From f1f9dde29e7d230689707b999a535ae640775722 Mon Sep 17 00:00:00 2001 From: Moonchild Date: Sun, 17 Dec 2023 22:56:04 +0100 Subject: [PATCH] Issue #2405 - Add a pref to disable CSP reporting. Resolves #2405 --- dom/security/nsCSPContext.cpp | 10 ++++++++++ dom/security/nsCSPService.cpp | 3 +++ dom/security/nsCSPService.h | 5 +++-- modules/libpref/init/all.js | 1 + 4 files changed, 17 insertions(+), 2 deletions(-) diff --git a/dom/security/nsCSPContext.cpp b/dom/security/nsCSPContext.cpp index b4818b5d0c..8cc83a6d97 100644 --- a/dom/security/nsCSPContext.cpp +++ b/dom/security/nsCSPContext.cpp @@ -827,6 +827,16 @@ nsCSPContext::SendReports(nsISupports* aBlockedContentSource, { NS_ENSURE_ARG_MAX(aViolatedPolicyIndex, mPolicies.Length() - 1); + if (!CSPService::sCSPReportingEnabled) { + // Reporting is pref-disabled. Don't do any actual work and return success. + nsContentUtils::ReportToConsoleNonLocalized( + NS_LITERAL_STRING("CSP violation report not sent: reports have been disabled contrary to spec."), + nsIScriptError::warningFlag, + NS_LITERAL_CSTRING("Content Security Policy"), + nullptr); + return NS_OK; + } + dom::CSPReport report; nsresult rv; diff --git a/dom/security/nsCSPService.cpp b/dom/security/nsCSPService.cpp index 5e5066b739..7ba531030d 100644 --- a/dom/security/nsCSPService.cpp +++ b/dom/security/nsCSPService.cpp @@ -25,12 +25,15 @@ using namespace mozilla; /* Keeps track of whether or not CSP is enabled */ bool CSPService::sCSPEnabled = true; +/* Keeps track of whether or not CSP reporting is enabled */ +bool CSPService::sCSPReportingEnabled = true; static LazyLogModule gCspPRLog("CSP"); CSPService::CSPService() { Preferences::AddBoolVarCache(&sCSPEnabled, "security.csp.enable"); + Preferences::AddBoolVarCache(&sCSPReportingEnabled, "security.csp.reporting.enabled"); } CSPService::~CSPService() diff --git a/dom/security/nsCSPService.h b/dom/security/nsCSPService.h index e9c82d438a..3c0883844f 100644 --- a/dom/security/nsCSPService.h +++ b/dom/security/nsCSPService.h @@ -14,8 +14,8 @@ #define CSPSERVICE_CONTRACTID "@mozilla.org/cspservice;1" #define CSPSERVICE_CID \ - { 0x8d2f40b2, 0x4875, 0x4c95, \ - { 0x97, 0xd9, 0x3f, 0x7d, 0xca, 0x2c, 0xb4, 0x60 } } + { 0x83d284d6, 0xf280, 0x48ae, \ + { 0xa5, 0x6b, 0x0f, 0x28, 0x11, 0x29, 0x83, 0x1b } } class CSPService : public nsIContentPolicy, public nsIChannelEventSink { @@ -26,6 +26,7 @@ public: CSPService(); static bool sCSPEnabled; + static bool sCSPReportingEnabled; protected: virtual ~CSPService(); diff --git a/modules/libpref/init/all.js b/modules/libpref/init/all.js index 9adfe7cc17..90dd0925aa 100644 --- a/modules/libpref/init/all.js +++ b/modules/libpref/init/all.js @@ -2187,6 +2187,7 @@ pref("security.notification_enable_delay", 500); pref("security.csp.enable", true); pref("security.csp.experimentalEnabled", false); pref("security.csp.enableStrictDynamic", true); +pref("security.csp.reporting.enabled", true); // Default Content Security Policy to apply to signed contents. pref("security.signed_content.CSP.default", "script-src 'self'; style-src 'self'");