Closed Bug 2068156 Opened 27 days ago Closed 26 days ago

Skip parsing a URI to look for a password the spec cannot hold

Categories

(DevTools :: Console, enhancement)

enhancement

Tracking

(firefox157 fixed)

RESOLVED FIXED
157 Branch
Tracking Status
firefox157 --- fixed

People

(Reporter: mayankleoboy1, Assigned: mayankleoboy1)

References

Details

Attachments

(1 file)

No description provided.

Console and nsScriptError both build an nsIURI out of a script filename on
every message, purely to ask whether it carries a password worth hiding. On
the console.clear() testcase in the bug that parse is 19% of the content
process main thread.

A password only reaches nsIURI through a userinfo component, and every
implementation that can report a non-empty one - nsStandardURL, DefaultURI,
and SubstitutingJARURI, which forwards to its source URL - derives it from a
literal '@'. Scanning for that byte first leaves the sanitizing path
unchanged and skips the parse otherwise.

Both call sites now share NS_GetSanitizedSpecFromSpec rather than spelling
the same check two different ways. That unifies one behaviour difference: on
a spec that has a password which cannot be hidden, Console used to fall back
to the raw spec, and nsScriptError to an empty string. The helper keeps
nsScriptError's behaviour, since emitting a spec known to contain a password
is the one outcome worth avoiding.

Console also had an NS_IsMainThread() check in front of the sanitizing,
added by bug 1246091 in 2016 when this code first became reachable from
workers and NS_NewURI was main thread only. Bug 1536744 renamed
NS_NewURIOnAnyThread to NS_NewURI in 2019, and nsIURI is immutable and
threadsafe, so the check has been dead weight since then. Dropping it also
means worker console events reaching a chrome console event handler - via
setConsoleEventHandler or retrieveConsoleEvents - get the same sanitizing
main thread ones already got.

Assignee: nobody → mayankleoboy1
Status: NEW → ASSIGNED
Pushed by mayankleoboy1@gmail.com: https://github.com/mozilla-firefox/firefox/commit/de09a5f0cc77 https://hg.mozilla.org/integration/autoland/rev/77f7147935b0 Bug 2067000 - Skip parsing a URI to look for a password the spec cannot hold. r=necko-reviewers,valentin
Status: ASSIGNED → RESOLVED
Closed: 26 days ago
Resolution: --- → FIXED
Target Milestone: --- → 157 Branch
Regressions: 2070111
QA Whiteboard: [qa-triage-done-c158/b157]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: