diff --git a/dom/security/nsCSPService.cpp b/dom/security/nsCSPService.cpp index 0b3054cfec..ec32889acf 100644 --- a/dom/security/nsCSPService.cpp +++ b/dom/security/nsCSPService.cpp @@ -75,19 +75,23 @@ subjectToCSP(nsIURI* aURI, nsContentPolicyType aContentType) { if (NS_SUCCEEDED(rv) && match) { return true; } - // finally we have to whitelist "about:" which does not fall in - // any of the two categories underneath but is not subject to CSP. + + // Finally we have to whitelist "about:" which does not fall into + // the category underneath and also "javascript:" which is not + // subject to CSP content loading rules. rv = aURI->SchemeIs("about", &match); if (NS_SUCCEEDED(rv) && match) { return false; } + rv = aURI->SchemeIs("javascript", &match); + if (NS_SUCCEEDED(rv) && match) { + return false; + } // Other protocols are not subject to CSP and can be whitelisted: // * URI_IS_LOCAL_RESOURCE // e.g. chrome:, data:, blob:, resource:, moz-icon: // * URI_INHERITS_SECURITY_CONTEXT - // e.g. javascript: - // // Please note that it should be possible for websites to // whitelist their own protocol handlers with respect to CSP, // hence we use protocol flags to accomplish that.