Closed
Bug 1806080
Opened 2 years ago
Closed 2 years ago
Mixed content level 2 makes csp directive: "block-all-mixed-content" obsolete
Categories
(Core :: DOM: Security, task, P3)
Core
DOM: Security
Tracking
()
RESOLVED
FIXED
112 Branch
Tracking | Status | |
---|---|---|
firefox112 | --- | fixed |
People
(Reporter: t.yavor, Assigned: freddy)
References
(Blocks 1 open bug)
Details
(Whiteboard: [domsecurity-active])
Attachments
(1 file)
Bug 1806080 - Mixed content level 2 makes csp directive: block-all-mixed-content obsolete. r=freddyb
(deleted),
text/x-phabricator-request
|
Details |
If mixed content level 2 is enabled we should disabled the "block-all-mixed-content" CSP directive according to the standard (W3C)
Reporter | ||
Updated•2 years ago
|
Assignee: nobody → lyavor
Reporter | ||
Comment 1•2 years ago
|
||
Updated•2 years ago
|
Severity: -- → S3
Priority: -- → P3
Whiteboard: [domsecurity-active]
Updated•2 years ago
|
Attachment #9308675 -
Attachment description: WIP: Bug 1806080 - Mixed content level 2 makes csp directive: block-all-mixed-content obsolete. r=freddyb → Bug 1806080 - Mixed content level 2 makes csp directive: block-all-mixed-content obsolete. r=freddyb
Pushed by fbraun@mozilla.com:
https://hg.mozilla.org/integration/autoland/rev/b98fe323e6b2
Mixed content level 2 makes csp directive: block-all-mixed-content obsolete. r=freddyb
Comment 3•2 years ago
|
||
Backed out changeset b98fe323e6b2 (bug 1806080) for causing bc failures at browser_csp_block_all_mixedcontent_and_mixed_content_display_upgrade.js
Backout: https://hg.mozilla.org/integration/autoland/rev/d196c64b9e196c0aba2cdb9250aac733be27453f
Failure log: https://treeherder.mozilla.org/logviewer?job_id=407077748&repo=autoland&lineNumber=12400
Flags: needinfo?(t.yavor)
Assignee | ||
Comment 4•2 years ago
|
||
Stealing. This should be simple enough to drag over the finish line.
Assignee: t.yavor → fbraun
Flags: needinfo?(t.yavor)
Pushed by fbraun@mozilla.com:
https://hg.mozilla.org/integration/autoland/rev/8f908328348e
Mixed content level 2 makes csp directive: block-all-mixed-content obsolete. r=freddyb
Comment 6•2 years ago
|
||
bugherder |
Status: NEW → RESOLVED
Closed: 2 years ago
status-firefox112:
--- → fixed
Resolution: --- → FIXED
Target Milestone: --- → 112 Branch
You need to log in
before you can comment on or make changes to this bug.
Description
•