Closed Bug 773040 Opened 12 years ago Closed 4 years ago

SecReview: Allow launching installed native apps from WebappsInstaller

Categories

(mozilla.org :: Security Assurance: Review Request, task)

task
Not set
normal

Tracking

(Not tracked)

RESOLVED INVALID

People

(Reporter: curtisk, Assigned: mgoodwin)

References

Details

(Whiteboard: [pending secreview][start yyyy-mm-dd][target yyyy-mm-dd][Fx])

SecReview tracking bug
Actions regarding the review of the dependent bug should be tracked here.
1) Who is/are the point of contact(s) for this review?
2) Please provide a short description of the feature / application (e.g. problem solved, use cases, etc.):
3) Please provide links to additional information (e.g. feature page, wiki) if available and not yet included in feature description:
4) Does this request block another bug? If so, please indicate the bug number
5) This review will be scheduled amongst other requested reviews. What is the urgency or needed completion date of this review?
6) To help prioritize this work request, does this project support a goal specifically listed on this quarter's goal list?  If so, which goal?
7) Please answer the following few questions: (Note: If you are asked to describe anything, 1-2 sentences shall suffice.)
7a) Does this feature or code change affect Firefox, Thunderbird or any product or service the Mozilla ships to end users?
7b) Are there any portions of the project that interact with 3rd party services?
7c) Will your application/service collect user data? If so, please describe
8) If you feel something is missing here or you would like to provide other kind of feedback, feel free to do so here (no limits on size):
9) Desired Date of review (if known from https://mail.mozilla.com/home/ckoenig@mozilla.com/Security%20Review.html) and whom to invite.
Blocks: 772600
No longer blocks: 745924
Blocks: 766199
No longer blocks: 766199
Assignee: curtisk → nobody
Whiteboard: [pending secreview][start mm/dd/yyyy][target mm/dd/yyyy] → [pending secreview][needs info]
I see that the blocked bug is resolved fixed, but we never completed the security review? please answer comment 0 so we can rectify this inconsistency.
Flags: needinfo?(dwalkowski)
Whiteboard: [pending secreview][needs info] → [pending secreview]
sent mail to dwalkowski asking if he could give us the info needed
Flags: needinfo?(dwalkowski)
Flags: needinfo?(dwalkowski)
From: Curtis Koenig <ckoenig@mozilla.com>
Cc: Bill  Walker <bwalker@mozilla.com>
To: Daniel Walkowski <dwalkowski@mozilla.com>
-----//-----
Daniel,
On April 8th I sent an email to you regrind the sec-review flag on this =
bug:

> Dan,
> I set the need info flag on this bug for you some time ago and I am =
going back through my cruft and noticed this one still hanging around. =
Would you mind taking a look at this and providing the information we =
need so we can close this out? If your not the correct person please =
direct me to someone who can help us if you would.

We would like to get this issue properly looked at and resolved. If you =
could take a look at the bug(s) and respond in bug comments that would =
be helpful in allowing us to move forward on this.
Thanks,
--
Curtis
1) Who is/are the point of contact(s) for this review?

Dan Walkowski (primary), Myk Melez (secondary)


2) Please provide a short description of the feature / application (e.g. problem solved, use cases, etc.):

This code allows Firefox to launch external applications on the host machine.
The intended purpose is to launch html 5 apps from the App Dashboard or App Store if they have been previously installed 'natively', meaning packaged into a native container that the host OS believes to be a native application. (using mozApps.install() or mozApps.installPackaged() )


3) Please provide links to additional information (e.g. feature page, wiki) if available and not yet included in feature description:



4) Does this request block another bug? If so, please indicate the bug number

No.


5) This review will be scheduled amongst other requested reviews. What is the urgency or needed completion date of this review?

No urgency or completion date at this time.


6) To help prioritize this work request, does this project support a goal specifically listed on this quarter's goal list?  If so, which goal?

Not part of a specific quarterly goal. This code was shipped in Firefox 16 but is rarely invoked due to the scarcity of app stores that use the mozApps API.


7a) Does this feature or code change affect Firefox, Thunderbird or any product or service the Mozilla ships to end users?

As mentioned in #2 above, it does allow Firefox to launch external native applications on-demand.

7b) Are there any portions of the project that interact with 3rd party services?

This code can be invoked by an app store, such as Firefox Marketplace, or a Dashboard, or other privileged code.


7c) Will your application/service collect user data? If so, please describe

No user data is collected as a result of these changes
Flags: needinfo?(dwalkowski)
Whiteboard: [pending secreview] → [pending secreview][triage needed]
Assignee: nobody → mgoodwin
Whiteboard: [pending secreview][triage needed] → [pending secreview]
Whiteboard: [pending secreview] → [pending secreview][start yyyy-mm-dd][target yyyy-mm-dd]
Whiteboard: [pending secreview][start yyyy-mm-dd][target yyyy-mm-dd] → [pending secreview][start yyyy-mm-dd][target yyyy-mm-dd][Fx]
Status: ASSIGNED → RESOLVED
Closed: 4 years ago
Resolution: --- → INVALID
You need to log in before you can comment on or make changes to this bug.