Closed Bug 1497216 Opened 6 years ago Closed 5 years ago

Apply Meta CSP to about:webrtc

Categories

(Core :: DOM: Security, enhancement, P3)

enhancement

Tracking

()

RESOLVED FIXED
mozilla69
Tracking Status
firefox69 --- fixed

People

(Reporter: ckerschb, Assigned: ckerschb)

References

Details

(Whiteboard: [domsecurity-backlog1])

Attachments

(2 files)

No description provided.
Assignee: nobody → ckerschb
Status: NEW → ASSIGNED
Attachment #9015881 - Flags: review?(gijskruitbosch+bugs)
Attachment #9015881 - Flags: review?(gijskruitbosch+bugs) → review+
Comment on attachment 9015881 [details] [diff] [review] bug_1497216_csp_about_webrtc.patch I'd be more comfortable if someone who works with webrtc also doublechecks there's nothing else that'll fall foul of this CSP.
Attachment #9015881 - Flags: review?(drno)
Comment on attachment 9015881 [details] [diff] [review] bug_1497216_csp_about_webrtc.patch Review of attachment 9015881 [details] [diff] [review]: ----------------------------------------------------------------- I'm trusting that Christoph has tested that about:webrtc still works with this patch applied :-)
Attachment #9015881 - Flags: review?(drno) → review+
Is there a reason this hasn't landed yet? :-)
Flags: needinfo?(ckerschb)
D'oh, I forgot, I guess this is waiting on bug 965637...
Flags: needinfo?(ckerschb)

There's a r+ patch which didn't land and no activity in this bug for 2 weeks.
:ckerschb, could you have a look please?

Flags: needinfo?(ckerschb)

Before we can apply CSP to system privileged about pages we have to fix Bug 965637, in which we move the CSP from the Principal into the Client. Please note that the Meta Bug 1492063 for applying CSP to system privileged about: pages is blocked by 965637. At the moment we are fixing the last remaining blockers and as soon as we have landed Bug 965637 I'll try to land all the dependencies of Bug 1492063 so we end up having all about: pages secured by a CSP.

Flags: needinfo?(ckerschb)
Status: ASSIGNED → RESOLVED
Closed: 5 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla69
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: