Closed Bug 323959 Opened 19 years ago Closed 17 years ago

Mailto: URI in <a ping> launches mail composition

Categories

(Core :: DOM: Core & HTML, defect)

x86
Windows XP
defect
Not set
normal

Tracking

()

RESOLVED FIXED

People

(Reporter: mozilla, Unassigned)

References

Details

Mailto: URI's in the current implementation of the ping attribute cause FF to launch a mail window.
*** This bug has been marked as a duplicate of 323924 ***
Status: NEW → RESOLVED
Closed: 19 years ago
Resolution: --- → DUPLICATE
no, checkloaduri will not fix this.
Status: RESOLVED → REOPENED
Resolution: DUPLICATE → ---
My patch in bug 324642 actually restricts pings to HTTP and HTTPS only, and that should solve this bug.
Status: REOPENED → ASSIGNED
Depends on: 324642
So, is this fixed?
Status: ASSIGNED → NEW
Assignee: general → nobody
Flags: blocking1.9?
QA Contact: ian → general
Is this still a problem? If it is, adding contentpolicy checks should prevent this, or simply doing a protocol based check like darin suggested.
Smaug: Could you check that we're doing contentpolicy checks here. And maybe even add http/https restrictions for pings.
Assignee: nobody → Olli.Pettay
Flags: blocking1.9? → blocking1.9+
As far as I see, you Jonas fixed this in Bug 323924: http://bonsai.mozilla.org/cvsblame.cgi?file=mozilla/docshell/base/nsWebShell.cpp&rev=1.696&mark=200,211,212,219,220,226-232#199 Some tests were added in bug 375314. Does anyone still see some problems here, or could we mark this bug fixed. (Well, this particular bug is fixed, mailto: certainly doesn't launch anything anymore)
Marking FIXED, please reopen if you see still some problems.
Assignee: Olli.Pettay → nobody
marking this fixed for real :)
Status: NEW → RESOLVED
Closed: 19 years ago17 years ago
Resolution: --- → FIXED
Component: DOM: HTML → DOM: Core & HTML
You need to log in before you can comment on or make changes to this bug.