Bug 1348801: Teach TriggeringPrincipal about OA when opening link in private window

This commit is contained in:
janekptacijarabaci 2018-04-30 23:58:51 +02:00 committed by Roy Tam
commit f99258328c

View file

@ -259,6 +259,19 @@ function openLinkIn(url, where, params) {
return;
}
// Teach the principal about the right OA to use, e.g. in case when
// opening a link in a new private window, or in a new container tab.
// Please note we do not have to do that for SystemPrincipals and we
// can not do it for NullPrincipals since NullPrincipals are only
// identical if they actually are the same object (See Bug: 1346759)
if (aPrincipal && aPrincipal.isCodebasePrincipal) {
let attrs = {
userContextId: aUserContextId,
privateBrowsingId: aIsPrivate || (w && PrivateBrowsingUtils.isWindowPrivate(w)),
};
aPrincipal = Services.scriptSecurityManager.createCodebasePrincipal(aPrincipal.URI, attrs);
}
if (!w || where == "window") {
// Strip referrer data when opening a new private window, to prevent
// regular browsing data from leaking into it.