From c318657acd3d8896dd07aeaa2777c1dee69d544b Mon Sep 17 00:00:00 2001 From: Shadow Date: Mon, 10 Mar 2025 22:02:20 +0000 Subject: [PATCH] Explicitly use javascript: instead of URI_INHERITS_SECURITY_CONTEXT within subjectToCSP() (#2696) Bug 1330035 Reviewed-on: https://repo.palemoon.org/MoonchildProductions/UXP/pulls/2696 Co-authored-by: Shadow Co-committed-by: Shadow --- dom/security/nsCSPService.cpp | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/dom/security/nsCSPService.cpp b/dom/security/nsCSPService.cpp index 0b3054cfec..ec32889acf 100644 --- a/dom/security/nsCSPService.cpp +++ b/dom/security/nsCSPService.cpp @@ -75,19 +75,23 @@ subjectToCSP(nsIURI* aURI, nsContentPolicyType aContentType) { if (NS_SUCCEEDED(rv) && match) { return true; } - // finally we have to whitelist "about:" which does not fall in - // any of the two categories underneath but is not subject to CSP. + + // Finally we have to whitelist "about:" which does not fall into + // the category underneath and also "javascript:" which is not + // subject to CSP content loading rules. rv = aURI->SchemeIs("about", &match); if (NS_SUCCEEDED(rv) && match) { return false; } + rv = aURI->SchemeIs("javascript", &match); + if (NS_SUCCEEDED(rv) && match) { + return false; + } // Other protocols are not subject to CSP and can be whitelisted: // * URI_IS_LOCAL_RESOURCE // e.g. chrome:, data:, blob:, resource:, moz-icon: // * URI_INHERITS_SECURITY_CONTEXT - // e.g. javascript: - // // Please note that it should be possible for websites to // whitelist their own protocol handlers with respect to CSP, // hence we use protocol flags to accomplish that.