mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-07 16:28:38 +09:00
[DOM] Don't allow internal MIME types to be assigned to DataTransfer
We already blocked x-moz-file(-promise) and x-moz-place* but of course people would find ways to abuse other internal types. This change now blocks everything except x-moz-url types which are harmless. (i.e. whitelist instead of blacklist)
This commit is contained in:
parent
7f3a7225af
commit
3bcd2ee360
2 changed files with 11 additions and 11 deletions
|
|
@ -639,16 +639,11 @@ DataTransfer::PrincipalMaySetData(const nsAString& aType,
|
|||
return false;
|
||||
}
|
||||
|
||||
if (aType.EqualsASCII(kFileMime) ||
|
||||
aType.EqualsASCII(kFilePromiseMime)) {
|
||||
NS_WARNING("Disallowing adding x-moz-file or x-moz-file-promize types to DataTransfer");
|
||||
return false;
|
||||
}
|
||||
|
||||
// Disallow content from creating x-moz-place flavors, so that it cannot
|
||||
// create fake Places smart queries exposing user data.
|
||||
if (StringBeginsWith(aType, NS_LITERAL_STRING("text/x-moz-place"))) {
|
||||
NS_WARNING("Disallowing adding moz-place types to DataTransfer");
|
||||
// Don't allow adding internal types of the form */x-moz-*, but
|
||||
// special-case the url types as they are simple variations of urls.
|
||||
if (FindInReadable(NS_LITERAL_STRING(kInternal_Mimetype_Prefix), aType) &&
|
||||
!StringBeginsWith(aType, NS_LITERAL_STRING("text/x-moz-url"))) {
|
||||
NS_WARNING("Disallowing adding requested internal type to DataTransfer");
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue