Blocklist Yahoo Toolbar versions < 2




9 years ago
3 years ago


(Reporter: cww, Assigned: jorgev)


Firefox Tracking Flags

(Not tracked)




9 years ago
Prevents right clicking see bug 462475 and bug 505067 .  May need QA to figure out the exact versions to block on.

Comment 1

9 years ago
Would be for Firefox 3.5+ only.
OS: Linux → All
Hardware: x86 → All

Comment 2

9 years ago
I will be pushing 2.0 GA on AMO in next couple days. This should fix the issue.

Comment 3

9 years ago
(In reply to comment #2)
Did this ever happen?  This is a major issue.
Nope.  Was the update pushed?

Comment 5

9 years ago
The update is still under review by AMO (more than week now). Not sure why?

Comment 6

9 years ago
(In reply to comment #5)
> The update is still under review by AMO (more than week now). Not sure why?

In looking at this last night, there are three reasons:

1) The update (v2.0.0.20090707075511) is minified or packed which doesn't allow us to review your code. An editor attempted to review it shortly after you submitted but couldn't due to this code issue.
2) The email on file for Yahoo Toolbar bounced when I emailed you last night
3) Yahoo Toolbar has over 107 security issues listed when run via our validation suite. 

I contacted someone else I knew at Yahoo to try to find the contact for the toolbar and luckily saw your reply.

Please upload a version of the toolbar that is not minified or packed and I'll make sure it gets reviewed quickly. Also, you will need to look at the security issues generated by the validation suite. 

Lastly, please log into your AMO account and update the owner email to a working email address please.

You can email me directly to work through some of these issues.
The right way to fix this is to upgrade the extension and release an update.  Blocklisting is pretty drastic a response for something like this when an easy update could solve the problem.
I've emailed Prasad and I'll see what he says.

Comment 9

9 years ago
I rejected the latest update a few months ago for other reasons (eval'ing remote JSON data being one of them). There has been no response from the developer since. Nick, have you heard anything?

If the problem persists, then I will consider sandboxing this add-on.
Assignee: nobody → jorge
Don't think this needs blocklisting.
Last Resolved: 9 years ago
Resolution: --- → WORKSFORME
Product: → Toolkit
You need to log in before you can comment on or make changes to this bug.