#1 Mark some about: URIs as trusted

Abierta
abierta hace 8 años por platform · 1 comentarios

Currently the extension considers all about: URIs as untrusted. This breaks Clean Uninstall which depends on about:addons being able to access resource: URIs. However, some about: URIs are indeed untrusted:

  • about:blank
  • about:srcdoc

And since WHATWG may add a new Web-accessible about: URI to their standards, we want to use whitelisting, rather than blacklisting.

Currently the extension considers all `about:` URIs as untrusted. This breaks [Clean Uninstall](https://addons.mozilla.org/en-US/firefox/addon/clean-uninstall/) which depends on `about:addons` being able to access resource: URIs. However, some about: URIs are indeed untrusted: * `about:blank` * `about:srcdoc` And since WHATWG may add a new Web-accessible `about:` URI to their standards, we want to use whitelisting, rather than blacklisting.
platform comentado hace 8 años
Propietario
* Whitelisted: `about:addons` https://addons.mozilla.org/en-US/firefox/addon/no-resource-uri-leak/versions/0.2.0
Inicie sesión para unirse a esta conversación.
Sin Milestone
Sin asignado
1 participantes
Cargando...
Cancelar
Guardar
Aún no existe contenido.