Closed Bug 437723 Opened 12 years ago Closed 12 years ago

[FIX]LookupPolicy does the wrong thing on jar: URIs

Categories

(Core :: Security, defect, P1)

defect

Tracking

()

RESOLVED FIXED
mozilla1.9.1a2

People

(Reporter: bzbarsky, Assigned: bzbarsky)

References

Details

(Keywords: fixed1.9.1, regression)

Attachments

(1 file)

This is a regression from bug 413161.  See bug 413161 comment 23 towards the end, and following comments.

The upshot is that saved privileges won't work right for unsigned jars, about: URIs (shouldn't be much of an issue) and view-source URIs (also probably not that bad, I think...).  They'll also not work right for any new nested URIs we or extensions might add.  This last is what worries me.
Flags: blocking1.9.1?
Flags: blocking1.9.0.1?
Blocks: 413161
(In reply to comment #0)
> The upshot is that saved privileges won't work right for unsigned jars

Might this bear on bug 435254 as well?  That's Windows-only, though, AFAICT. :/
It doesn't, and that bug is XP...  I marked it duplicate.
OS: Linux → All
Hardware: PC → All
Assignee: nobody → jonas
Flags: wanted1.9.0.x+
Flags: blocking1.9.1?
Flags: blocking1.9.1+
Flags: blocking1.9.0.1?
Flags: blocking1.9.0.1-
Priority: -- → P1
Progress on this, Jonas?
Attached patch Just fix itSplinter Review
Assignee: jonas → bzbarsky
Status: NEW → ASSIGNED
Attachment #331396 - Flags: superreview?(jonas)
Attachment #331396 - Flags: review?(jonas)
Summary: LookupPolicy does the wrong thing on jar: URIs → [FIX]LookupPolicy does the wrong thing on jar: URIs
Comment on attachment 331396 [details] [diff] [review]
Just fix it

Thanks!
Attachment #331396 - Flags: superreview?(jonas)
Attachment #331396 - Flags: superreview+
Attachment #331396 - Flags: review?(jonas)
Attachment #331396 - Flags: review+
Checked in.
Status: ASSIGNED → RESOLVED
Closed: 12 years ago
Flags: in-testsuite?
Resolution: --- → FIXED
Target Milestone: --- → mozilla1.9.1a2
Keywords: fixed1.9.1
You need to log in before you can comment on or make changes to this bug.