Closed Bug 1607673 Opened 5 years ago Closed 5 years ago

follow-up: Do not only assert but really disallow loading http(s) scripts into system privileged contexts

Categories

(Core :: DOM: Security, task, P3)

task

Tracking

()

RESOLVED DUPLICATE of bug 1543579

People

(Reporter: ckerschb, Assigned: freddy)

References

Details

(Whiteboard: [domsecurity-active])

No description provided.
Type: defect → task
Whiteboard: [domsecurity-active]
Assignee: ckerschb → fbraun
Status: ASSIGNED → RESOLVED
Closed: 5 years ago
Resolution: --- → DUPLICATE

Bug 1613609 will turn the deny-list approach (consisting of of HTTP/HTTPS/FTP) into a default allow-list

You need to log in before you can comment on or make changes to this bug.