab. r=devtools-reviewers,bomsy https://hg.mozilla.org/integration/autoland/rev/357aeef0e910 Add a CSP to the devtool's Responsive toolbar. r=devtools-reviewers,bomsy
Regressions: 1950038

For tracking purposes I am going to open a new bug for the remaining files without a CSP.

Keywords: leave-open
Blocks: 1950311
Pushed by tschuster@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/f21cecb256a6 Add a CSP to the devtool's Inspector Markup View. r=devtools-reviewers,bomsy
Summary: Add a CSP to all devtools documents → Add a CSP to devtools documents
Status: NEW → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
Target Milestone: --- → 137 Branch
Regressions: 1954706
Regressions: 1955854
Regressed by: 1957333
No longer regressed by: 1957333
Regressions: 1957333
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: