mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-07 00:08:39 +09:00
Explicitly use javascript: instead of URI_INHERITS_SECURITY_CONTEXT within subjectToCSP() (#2696)
Bug 1330035 Reviewed-on: https://repo.palemoon.org/MoonchildProductions/UXP/pulls/2696 Co-authored-by: Shadow <shadow@no-reply.palemoon.org> Co-committed-by: Shadow <shadow@no-reply.palemoon.org>
This commit is contained in:
parent
a2c6127832
commit
c318657acd
1 changed files with 8 additions and 4 deletions
|
|
@ -75,19 +75,23 @@ subjectToCSP(nsIURI* aURI, nsContentPolicyType aContentType) {
|
|||
if (NS_SUCCEEDED(rv) && match) {
|
||||
return true;
|
||||
}
|
||||
// finally we have to whitelist "about:" which does not fall in
|
||||
// any of the two categories underneath but is not subject to CSP.
|
||||
|
||||
// Finally we have to whitelist "about:" which does not fall into
|
||||
// the category underneath and also "javascript:" which is not
|
||||
// subject to CSP content loading rules.
|
||||
rv = aURI->SchemeIs("about", &match);
|
||||
if (NS_SUCCEEDED(rv) && match) {
|
||||
return false;
|
||||
}
|
||||
rv = aURI->SchemeIs("javascript", &match);
|
||||
if (NS_SUCCEEDED(rv) && match) {
|
||||
return false;
|
||||
}
|
||||
|
||||
// Other protocols are not subject to CSP and can be whitelisted:
|
||||
// * URI_IS_LOCAL_RESOURCE
|
||||
// e.g. chrome:, data:, blob:, resource:, moz-icon:
|
||||
// * URI_INHERITS_SECURITY_CONTEXT
|
||||
// e.g. javascript:
|
||||
//
|
||||
// Please note that it should be possible for websites to
|
||||
// whitelist their own protocol handlers with respect to CSP,
|
||||
// hence we use protocol flags to accomplish that.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue