Make framebusting pref independent of pop-up blocking
Categories
(Core :: DOM: Security, task)
Tracking
()
People
(Reporter: maltejur, Assigned: maltejur)
References
(Blocks 1 open bug)
Details
Attachments
(5 files)
To address Bug 2003033, we should consider allowing the framebusting prevention to be enabled by dom.security.framebusting_intervention.enabled independently of pop-up blocking is disabled by dom.disable_open_during_load. The combined permission for pop-up blocking and preventing framebusting could be kept as it is right now. This would require slight UI adjustments in the settings.
| Assignee | ||
Comment 1•2 months ago
|
||
| Assignee | ||
Updated•2 months ago
|
Updated•2 months ago
|
| Assignee | ||
Comment 2•2 months ago
|
||
In the Privacy & Security settings pane, have the "Block pop-ups and third-party
redirects" checkbox control both "dom.disable_open_during_load" and
"dom.security.framebusting_intervention.enabled", instead of previously just
"dom.disable_open_during_load". The checkbox will be in an unchecked state if
only one of the prefs is set. This state will only be reached in case one of the
prefs is manually changed through "about:config" or similar.
Updated•2 months ago
|
| Assignee | ||
Comment 3•2 months ago
|
||
Update the SitePermission configuration for the popup permission, now that it
can also be used in configurations where either pop-up blocking or the
framebusting protection can be disabled. This includes using different labels if
only one of the prefs is enabled.
| Assignee | ||
Comment 4•2 months ago
|
||
The framebusting protection now no longer gets disabled when
dom.disable_open_during_load gets disabled. The option in the settings UI still
controls both pop-up blocking and the framebusting protection at the same time,
and the "popup" permission is also still shared, so the PopupBlocking policy
should control both prefs.
| Assignee | ||
Comment 5•2 months ago
|
||
Description
•