gecko-dev/dom/security
Oliver Medhurst 465206f92c Bug 1793560 - Remove navigate-to CSP directive r=tschuster
It has never shipped after being implemented years ago,
and was removed from spec in September 2022:
https://github.com/w3c/webappsec-csp/pull/564

Now skipping navigate-to WPT tests. Filed issue upstream for their future removal:
https://github.com/w3c/webappsec-csp/issues/608
Consensus seems to agree to remove, will do in follow up bug once landed.

Also removed our own tests.

Added a hack in StartDocumentLoad as just removing the navigate-to check call
breaks some inhertiance, see comment for more info.

Differential Revision: https://phabricator.services.mozilla.com/D181630
2024-01-03 16:43:12 +00:00
..
featurepolicy Bug 1589554 - Part 6: Screen Wake Lock testing. r=webdriver-reviewers,webidl,dom-core,saschanaz,whimboo,edgar 2023-12-05 23:58:08 +00:00
fuzztest
sanitizer Bug 1864838 - Update sanitizer tests. r=freddyb 2023-11-28 11:04:03 +00:00
test Bug 1793560 - Remove navigate-to CSP directive r=tschuster 2024-01-03 16:43:12 +00:00
CSPEvalChecker.cpp Bug 1864168 - Part 2: Use 1-origin column number in nsJSUtils::GetCallingLocation. r=smaug,anti-tracking-reviewers,devtools-reviewers,ochameau,pbz 2023-11-22 12:31:31 +00:00
CSPEvalChecker.h
DOMSecurityMonitor.cpp Bug 1864168 - Part 2: Use 1-origin column number in nsJSUtils::GetCallingLocation. r=smaug,anti-tracking-reviewers,devtools-reviewers,ochameau,pbz 2023-11-22 12:31:31 +00:00
DOMSecurityMonitor.h
FramingChecker.cpp Bug 1659763 - Fix failing x-frame-options web platform tests; r=freddyb,necko-reviewers,valentin 2023-06-26 11:58:47 +00:00
FramingChecker.h Bug 1659763 - Fix failing x-frame-options web platform tests; r=freddyb,necko-reviewers,valentin 2023-06-26 11:58:47 +00:00
PolicyTokenizer.cpp
PolicyTokenizer.h
ReferrerInfo.cpp Bug 1622090 - Implement loading=lazy for <iframe> r=emilio 2023-10-18 14:13:29 +00:00
ReferrerInfo.h Bug 1622090 - Implement loading=lazy for <iframe> r=emilio 2023-10-18 14:13:29 +00:00
SRICheck.cpp Bug 1409200 - Implement CSP-3 support for hashes matching external resources with an integrity attribute. r=freddyb 2023-06-09 18:40:00 +00:00
SRICheck.h Bug 1409200 - Implement CSP-3 support for hashes matching external resources with an integrity attribute. r=freddyb 2023-06-09 18:40:00 +00:00
SRILogHelper.h
SRIMetadata.cpp
SRIMetadata.h
SecFetch.cpp Bug 1819592 - Don't set Sec- headers for system requests. r=freddyb,ckerschb 2023-07-23 10:49:31 +00:00
SecFetch.h
moz.build
nsCSPContext.cpp Bug 1793560 - Remove navigate-to CSP directive r=tschuster 2024-01-03 16:43:12 +00:00
nsCSPContext.h Bug 1793560 - Remove navigate-to CSP directive r=tschuster 2024-01-03 16:43:12 +00:00
nsCSPParser.cpp Bug 1793560 - Remove navigate-to CSP directive r=tschuster 2024-01-03 16:43:12 +00:00
nsCSPParser.h
nsCSPService.cpp Bug 1793560 - Remove navigate-to CSP directive r=tschuster 2024-01-03 16:43:12 +00:00
nsCSPService.h
nsCSPUtils.cpp Bug 1793560 - Remove navigate-to CSP directive r=tschuster 2024-01-03 16:43:12 +00:00
nsCSPUtils.h Bug 1793560 - Remove navigate-to CSP directive r=tschuster 2024-01-03 16:43:12 +00:00
nsContentSecurityManager.cpp Bug 1871581 - Add missing (but implicitly used) ExtContentPolicy::TYPE_WEB_IDENTITY. r=necko-reviewers,jesup 2024-01-03 10:54:12 +00:00
nsContentSecurityManager.h Bug 1691658 - block http redirects to data: protocol, r=necko-reviewers,ckerschb,valentin 2023-04-12 09:43:00 +00:00
nsContentSecurityUtils.cpp Bug 1864168 - Part 2: Use 1-origin column number in nsJSUtils::GetCallingLocation. r=smaug,anti-tracking-reviewers,devtools-reviewers,ochameau,pbz 2023-11-22 12:31:31 +00:00
nsContentSecurityUtils.h Bug 1629307 - prevent auth prompts (status 401) if XFO checks fails. r=necko-reviewers,valentin,ckerschb 2023-02-15 17:27:46 +00:00
nsHTTPSOnlyStreamListener.cpp Bug 1871581 - Add missing (but implicitly used) ExtContentPolicy::TYPE_WEB_IDENTITY. r=necko-reviewers,jesup 2024-01-03 10:54:12 +00:00
nsHTTPSOnlyStreamListener.h
nsHTTPSOnlyUtils.cpp Bug 1859576 - Try to log HTTPS-Only/First messages to triggering window of loadinfo if inner window does not exist yet r=freddyb 2023-11-06 09:49:08 +00:00
nsHTTPSOnlyUtils.h Bug 1839612: HTTPS-First: Clear HTTPS_ONLY_EXEMPT on every load r=necko-reviewers,freddyb,kershaw 2023-07-11 11:07:24 +00:00
nsIHttpsOnlyModePermission.idl
nsMixedContentBlocker.cpp Bug 1871581 - Add missing (but implicitly used) ExtContentPolicy::TYPE_WEB_IDENTITY. r=necko-reviewers,jesup 2024-01-03 10:54:12 +00:00
nsMixedContentBlocker.h Bug 1851802 - Make mixed content upgrade for audio/video/image individually togglable. r=freddyb 2023-09-13 11:27:12 +00:00