mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-02 13:58:40 +09:00
Block http auth prompt for cross-origin image subresources by default.
Still allow this to be bypassed with a pref for those really rare corner cases where images are loaded cross-origin by design and the session hasn't been/can't be authenticated ahead of time.
This commit is contained in:
parent
e4273a3c58
commit
8ad0b46284
3 changed files with 28 additions and 7 deletions
|
|
@ -95,6 +95,8 @@ nsHttpChannelAuthProvider::~nsHttpChannelAuthProvider()
|
|||
uint32_t nsHttpChannelAuthProvider::sAuthAllowPref =
|
||||
SUBRESOURCE_AUTH_DIALOG_ALLOW_ALL;
|
||||
|
||||
bool nsHttpChannelAuthProvider::sImgCrossOriginAuthAllowPref = false;
|
||||
|
||||
void
|
||||
nsHttpChannelAuthProvider::InitializePrefs()
|
||||
{
|
||||
|
|
@ -102,6 +104,9 @@ nsHttpChannelAuthProvider::InitializePrefs()
|
|||
mozilla::Preferences::AddUintVarCache(&sAuthAllowPref,
|
||||
"network.auth.subresource-http-auth-allow",
|
||||
SUBRESOURCE_AUTH_DIALOG_ALLOW_ALL);
|
||||
mozilla::Preferences::AddBoolVarCache(&sImgCrossOriginAuthAllowPref,
|
||||
"network.auth.subresource-http-img-XO-auth",
|
||||
false);
|
||||
}
|
||||
|
||||
NS_IMETHODIMP
|
||||
|
|
@ -867,15 +872,15 @@ nsHttpChannelAuthProvider::GetCredentialsForChallenge(const char *challenge,
|
|||
else if (authFlags & nsIHttpAuthenticator::IDENTITY_ENCRYPTED)
|
||||
level = nsIAuthPrompt2::LEVEL_PW_ENCRYPTED;
|
||||
|
||||
// Depending on the pref setting, the authentication dialog may be
|
||||
// Depending on the pref settings, the authentication dialog may be
|
||||
// blocked for all sub-resources, blocked for cross-origin
|
||||
// sub-resources, or always allowed for sub-resources.
|
||||
// For more details look at the bug 647010.
|
||||
// BlockPrompt will set mCrossOrigin parameter as well.
|
||||
// If always allowed, image prompts may still be blocked by pref.
|
||||
// BlockPrompt() will set the mCrossOrigin parameter as well.
|
||||
if (BlockPrompt()) {
|
||||
LOG(("nsHttpChannelAuthProvider::GetCredentialsForChallenge: "
|
||||
"Prompt is blocked [this=%p pref=%d]\n",
|
||||
this, sAuthAllowPref));
|
||||
"Prompt is blocked [this=%p pref=%d img-pref=%d]\n",
|
||||
this, sAuthAllowPref, sImgCrossOriginAuthAllowPref));
|
||||
return NS_ERROR_ABORT;
|
||||
}
|
||||
|
||||
|
|
@ -983,7 +988,15 @@ nsHttpChannelAuthProvider::BlockPrompt()
|
|||
// the sub-resources only if they are not cross-origin.
|
||||
return !topDoc && !xhr && mCrossOrigin;
|
||||
case SUBRESOURCE_AUTH_DIALOG_ALLOW_ALL:
|
||||
// Allow the http-authentication dialog.
|
||||
// Allow the http-authentication dialog for subresources.
|
||||
// If the pref network.auth.subresource-http-img-XO-auth is set to false,
|
||||
// the http authentication dialog for image subresources is still blocked.
|
||||
if (!sImgCrossOriginAuthAllowPref &&
|
||||
loadInfo &&
|
||||
((loadInfo->GetExternalContentPolicyType() == nsIContentPolicy::TYPE_IMAGE) ||
|
||||
(loadInfo->GetExternalContentPolicyType() == nsIContentPolicy::TYPE_IMAGESET))) {
|
||||
return true;
|
||||
}
|
||||
return false;
|
||||
default:
|
||||
// This is an invalid value.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue