Closed
Bug 266794
Opened 20 years ago
Closed 20 years ago
"Allowed sites to install software" is not an accurate representation of actual sites installing software
Categories
(Toolkit :: Add-ons Manager, defect)
Tracking
()
RESOLVED
DUPLICATE
of bug 257055
People
(Reporter: ccurzio+mozilla, Assigned: bugs)
References
()
Details
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.3) Gecko/20041026 Firefox/1.0RC1
Build Identifier: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.3) Gecko/20041026 Firefox/1.0RC1
If you attempt to install an xpi from a page on www.foo.com, the typical "To
protect your computer" prevention bar is displayed. Allowing software to be
installed from www.foo.com will permit the software to be installed, even if
it's actually located on another server.
Reproducible: Always
Steps to Reproduce:
1. Go to a page that has an xpi available for installation where the xpi is on a
different server.
2. Click to install the xpi.
3. Allow the site linking to the xpi to install software.
Actual Results:
Software was immediately installed after re-clicking the xpi link once the site
was allowed.
Expected Results:
I'm not really sure. Maybe prompt for the actual site where the xpi is located
for allowing software installation?
Comment 1•20 years ago
|
||
You *are* prompted for the site the file is actually located at -- that's on the
install confirmation dialog that comes up.
Status: NEW → RESOLVED
Closed: 20 years ago
Resolution: --- → INVALID
Reporter | ||
Comment 2•20 years ago
|
||
No, you're wrong. You're not prompted for the correct server. That's the point
of this bug.
If you go to the following URL:
http://www.accipiter.org/moztest/extension.html
and click the link, it's going to say "Firefox prevented this site
(www.accipiter.org) from installing software on your computer." Then if you edit
the options and allow www.accipiter.org in the "Allowed Sites" window, the
software will install just fine. All the while, the xpi is actually located on
www.cosmicat.com.
Additionally, if you allow www.cosmicat.com (and NOT www.accipiter.org) to
install software, and you click the link on the page above, you still aren't
allowed to install it without allowing www.accipiter.org.
Status: RESOLVED → REOPENED
Resolution: INVALID → ---
Comment 3•20 years ago
|
||
I'm running version 1.0, I am prompted the correct location.
BUT: That yellow bar that becomes visible when firefox blocked something, says
it blocked server 'foo.com' from installing software - while the software is on
'bar.com'.
See http://science.slashdot.org/comments.pl?sid=131033&cid=10938788 for this one
:-)
Comment 4•20 years ago
|
||
This is the correct behavior. The whitelist applies to the site linking to the
xpi, and the accept prompt shows the actual location of the XPI.
*** This bug has been marked as a duplicate of 257055 ***
Status: REOPENED → RESOLVED
Closed: 20 years ago → 20 years ago
Resolution: --- → DUPLICATE
Updated•17 years ago
|
Product: Firefox → Toolkit
You need to log in
before you can comment on or make changes to this bug.
Description
•