#1 Mark some about: URIs as trusted

باز‌کردن
8 سال پیش باز شده توسط platform · 1 دیدگاه

Currently the extension considers all about: URIs as untrusted. This breaks Clean Uninstall which depends on about:addons being able to access resource: URIs. However, some about: URIs are indeed untrusted:

  • about:blank
  • about:srcdoc

And since WHATWG may add a new Web-accessible about: URI to their standards, we want to use whitelisting, rather than blacklisting.

Currently the extension considers all `about:` URIs as untrusted. This breaks [Clean Uninstall](https://addons.mozilla.org/en-US/firefox/addon/clean-uninstall/) which depends on `about:addons` being able to access resource: URIs. However, some about: URIs are indeed untrusted: * `about:blank` * `about:srcdoc` And since WHATWG may add a new Web-accessible `about:` URI to their standards, we want to use whitelisting, rather than blacklisting.
platform نظر 8 سال پیش
مالک
* Whitelisted: `about:addons` https://addons.mozilla.org/en-US/firefox/addon/no-resource-uri-leak/versions/0.2.0
برای پیوستن به گفتگو، وارد شودید.
بدون نقطه عطف
بدون مسئول رسیدگی
1 مشارکت کننده
درحال بارگذاری...
لغو
ذخيره
هنوز محتوایی ایجاد نشده.