Closed Bug 1508654 Opened 6 years ago Closed 6 years ago

Add assert to nsDocShellLoadState::SetupTriggeringPrincipal to remove inferred referrer triggering principal

Categories

(Core :: DOM: Security, enhancement, P1)

65 Branch
enhancement

Tracking

()

RESOLVED FIXED
mozilla66
Tracking Status
firefox65 --- wontfix
firefox66 --- fixed

People

(Reporter: jkt, Assigned: jkt)

References

(Blocks 1 open bug)

Details

(Whiteboard: [domsecurity-active])

Attachments

(1 file)

In nsDocShellLoadState::SetupTriggeringPrincipal we are inferring a codebase principal when there isn't a triggering principal but there is a referrer. We should require an explicit principal always.
Depends on changes in: Bug 1508609
Pushed by jkingston@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/b36b70ed2ed2 adding in assert for referrer implied codebase principal. r=ckerschb
Status: ASSIGNED → RESOLVED
Closed: 6 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla66
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: