Closed Bug 2045980 Opened 2 months ago Closed 29 days ago

Expand SitePolicies to cover forced HTTPS connections

Categories

(Enterprise Products :: Firefox, enhancement, P2)

enhancement

Tracking

(firefox155 fixed)

RESOLVED FIXED
Tracking Status
firefox155 --- fixed

People

(Reporter: bsmth, Assigned: mossop)

References

(Blocks 1 open bug)

Details

(Whiteboard: [size=1.5])

User Story

As an admin, I want the `SitePolicies` policy to support a `ForceHttpsOnly` field, so that I can require matched sites to use HTTPS with no HTTP fallback.

Acceptance criteria:

- `ForceHttpsOnly` is a boolean field on a `SitePolicies` entry.  When enabled, HTTP requests upgraded for the matched site to HTTPS.
- If the HTTPS connection fails or is unavailable, there's no fallback to HTTP.

Implementation notes:
- Reference: `SitePolicies` enterprise policy.
- Related prefs: dom.security.https_only_mode, dom.security.https_only_mode_pbm

Out of scope:
- New site-matching syntax; constraints reuse the existing SitePolicies site-matching mechanism.

Attachments

(1 file)

No description provided.
Severity: -- → S2
Whiteboard: [size=1.5]
Assignee: nobody → dtownsend
Attachment #9621560 - Attachment description: WIP: Bug 2045980: Add a site policy for https-only mode. → Bug 2045980: Add a site policy for https-only mode. r=mkaply!,#necko-reviewers!
Status: NEW → RESOLVED
Closed: 29 days ago
Resolution: --- → FIXED
Flags: qe-verify+
QA Contact: pmagyari
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: