Closed
Bug 1951670
Opened 10 months ago
Closed 10 months ago
Add a report-only CSP for blocking inline event handlers in browser.xhtml (for Release)
Categories
(Core :: DOM: Security, task)
Core
DOM: Security
Tracking
()
RESOLVED
FIXED
138 Branch
People
(Reporter: tschuster, Assigned: tschuster)
References
Details
Attachments
(1 file)
|
48 bytes,
text/x-phabricator-request
|
pascalc
:
approval-mozilla-beta+
|
Details | Review |
No description provided.
| Assignee | ||
Comment 1•10 months ago
|
||
Pushed by tschuster@mozilla.com:
https://hg.mozilla.org/integration/autoland/rev/7a2ecdf66a2b
Add a report-only CSP pref for blocking inline event handlers in browser.xhtml. r=freddyb,firefox-desktop-core-reviewers ,mconley
Comment 3•10 months ago
|
||
| bugherder | ||
Status: NEW → RESOLVED
Closed: 10 months ago
status-firefox138:
--- → fixed
Resolution: --- → FIXED
Target Milestone: --- → 138 Branch
| Assignee | ||
Comment 4•10 months ago
•
|
||
Comment on attachment 9469744 [details]
Bug 1951670 - Add a report-only CSP pref for blocking inline event handlers in browser.xhtml. r?freddyb
Beta/Release Uplift Approval Request
- User impact if declined/Reason for urgency: We want to collect this Telemetry as soon as possible in Release so uplifting to Beta gives us a way to do this.
- Is this code covered by automated tests?: Yes
- Has the fix been verified in Nightly?: Yes
- Needs manual test from QE?: No
- If yes, steps to reproduce:
- List of other uplifts needed: bug 1953374
- Risk to taking this patch: Medium
- Why is the change risky/not risky? (and alternatives if risky): We had a blocking CSP in Nightly/Beta for a while now. We are going to have a non-blocking (report-only) CSP for late beta/release. This is covered by tests.
- String changes made/needed:
- Is Android affected?: Yes
Attachment #9469744 -
Flags: approval-mozilla-beta?
Updated•10 months ago
|
Attachment #9469744 -
Flags: approval-mozilla-beta? → approval-mozilla-beta+
Updated•10 months ago
|
status-firefox137:
--- → fixed
You need to log in
before you can comment on or make changes to this bug.
Description
•