gecko-dev/dom/security
Frederik Braun d7310ca214 Bug 1543579 - Disallow SystemPrincipal for Remote documents on all channels r=ckerschb,tjr
Differential Revision: https://phabricator.services.mozilla.com/D54091

--HG--
extra : moz-landing-system : lando
2019-12-02 10:45:23 +00:00
..
featurepolicy Backed out 2 changesets (bug 1598470, bug 1595720) for causing browser_fullscreen_cross_origin.js to permafail CLOSED TREE 2019-12-02 12:55:37 +02:00
fuzztest Bug 1560455 - rename CodebasePrincipal to ContentPrincipal. r=ckerschb 2019-07-08 16:37:45 +00:00
test Bug 1543579 - Disallow SystemPrincipal for Remote documents on all channels r=ckerschb,tjr 2019-12-02 10:45:23 +00:00
CSPEvalChecker.cpp Bug 1583949 - Add a check for IsEvalAllowed to the worker callpath for eval() r=ckerschb,baku 2019-10-08 17:31:35 +00:00
CSPEvalChecker.h
DOMSecurityManager.cpp Bug 1599843 - DOMSecurityManager::EnforeXFrameOptionsCheck is infallible. r=baku 2019-11-27 20:51:37 +00:00
DOMSecurityManager.h Bug 1599843 - DOMSecurityManager::EnforeXFrameOptionsCheck is infallible. r=baku 2019-11-27 20:51:37 +00:00
FramingChecker.cpp Bug 1593832: Enforce XFO and frame-ancestors in parent process if fission is enabled and in content if running in regular mode until we can determine whether a load results in a download in the parent process. r=bzbarsky,jkt 2019-11-27 14:26:38 +00:00
FramingChecker.h Bug 1584998: Make x-frame-options work with fission enabled. r=jkt,farre,johannh,flod 2019-10-31 08:28:35 +00:00
PolicyTokenizer.cpp
PolicyTokenizer.h
ReferrerInfo.cpp Bug 1598647 - Set Origin to null with network.http.referer.hideOnionSource r=JuniorHsu 2019-11-25 13:29:47 +00:00
ReferrerInfo.h Bug 1591226 - Convert network.http.referer.XOriginTrimmingPolicy to static pref. r=njn 2019-10-25 04:55:12 +00:00
SRICheck.cpp
SRICheck.h
SRILogHelper.h
SRIMetadata.cpp
SRIMetadata.h
moz.build Bug 1584993: Make CSP frame-ancestors work with fission enabled. r=jkt,farre,valentin 2019-10-22 10:57:43 +00:00
nsCSPContext.cpp Bug 1593832: Enforce XFO and frame-ancestors in parent process if fission is enabled and in content if running in regular mode until we can determine whether a load results in a download in the parent process. r=bzbarsky,jkt 2019-11-27 14:26:38 +00:00
nsCSPContext.h Bug 1580710: Expose functionality on the CSP Object to allow skipping the inline style checks. r=bzbarsky 2019-09-16 23:47:19 +00:00
nsCSPParser.cpp Bug 1529068 - Implementation of the navigate-to CSP directive as defined in CSP Level 3. r=ckerschb,mccr8 2019-09-10 22:33:51 +00:00
nsCSPParser.h Bug 1557793 part 2. Stop using [array] in nsIStringBundle. r=Pike 2019-06-11 15:51:51 +00:00
nsCSPService.cpp Bug 1583932 - Remove aRequestOrigin from nsCSPContext::ShouldLoad r=ckerschb 2019-09-30 10:38:32 +00:00
nsCSPService.h Bug 1583076 - Make nsCSPService::ConsultCSPForRedirect return both the AsyncOnChannelRedirect result, as well as an optional result to cancel the old channel with. r=ckerschb 2019-09-25 08:25:22 +00:00
nsCSPUtils.cpp Bug 1529068 - Implementation of the navigate-to CSP directive as defined in CSP Level 3. r=ckerschb,mccr8 2019-09-10 22:33:51 +00:00
nsCSPUtils.h Bug 1529068 - Implementation of the navigate-to CSP directive as defined in CSP Level 3. r=ckerschb,mccr8 2019-09-10 22:33:51 +00:00
nsContentSecurityManager.cpp Bug 1543579 - Disallow SystemPrincipal for Remote documents on all channels r=ckerschb,tjr 2019-12-02 10:45:23 +00:00
nsContentSecurityManager.h Bug 1543579 - Disallow SystemPrincipal for Remote documents on all channels r=ckerschb,tjr 2019-12-02 10:45:23 +00:00
nsContentSecurityUtils.cpp Backed out 11 changesets (bug 1582512) for causing valgrind bustages. 2019-11-20 18:44:45 +02:00
nsContentSecurityUtils.h Backed out 11 changesets (bug 1582512) for causing valgrind bustages. 2019-11-20 18:44:45 +02:00
nsMixedContentBlocker.cpp Bug 1585604 - Remove telemetry for mixed object subrequst counting. r=ckerschb 2019-10-02 11:17:28 +00:00
nsMixedContentBlocker.h Bug 1376309 - Allow localhost ws:// connections from secure origins. r=jkt 2019-08-07 00:19:59 +00:00