Closed
Bug 56260
Opened 25 years ago
Closed 25 years ago
"Remember this decision" always active
Categories
(Core :: Security, defect, P1)
Tracking
()
VERIFIED
FIXED
mozilla0.9.4
People
(Reporter: oliver.fels, Assigned: security-bugs)
References
Details
(Whiteboard: patch)
Attachments
(1 file)
|
811 bytes,
patch
|
Details | Diff | Splinter Review |
When accessing a site with a signed script which applies enablePrivilege, the
checkbox in the "Remember this decision" dialog seems to be active by default.
This is a major security flaw as it leads to misunderstandings and confusion.
Updated•25 years ago
|
QA Contact: czhang → junruh
Comment 1•25 years ago
|
||
setting bug status to New. Oliver Fels, what behavior do you expect, not
checked by defualt or a different message explaining the default?
Status: UNCONFIRMED → NEW
Ever confirmed: true
| Reporter | ||
Comment 2•25 years ago
|
||
It should be unchecked by default.
The current setting makes it too easy for users for just clicking away the message without having noticed the dialog. The user should actively grant that he doesn't want to be bothered with that security issue again by checking the box and presseing OK.
| Assignee | ||
Comment 4•25 years ago
|
||
Mass adding mozilla0.9 keyword (mass changing milestone doesn't seem to work).
Status: NEW → ASSIGNED
Keywords: mozilla0.9
| Assignee | ||
Comment 5•25 years ago
|
||
Mass changing milestone to Moz1.0 - stuff targeted for late spring/early summer.
Target Milestone: --- → mozilla1.0
| Assignee | ||
Comment 6•25 years ago
|
||
Target is now 0.9.5, Priority P1.
Priority: P3 → P1
Target Milestone: mozilla1.0 → mozilla0.9.5
| Assignee | ||
Comment 8•25 years ago
|
||
| Assignee | ||
Updated•25 years ago
|
Whiteboard: patch
Comment 9•25 years ago
|
||
sr=jst
| Assignee | ||
Comment 10•25 years ago
|
||
Fix checked in.
Status: ASSIGNED → RESOLVED
Closed: 25 years ago
Resolution: --- → FIXED
Comment 11•24 years ago
|
||
Verified on
build: 2001-09-13-0.9.4
platform: Win NT
The checkbox is now not active by default.
Status: RESOLVED → VERIFIED
You need to log in
before you can comment on or make changes to this bug.
Description
•