roytam1
1b648cc1d8
Merge remote-tracking branch 'origin/tracking' into custom
2024-09-13 10:04:42 +08:00
FranklinDM
2d60c54926
Issue #2578 - Part 2: Implement preference for disabling CORS preflight requests if CORS is disabled
2024-09-13 10:03:53 +08:00
roytam1
0d1cf674f0
Merge remote-tracking branch 'origin/tracking' into custom
2024-07-10 14:55:58 +08:00
Moonchild
d9ff917f15
Issue #2542 - Part 9: Remove TODO comment.
...
From our understanding of the spec, our current implementation is
feature-complete.
2024-07-10 14:49:39 +08:00
Moonchild
fffe6c4996
Issue #2542 - Part 7: Move SecFetch.* to /netwerk where it belongs.
2024-07-10 14:49:06 +08:00
Moonchild
8076de8965
Issue #2542 - Part 2: Base implementation of Sec-Fetch-* header code.
...
Currently following Mozilla putting stuff in /dom for additional porting,
but it's actually the wrong location since it belongs in /netwerk with
the other code that deals with http headers.
2024-07-10 14:45:39 +08:00
roytam1
bf385f38eb
UAO: add general.useragent.(change_)app_version
2024-07-09 17:02:32 +08:00
roytam1
f596e3d581
UAO: correct UA string rebuild code, add platform_version pref.
2024-07-09 14:08:03 +08:00
roytam1
f8c34e7c0a
network: follow-up rev 914569c0b (rework)
2024-07-09 11:35:15 +08:00
roytam1
b5d57ea4e7
Revert "network: follow-up rev 914569c0b"
...
This reverts commit a50a1db5a7 .
2024-07-09 11:27:32 +08:00
roytam1
a50a1db5a7
network: follow-up rev 914569c0b
2024-07-09 11:10:55 +08:00
roytam1
914569c0b9
network: UserAgent: add Platform Version override
2024-07-09 10:21:29 +08:00
roytam1
f8f3b3ee43
Merge remote-tracking branch 'origin/tracking' into custom
2024-05-22 15:26:11 +08:00
Moonchild
f3413e94b9
[network] Make http digest auth cnonce length configurable.
2024-05-22 15:20:46 +08:00
roytam1
552db66da0
Merge remote-tracking branch 'origin/tracking' into custom
2024-04-19 09:37:04 +08:00
Moonchild
1ddd3ea76b
[network] Keep track of and check HTTP/2 header sizes.
2024-04-19 09:34:14 +08:00
roytam1
b0345ff809
Merge remote-tracking branch 'origin/tracking' into custom
2024-01-18 10:17:09 +08:00
Moonchild
79b4c36ef8
Issue #2451 - Send referrer headers with CORS preflight requests.
...
This is dependent on referrer policy.
Fixes #2451
2024-01-18 10:04:42 +08:00
roytam1
80c4f1d745
Merge remote-tracking branch 'origin/tracking' into custom
2024-01-11 09:52:46 +08:00
Brian Smith
811bcbefd4
Issue #2402 - Optionally strictly enforce the MIME type of scripts loaded by importScripts(). https://bugzilla.mozilla.org/show_bug.cgi?id=1514680 This is default on in Firefox 67 but Moonchild requested it be set off by default.
2024-01-11 09:46:39 +08:00
roytam1
fa72b197d9
Merge remote-tracking branch 'origin/tracking' into custom
2024-01-05 10:11:42 +08:00
Martok
c451531d54
Issue #2430 - No longer force tcp send buffer size on HTTP/2 uploads > 128KB
...
With connection-level and stream-level flow control, it is not needed.
On fast connections with large-ish BWP, this can improve upload speed by > 5x
2024-01-05 10:11:19 +08:00
Martok
3e65ae353a
Issue #2430 - Allow network.http.spdy.chunk-size to be larger than 16K
...
According to https://datatracker.ietf.org/doc/html/rfc7540#section-4.2 The size of a frame payload is limited by the maximum size that a
receiver advertises in the SETTINGS_MAX_FRAME_SIZE setting. This
setting can have any value between 2^14 (16,384) and 2^24-1
(16,777,215) octets, inclusive.
2024-01-05 10:10:50 +08:00
roytam1
3039da2cb2
websocket: workaround of mSocketThread use-after-free when application is terminating
2023-12-27 19:18:18 +08:00
roytam1
5a362aa15b
Merge remote-tracking branch 'origin/tracking' into custom
2023-12-15 10:29:04 +08:00
Moonchild
f96001ba7c
No issue - Allow redirects for requests that require preflight
...
Spec update, see Bug 1312864
2023-12-15 09:07:32 +08:00
roytam1
ecd3cd8676
Merge remote-tracking branch 'origin/tracking' into custom
2023-10-18 11:48:06 +08:00
Moonchild
50ad087351
Issue #1721 - Implement GlobalPrivacyControl
...
(and get rid of failed DoNotTrack)
2023-10-18 10:17:23 +08:00
roytam1
ca9d8d3960
Merge remote-tracking branch 'origin/tracking' into custom
2023-10-18 10:03:32 +08:00
Moonchild
0315aeee73
Issue #1721 - Follow-up: Properly protect GPC header
...
Make it a singleton so it cannot be overwritten.
2023-10-18 09:54:42 +08:00
roytam1
ad0a69ae15
Merge remote-tracking branch 'origin/tracking' into custom
2023-09-28 11:51:45 +08:00
Moonchild
fb38f6d74e
[network] Refactor TransactionObserver::OnDataAvailable()
2023-09-28 11:51:24 +08:00
roytam1
92d9218cf1
Merge remote-tracking branch 'origin/tracking' into custom
2023-08-31 22:43:48 +08:00
Moonchild
613cd8f4cb
[network] Hold a strong ref to mChannel in OpenConn
2023-08-31 22:42:16 +08:00
Moonchild
058e936f62
[network] Add locking around access to WebSocketChannel::mPMCECompressor
2023-08-31 22:41:14 +08:00
roytam1
9f1550fb53
Merge remote-tracking branch 'origin/tracking' into custom
2023-07-06 10:39:29 +08:00
Moonchild
96d1e2766f
[network] Prepare for requiring Authorization in CORS ACAH preflight
...
The Authorization header with a JSON Web Token (JWT) can be sent via
XMLHttpRequest without explicit authorization via Access-Control headers.
According to the spec, this must always explicitly be mentioned in ACAH
request headers and isn't allowed to be wildcarded. However, nobody
currently obeys this rule and many websites are misconfigured because
Chromium and Firefox always allowed it.
This patch adds the more stricter code but keeps it behind an #ifdef 0
to be released later on if and when there is enough consensus on the web
to obey this spec. This patch explicitly avoids the added complexity
Mozilla added to educate web devs since our role in that respect is not
significant. it's not preffed and it won't throw an explicit deprecation
warning.
See Mozilla bugs 1687364 and 1841019.
2023-07-06 10:25:09 +08:00
roytam1
725b27a0f5
Merge remote-tracking branch 'origin/tracking' into custom
2023-05-05 23:02:05 +08:00
Moonchild
a39fd9e75f
Issue #1656 - Remove more vim control lines.
...
Vim control lines were re-introduced or not entirely cleaned up.
This nukes them again.
Removing from modules, netwerk, security, storage, testing, toolkit, and
a few scattered misc files. More to come.
2023-05-05 22:59:16 +08:00
roytam1
cad030d6cc
Merge remote-tracking branch 'origin/tracking' into custom
2023-01-19 09:43:10 +08:00
Moonchild
525b4e1888
[network] Avoid queue manipulation inside a loop
2023-01-19 09:40:35 +08:00
roytam1
120ac6d556
Merge remote-tracking branch 'origin/tracking' into custom
2022-12-30 09:29:56 +08:00
Moonchild
c95a802078
Issue #2070 - When multiple HSTS headers are received, only consider the first.
...
This implements a plain interpretations of RFC 6797, which says to only consider
the first HSTS header.
This slightly conflicts with RFC 7230, which says that sending multiple headers
which can't be merged is illegal (except for a specific whitelist which HSTS isn't in),
so this situation should never occur in the first place (and would therefore not need
the explicit entry in RFC 6797).
It improves HSTS robustness dealing with non-compliant servers.
Resolves #2070
2022-12-30 09:21:48 +08:00
roytam1
4ea078d68f
Merge remote-tracking branch 'origin/tracking' into custom
2022-12-16 11:25:59 +08:00
Moonchild
6a1e540412
[network] move some generic websocket code to the baseclass
2022-12-16 11:24:17 +08:00
roytam1
de0b4ac202
Merge remote-tracking branch 'origin/tracking' into custom
2022-11-25 11:46:08 +08:00
Moonchild
7fab5ebd11
WebSocketChannel::CleanupConnection should run on the socket thread
2022-11-25 11:42:30 +08:00
Moonchild
37f0199c79
[Network, DOM] Align our implementation with the current CORS/Fetch spec.
2022-11-25 11:41:52 +08:00
roytam1
f9dc0e6d15
Merge remote-tracking branch 'origin/tracking' into custom
2022-11-10 14:55:46 +08:00
Moonchild
0a079c2b90
Issue #2024 - Part 2: Add wildcard to Access-Control-Allow-{Method|Headers}
...
For requests without credentials, add wildcard to Access-Control-Allow-Headers
and Access-Control-Allow-Method.
Resolves #2024
2022-11-10 14:54:54 +08:00