Moonchild
95120acbb2
[DOM security] Be more explicit about CSP checks and reports.
2022-09-22 10:18:33 +08:00
Moonchild
5dfded811d
Issue #80 - reinstated unified building for some large chunks of our code.
...
This should reduce compile complexity saving time and reducing linker stress.
2022-09-07 10:36:23 +08:00
Moonchild
3caca43d30
Issue #1710 - Check for triggering principal URI in FTP subresource check.
...
Resolves #1710
2021-01-14 22:19:17 +08:00
Moonchild
0cd673d720
Issue #1656 - Part 6: Clean up the build files
2020-09-25 22:04:23 +08:00
Moonchild
ed7e49eda6
Issue #1656 - Part 2: Unmangle some unfortunate UTF-8 victims.
...
The poor fellows got lost in an ASCII-interpretation of the world.
2020-09-25 22:04:14 +08:00
Moonchild
8c395520d9
Issue #1656 - Part 1: Nuke most vim config lines in the tree.
...
Since these are just interpreted comments, there's 0 impact on actual code.
This removes all lines that match /* vim: set(.*)tw=80: */ with S&R -- there are
a few others scattered around which will be removed manually in a second part.
2020-09-25 22:04:12 +08:00
Moonchild
b6d9a013c8
Issue #80 - De-unify dom/security
...
Exception: CSPUtils relies on something in CSPContext, but on
Windows it throws in an MSVC include which provides no hints.
2020-05-02 08:25:00 +08:00
wolfbeast
2537698cd2
[CSP] Allow not having a Port for RessourceURI if the Scheme has no
...
Default Port
2020-02-13 07:17:36 +08:00
wolfbeast
c2fafd67b0
Fix whitelisting of JavaScript-uris by CSP hash.
2019-09-06 23:50:03 +08:00
Sebastian Streich
3f25eeefaf
Add checks to respect CSP-wildcard + Ports.
2019-09-06 23:49:53 +08:00
win7-7
e6f376f5ef
Convert dom/base/nsImageLoadingContent.cpp to use AsyncOpen2 and followups along with it (1445670 and 1373780 part 2 and 3)
...
Convert dom/base/nsImageLoadingContent.cpp to use AsyncOpen2 and followups along with it (1445670 and 1373780 part 2 and 3)
2019-08-10 06:26:08 +08:00
wolfbeast
e4273a3c58
Selectively allow ftp subresources in the blocked mode.
...
- Allow "Save As..." downloads
- Allow subresource use if the top-level document is also on FTP
2019-07-19 10:03:19 +08:00
wolfbeast
797f3eae35
Add preference to allow the loading of FTP subresources for corner cases
2019-07-19 10:03:17 +08:00
wolfbeast
59ee48bfb0
Prevent loading of document subresources over FTP.
2019-03-16 07:01:31 +08:00
adeshkp
aea50f182f
Telemetry: Remove stubs and related code
2019-02-16 00:24:04 +08:00
Gaming4JC
30797d4da8
backport mozbug 1334776 - CVE-2017-7797 Header name interning leaks across origins
...
Potential attack: session supercookie.
[Moz Notes](https://bugzilla.mozilla.org/show_bug.cgi?id=1334776#c5 ):
"The problem is that for unknown header names we store the first one we see and then later we case-insensitively match against that name *globally*. That means you can track if a user agent has already seen a certain header name used (by using a different casing and observing whether it gets normalized). This would allow you to see if a user has used a sensitive service that uses custom header names, or allows you to track a user across sites, by teaching the browser about a certain header case once and then observing if different casings get normalized to that.
What we should do instead is only store the casing for a header name for each header list and not globally. That way it only leaks where it's expected (and necessary) to leak."
[Moz fix note](https://bugzilla.mozilla.org/show_bug.cgi?id=1334776#c8 ):
"nsHttpAtom now holds the old nsHttpAtom and a string that is case sensitive (only for not standard headers).
So nsHttpAtom holds a pointer to a header name. (header names are store on a static structure). This is how it used to be. I left that part the same but added a nsCString which holds a string that was used to resoled the header name. So when we parse headers we call ResolveHeader with a char*. If it is a new header name the char* will be stored in a HttpHeapAtom, nsHttpAtom::_val will point to HttpHeapAtom::value and the same strings will be stored in mLocalCaseSensitiveHeader. For the first resolve request they will be the same but for the following maybe not. At the end this nsHttpAtom will be stored in nsHttpHeaderArray. For all operation we will used the old char* except when we are returning it to a script using VisitHeaders."
2019-02-16 00:14:28 +08:00
wolfbeast
8c8145e620
Remove all C++ Telemetry Accumulation calls.
...
This creates a number of stubs and leaves some surrounding code that may be irrelevant (eg. recorded time stamps, status variables).
Stub resolution/removal should be a follow-up to this.
2019-02-16 00:12:32 +08:00
janekptacijarabaci
df880ae53f
nsIContentPolicy::TYPE_DOCUMENT - Use "aLoadInfo->ContextForTopLevelLoad()" instead of "aLoadInfo->LoadingNode()"
...
Issue #600
2019-02-16 00:07:41 +08:00
janekptacijarabaci
53c39834e6
Bug 1469150 - CSP: Scripts with valid nonce get blocked if URL redirects is fixed (follow up)
2019-02-16 00:04:37 +08:00
janekptacijarabaci
a6d927b167
Bug 1469150 - Tests added to check scripts with valid nonce is allowed if URL redirects (follow up)
2019-02-16 00:04:36 +08:00
janekptacijarabaci
c8131a687a
Bug 1469150 - CSP: Scripts with valid nonce get blocked if URL redirects
...
https://bugzilla.mozilla.org/show_bug.cgi?id=1469150
2019-02-16 00:04:34 +08:00
janekptacijarabaci
9578e970f0
Bug 1430758 - No CSP directive for nsIContentPolicy::TYPE_SAVEAS_DOWNLOAD
2019-02-16 00:03:19 +08:00
janekptacijarabaci
97c6ecff55
Bug 1398229 - Save-link-as feature should use the loading principal - implementation of nsIContentPolicy.TYPE_SAVE_AS_DOWNLOAD
2019-02-16 00:03:18 +08:00
Gaming4JC
d4ac94cf3e
Remove support and tests for HSTS priming from the tree. Fixes #384
2019-02-15 23:59:39 +08:00
wolfbeast
719ac1bc38
Remove MOZ_B2G leftovers and some dead B2G-only components.
2019-02-15 23:57:05 +08:00
janekptacijarabaci
69c0760b8b
Bug 1359204 - Do not query nested URI within CheckChannel in ContentSecurityManager
2019-02-15 23:54:50 +08:00
janekptacijarabaci
846daf6d3b
Bug 1182569: Update ContentSecurityManager to handle docshell loads
2019-02-15 23:54:22 +08:00
janekptacijarabaci
7f09dee539
moebius#187: DOM - nsIContentPolicy - context (document)
...
https://github.com/MoonchildProductions/moebius/pull/187
2019-02-15 23:49:47 +08:00
janekptacijarabaci
850879535a
Revert "Bug 1182569: Update ContentSecurityManager to handle docshell loads"
...
This reverts commit 2e33335820b2816bee111e78588ac82e401c86ae.
2019-02-15 23:49:44 +08:00
janekptacijarabaci
983926cce7
Bug 1182569: Update ContentSecurityManager to handle docshell loads
...
native in moebius
2019-02-15 23:49:30 +08:00
janekptacijarabaci
9e52126f1a
Bug 1329288: Allow content policy consumers to identify contentPolicy checks from docshell
2019-02-15 23:49:24 +08:00
janekptacijarabaci
79fb0b8506
Bug 1329288 - Test ContentPolicy blocks opening a new window
2019-02-15 23:49:23 +08:00
janekptacijarabaci
18d312235d
moebius#230: Consider blocking top level window data: URIs (part 3/3 without tests)
...
https://github.com/MoonchildProductions/moebius/pull/230
2019-02-15 23:49:20 +08:00
janekptacijarabaci
73f89fe562
moebius#226: Consider blocking top level window data: URIs (part 2/2 without tests)
...
https://github.com/MoonchildProductions/moebius/pull/226
2019-02-15 23:49:19 +08:00
janekptacijarabaci
712d19e1b7
moebius#223: Consider blocking top level window data: URIs (part 1/3 without tests)
...
https://github.com/MoonchildProductions/moebius/pull/223
2019-02-15 23:49:17 +08:00
janekptacijarabaci
8aa17f5b90
moebius#159: CSP - support for "frame-ancestors" in "Content-Security-Policy-Report-Only"
...
https://github.com/MoonchildProductions/moebius/pull/159
2019-02-15 23:45:38 +08:00
janekptacijarabaci
6509b677d3
Bug 1288768 - Better error reporting for network errors in workers
2019-02-15 23:42:47 +08:00
wolfbeast
0665a343a5
Add support for CSP v3 "worker-src" directive
2019-02-15 23:35:05 +08:00
janekptacijarabaci
96886141e1
CSP: connect-src 'self' should always include https: and wss: schemes
2019-02-15 23:33:23 +08:00
janekptacijarabaci
ee67abc801
CSP: Support IDNs in connect-src
2019-02-15 23:33:21 +08:00
janekptacijarabaci
7de286b67c
CSP: Ignore nonces on <img> per spec
2019-02-15 23:33:20 +08:00
janekptacijarabaci
54e7645cb6
CSP: Upgrade SO navigational requests per spec.
2019-02-15 23:33:18 +08:00
janekptacijarabaci
a01c9abce8
CSP 2 - ignore (x-)frame-options if CSP with frame-ancestors directive exists
2019-02-15 23:33:17 +08:00
wolfbeast
4923ad3b10
Explicitly cancel channel after mixed content redirect.
2019-02-15 23:30:31 +08:00
wolfbeast
fd1bb58ea8
CSP should only check host (not including path) when performing frame ancestors checks.
...
This has been explicitly stated in the CSP-3 spec.
2019-02-15 23:29:42 +08:00
Roy Tam
dcd9973243
import FIREFOX_52_6_0esr_RELEASE from mozilla-esr52 hg repo
2018-01-19 03:59:58 +08:00