Closed Bug 1951670 Opened 10 months ago Closed 10 months ago

Add a report-only CSP for blocking inline event handlers in browser.xhtml (for Release)

Categories

(Core :: DOM: Security, task)

task

Tracking

()

RESOLVED FIXED
138 Branch
Tracking Status
firefox137 --- fixed
firefox138 --- fixed

People

(Reporter: tschuster, Assigned: tschuster)

References

Details

Attachments

(1 file)

No description provided.
Pushed by tschuster@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/7a2ecdf66a2b Add a report-only CSP pref for blocking inline event handlers in browser.xhtml. r=freddyb,firefox-desktop-core-reviewers ,mconley
Status: NEW → RESOLVED
Closed: 10 months ago
Resolution: --- → FIXED
Target Milestone: --- → 138 Branch

Comment on attachment 9469744 [details]
Bug 1951670 - Add a report-only CSP pref for blocking inline event handlers in browser.xhtml. r?freddyb

Beta/Release Uplift Approval Request

  • User impact if declined/Reason for urgency: We want to collect this Telemetry as soon as possible in Release so uplifting to Beta gives us a way to do this.
  • Is this code covered by automated tests?: Yes
  • Has the fix been verified in Nightly?: Yes
  • Needs manual test from QE?: No
  • If yes, steps to reproduce:
  • List of other uplifts needed: bug 1953374
  • Risk to taking this patch: Medium
  • Why is the change risky/not risky? (and alternatives if risky): We had a blocking CSP in Nightly/Beta for a while now. We are going to have a non-blocking (report-only) CSP for late beta/release. This is covered by tests.
  • String changes made/needed:
  • Is Android affected?: Yes
Attachment #9469744 - Flags: approval-mozilla-beta?
Attachment #9469744 - Flags: approval-mozilla-beta? → approval-mozilla-beta+
Blocks: 1966120
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: