Closed
Bug 2027045
Opened 6 months ago
Closed 6 months ago
Sanitizer: Prevent the creation of custom elements using is= (in the default config)
Categories
(Core :: DOM: Security, defect)
Core
DOM: Security
Tracking
()
RESOLVED
FIXED
151 Branch
| Tracking | Status | |
|---|---|---|
| firefox151 | --- | fixed |
People
(Reporter: tschuster, Assigned: tschuster)
References
(Blocks 1 open bug)
Details
Attachments
(1 file)
The is "attribute" can be used to make something a custom element. The default Sanitizer config does not allow any custom tag names like <custom-element> and there was actually no intention to allow something like <div is="custom-div"> either. While we are still discussing how users should be able to opt-in or opt-out the is "attribute" with a custom config, it's pretty obvious that we should remove support for this from the default config ASAP.
| Assignee | ||
Comment 1•6 months ago
|
||
| Assignee | ||
Comment 2•6 months ago
|
||
Keith, I would love to have some feedback if this approach makes sense. Is there any other data that might need to be adjusted when removing custom elements data for an element like maybe for children or something?
Flags: needinfo?(mozilla)
Updated•6 months ago
|
Attachment #9559352 -
Attachment description: WIP: Bug 2027045 - Sanitizer: Prevent the creation of custom elements using is= (in the default config) → Bug 2027045 - Sanitizer: Prevent the creation of custom elements using is= (in the default config). r?emilio
Pushed by tschuster@mozilla.com:
https://github.com/mozilla-firefox/firefox/commit/3c4908151d3c
https://hg.mozilla.org/integration/autoland/rev/c92564aaa32c
Sanitizer: Prevent the creation of custom elements using is= (in the default config). r=emilio
Pushed by agoloman@mozilla.com:
https://github.com/mozilla-firefox/firefox/commit/2ee80164535e
https://hg.mozilla.org/integration/autoland/rev/e43c25038272
Revert "Bug 2027045 - Sanitizer: Prevent the creation of custom elements using is= (in the default config). r=emilio" for causing build bustages @Sanitizer.cpp.
Backed out for causing build bustages @Sanitizer.cpp.
Flags: needinfo?(tschuster)
Pushed by tschuster@mozilla.com:
https://github.com/mozilla-firefox/firefox/commit/c802e213bdc2
https://hg.mozilla.org/integration/autoland/rev/fd491ecef60b
Sanitizer: Prevent the creation of custom elements using is= (in the default config). r=emilio
| Assignee | ||
Updated•6 months ago
|
Flags: needinfo?(tschuster)
Comment 8•6 months ago
|
||
| bugherder | ||
Status: NEW → RESOLVED
Closed: 6 months ago
status-firefox151:
--- → fixed
Resolution: --- → FIXED
Target Milestone: --- → 151 Branch
Created web-platform-tests PR https://github.com/web-platform-tests/wpt/pull/59183 for changes under testing/web-platform/tests
Upstream PR merged by moz-wptsync-bot
Updated•5 months ago
|
QA Whiteboard: [qa-triage-done-c152/b151]
| Assignee | ||
Updated•4 months ago
|
See Also: → CVE-2026-12315
You need to log in
before you can comment on or make changes to this bug.
Description
•