Shadow
c318657acd
Explicitly use javascript: instead of URI_INHERITS_SECURITY_CONTEXT within subjectToCSP() ( #2696 )
...
Bug 1330035
Reviewed-on: https://repo.palemoon.org/MoonchildProductions/UXP/pulls/2696
Co-authored-by: Shadow <shadow@no-reply.palemoon.org>
Co-committed-by: Shadow <shadow@no-reply.palemoon.org>
2025-03-12 10:31:54 +08:00
Shadow
a2c6127832
No Issue - Make nsCSPService cancel the channel if a redirect is blocked by CSP
...
Bug 1338304
2025-03-12 10:31:37 +08:00
Moonchild
c41c1c63d5
[DOM] Honor security.csp.reporting.enabled pref in more places.
2025-02-18 19:11:24 +08:00
Moonchild
fffe6c4996
Issue #2542 - Part 7: Move SecFetch.* to /netwerk where it belongs.
2024-07-10 14:49:06 +08:00
Moonchild
53149ed646
Issue #2542 - Part 6: Add Sec-Fetch-User header for all requests that are the direct result of a system principal request.
...
This means navigation resulting from interaction with the browser UI
should result in a -user header (address bar navigation, bookmarks, etc.)
2024-07-10 14:48:35 +08:00
Moonchild
0ef8b05101
Issue #2542 - Part 5: Assume browser-initiated requests for unspecified content types to always be user-triggered.
2024-07-10 14:48:15 +08:00
Moonchild
9846090a38
Issue #2542 - Part 4b: Fix pointer mess-up.
2024-07-10 14:47:58 +08:00
Moonchild
65a588ba17
Issue #2542 - Part 4: Use BasePrincipal's IsSameOrigin() in SecFetch.
2024-07-10 14:47:20 +08:00
Moonchild
8ee9e3bc52
Issue #2542 - Part 2b: Fix typo in pref check
2024-07-10 14:46:36 +08:00
Moonchild
8076de8965
Issue #2542 - Part 2: Base implementation of Sec-Fetch-* header code.
...
Currently following Mozilla putting stuff in /dom for additional porting,
but it's actually the wrong location since it belongs in /netwerk with
the other code that deals with http headers.
2024-07-10 14:45:39 +08:00
Moonchild
1f4b858be2
Issue #2542 - Part 1b: Fix dom.securecontext.whitelist code issues
...
Some minor bugfixes (wrong condition and string type)
2024-07-10 14:44:56 +08:00
Moonchild
0c71a6ada0
Issue #2542 - Part 1: Factor out Potentially Trustworthy URI checks.
...
For sake of ease of use, converted to boolean functions that just assume "false"
in case of errors.
Note: Mozilla makes special arrangements for .onion addresses as well but
we explicitly do not adopt that. TOR browser can do that all day if it wants.
2024-07-10 14:44:37 +08:00
Moonchild
721ded9b48
Issue #2466 - Part 3: Implement style-src-elem and style-src-attr
2024-02-08 14:33:59 +08:00
Moonchild
ff01a35bdb
Issue #2466 - Part 2: Implement script-src-elem and script-src-attr
2024-02-08 14:33:43 +08:00
Moonchild
4ea2206c15
Issue #2466 - Part 1: Reduce nsContentPolicy type usage.
...
Use CSPDirective instead, since it directly deals with CSP anyway.
This cleanup prepares for the following changes.
2024-02-08 14:33:28 +08:00
Brian Smith
b842a1937a
Issue #2402 - Fill in column in CSP Report.
2024-01-11 09:51:07 +08:00
Brian Smith
e21d466d13
Issue #2402 - Print Related JS-Line on CSP Violation (if any). https://bugzilla.mozilla.org/show_bug.cgi?id=1100630
2024-01-11 09:50:49 +08:00
Brian Smith
5b068f3726
Issue #2402 - CSP Violation events should have the correct sample for inline contexts. https://bugzilla.mozilla.org/show_bug.cgi?id=1473587 Add preference to increase max length of CSP report source sample. https://bugzilla.mozilla.org/show_bug.cgi?id=1415352 Return valid columnNumber value in CSP violation events. https://bugzilla.mozilla.org/show_bug.cgi?id=1418246
2024-01-11 09:50:12 +08:00
Brian Smith
e74612e23e
Issue #2402 - Workers.setTimeout/setInterval must handle CSP rejections. https://bugzilla.mozilla.org/show_bug.cgi?id=1490165 Has some namespace issues adding the files, so differs slightly.
2024-01-11 09:47:22 +08:00
Brian Smith
9cd8aafeaa
Issue #2402 - CSP violation: blockedURI inline/eval. https://bugzilla.mozilla.org/show_bug.cgi?id=1418241 CSP: Blocked URI should be empty for inline violations. https://bugzilla.mozilla.org/show_bug.cgi?id=1236222
2024-01-11 09:46:53 +08:00
Brian Smith
6979441734
Issue #2402 - importScripts should be governed by script-src in Web Workers. https://bugzilla.mozilla.org/show_bug.cgi?id=1322111 Add TYPE_INTERNAL_WORKER_IMPORT_SCRIPTS content policy. Update the Cache API schema to account for new nsIContentPolicy type.
2024-01-11 09:45:52 +08:00
Brian Smith
1e0851158e
Issue #2402 - Fix SecurityPolicyViolationEvent.violatedDirective. https://bugzilla.mozilla.org/show_bug.cgi?id=1418243
2024-01-11 09:43:27 +08:00
Brian Smith
ec29404083
Issue #2402 - Implement security policy violation event. https://bugzilla.mozilla.org/show_bug.cgi?id=1037335
2024-01-11 09:43:10 +08:00
Brian Smith
1349cf2d01
Issue #2402 - Remove child-src deprecation warning. https://bugzilla.mozilla.org/show_bug.cgi?id=1486331
2024-01-11 09:42:51 +08:00
Brian Smith
bfabbcd311
Issue #2402 - Ignore empty CSP directives. https://bugzilla.mozilla.org/show_bug.cgi?id=1439425
2024-01-11 09:42:36 +08:00
Moonchild
f1f9dde29e
Issue #2405 - Add a pref to disable CSP reporting.
...
Resolves #2405
2023-12-21 10:15:17 +08:00
Moonchild
71ce058b03
[DOM] Check if rootDoc is secure context for web compat
2023-11-24 17:04:52 +08:00
Moonchild
95120acbb2
[DOM security] Be more explicit about CSP checks and reports.
2022-09-22 10:18:33 +08:00
Moonchild
5dfded811d
Issue #80 - reinstated unified building for some large chunks of our code.
...
This should reduce compile complexity saving time and reducing linker stress.
2022-09-07 10:36:23 +08:00
Moonchild
3caca43d30
Issue #1710 - Check for triggering principal URI in FTP subresource check.
...
Resolves #1710
2021-01-14 22:19:17 +08:00
Moonchild
0cd673d720
Issue #1656 - Part 6: Clean up the build files
2020-09-25 22:04:23 +08:00
Moonchild
ed7e49eda6
Issue #1656 - Part 2: Unmangle some unfortunate UTF-8 victims.
...
The poor fellows got lost in an ASCII-interpretation of the world.
2020-09-25 22:04:14 +08:00
Moonchild
8c395520d9
Issue #1656 - Part 1: Nuke most vim config lines in the tree.
...
Since these are just interpreted comments, there's 0 impact on actual code.
This removes all lines that match /* vim: set(.*)tw=80: */ with S&R -- there are
a few others scattered around which will be removed manually in a second part.
2020-09-25 22:04:12 +08:00
Moonchild
b6d9a013c8
Issue #80 - De-unify dom/security
...
Exception: CSPUtils relies on something in CSPContext, but on
Windows it throws in an MSVC include which provides no hints.
2020-05-02 08:25:00 +08:00
wolfbeast
2537698cd2
[CSP] Allow not having a Port for RessourceURI if the Scheme has no
...
Default Port
2020-02-13 07:17:36 +08:00
wolfbeast
c2fafd67b0
Fix whitelisting of JavaScript-uris by CSP hash.
2019-09-06 23:50:03 +08:00
Sebastian Streich
3f25eeefaf
Add checks to respect CSP-wildcard + Ports.
2019-09-06 23:49:53 +08:00
win7-7
e6f376f5ef
Convert dom/base/nsImageLoadingContent.cpp to use AsyncOpen2 and followups along with it (1445670 and 1373780 part 2 and 3)
...
Convert dom/base/nsImageLoadingContent.cpp to use AsyncOpen2 and followups along with it (1445670 and 1373780 part 2 and 3)
2019-08-10 06:26:08 +08:00
wolfbeast
e4273a3c58
Selectively allow ftp subresources in the blocked mode.
...
- Allow "Save As..." downloads
- Allow subresource use if the top-level document is also on FTP
2019-07-19 10:03:19 +08:00
wolfbeast
797f3eae35
Add preference to allow the loading of FTP subresources for corner cases
2019-07-19 10:03:17 +08:00
wolfbeast
59ee48bfb0
Prevent loading of document subresources over FTP.
2019-03-16 07:01:31 +08:00
adeshkp
aea50f182f
Telemetry: Remove stubs and related code
2019-02-16 00:24:04 +08:00
Gaming4JC
30797d4da8
backport mozbug 1334776 - CVE-2017-7797 Header name interning leaks across origins
...
Potential attack: session supercookie.
[Moz Notes](https://bugzilla.mozilla.org/show_bug.cgi?id=1334776#c5 ):
"The problem is that for unknown header names we store the first one we see and then later we case-insensitively match against that name *globally*. That means you can track if a user agent has already seen a certain header name used (by using a different casing and observing whether it gets normalized). This would allow you to see if a user has used a sensitive service that uses custom header names, or allows you to track a user across sites, by teaching the browser about a certain header case once and then observing if different casings get normalized to that.
What we should do instead is only store the casing for a header name for each header list and not globally. That way it only leaks where it's expected (and necessary) to leak."
[Moz fix note](https://bugzilla.mozilla.org/show_bug.cgi?id=1334776#c8 ):
"nsHttpAtom now holds the old nsHttpAtom and a string that is case sensitive (only for not standard headers).
So nsHttpAtom holds a pointer to a header name. (header names are store on a static structure). This is how it used to be. I left that part the same but added a nsCString which holds a string that was used to resoled the header name. So when we parse headers we call ResolveHeader with a char*. If it is a new header name the char* will be stored in a HttpHeapAtom, nsHttpAtom::_val will point to HttpHeapAtom::value and the same strings will be stored in mLocalCaseSensitiveHeader. For the first resolve request they will be the same but for the following maybe not. At the end this nsHttpAtom will be stored in nsHttpHeaderArray. For all operation we will used the old char* except when we are returning it to a script using VisitHeaders."
2019-02-16 00:14:28 +08:00
wolfbeast
8c8145e620
Remove all C++ Telemetry Accumulation calls.
...
This creates a number of stubs and leaves some surrounding code that may be irrelevant (eg. recorded time stamps, status variables).
Stub resolution/removal should be a follow-up to this.
2019-02-16 00:12:32 +08:00
janekptacijarabaci
df880ae53f
nsIContentPolicy::TYPE_DOCUMENT - Use "aLoadInfo->ContextForTopLevelLoad()" instead of "aLoadInfo->LoadingNode()"
...
Issue #600
2019-02-16 00:07:41 +08:00
janekptacijarabaci
53c39834e6
Bug 1469150 - CSP: Scripts with valid nonce get blocked if URL redirects is fixed (follow up)
2019-02-16 00:04:37 +08:00
janekptacijarabaci
a6d927b167
Bug 1469150 - Tests added to check scripts with valid nonce is allowed if URL redirects (follow up)
2019-02-16 00:04:36 +08:00
janekptacijarabaci
c8131a687a
Bug 1469150 - CSP: Scripts with valid nonce get blocked if URL redirects
...
https://bugzilla.mozilla.org/show_bug.cgi?id=1469150
2019-02-16 00:04:34 +08:00
janekptacijarabaci
9578e970f0
Bug 1430758 - No CSP directive for nsIContentPolicy::TYPE_SAVEAS_DOWNLOAD
2019-02-16 00:03:19 +08:00
janekptacijarabaci
97c6ecff55
Bug 1398229 - Save-link-as feature should use the loading principal - implementation of nsIContentPolicy.TYPE_SAVE_AS_DOWNLOAD
2019-02-16 00:03:18 +08:00