gecko-dev/dom/security
Malte Juergens 84aacf5dbe Bug 1858565 - Make HTTPS-Only/First handle Superfluos Auth correctly r=freddyb,necko-reviewers,valentin
- Introduce new error `NS_ERROR_SUPERFLUOS_AUTH`
- Make `nsHttpChannelAuthProvider::CheckForSuperfluousAuth` return that new error instead of `NS_ERROR_ABORT`
- If `CheckForSuperfluosAuth` fails, set the status of the http channel to the rv of `CheckForSuperfluosAuth` (this should always be the newly introduced error)
- Add the new error code  to `nsHTTPSOnlyUtils::HttpsUpgradeUnrelatedErrorCode` to make sure HTTPS-Only/First will not think that the request failed

Differential Revision: https://phabricator.services.mozilla.com/D191276
2023-11-06 09:48:48 +00:00
..
featurepolicy Bug 1855296 - convert .ini manifests to .toml: batch 9 dom/[m-s]**/mochitest.ini r=jmaher,media-playback-reviewers,alwu 2023-10-03 19:35:22 +00:00
fuzztest
sanitizer Bug 1858673 - Remove now unnecessary disabling of ESLint no-unsanitized/* rules from test files. r=freddyb,media-playback-reviewers,credential-management-reviewers,devtools-reviewers,sessionstore-reviewers,places-reviewers,aosmond,sgalich,dao,padenot 2023-10-24 08:48:41 +00:00
test Bug 1858565 - Make HTTPS-Only/First handle Superfluos Auth correctly r=freddyb,necko-reviewers,valentin 2023-11-06 09:48:48 +00:00
CSPEvalChecker.cpp
CSPEvalChecker.h
DOMSecurityMonitor.cpp Bug 1824589 - Convert toolkit/components/narrate to ES modules. r=Gijs 2023-03-27 16:06:59 +00:00
DOMSecurityMonitor.h
FramingChecker.cpp Bug 1659763 - Fix failing x-frame-options web platform tests; r=freddyb,necko-reviewers,valentin 2023-06-26 11:58:47 +00:00
FramingChecker.h Bug 1659763 - Fix failing x-frame-options web platform tests; r=freddyb,necko-reviewers,valentin 2023-06-26 11:58:47 +00:00
PolicyTokenizer.cpp
PolicyTokenizer.h
ReferrerInfo.cpp Bug 1622090 - Implement loading=lazy for <iframe> r=emilio 2023-10-18 14:13:29 +00:00
ReferrerInfo.h Bug 1622090 - Implement loading=lazy for <iframe> r=emilio 2023-10-18 14:13:29 +00:00
SRICheck.cpp Bug 1409200 - Implement CSP-3 support for hashes matching external resources with an integrity attribute. r=freddyb 2023-06-09 18:40:00 +00:00
SRICheck.h Bug 1409200 - Implement CSP-3 support for hashes matching external resources with an integrity attribute. r=freddyb 2023-06-09 18:40:00 +00:00
SRILogHelper.h
SRIMetadata.cpp
SRIMetadata.h
SecFetch.cpp Bug 1819592 - Don't set Sec- headers for system requests. r=freddyb,ckerschb 2023-07-23 10:49:31 +00:00
SecFetch.h
moz.build
nsCSPContext.cpp Bug 1624819 - Remove TaskCategory and other quantum dom remnants. r=smaug,media-playback-reviewers,credential-management-reviewers,cookie-reviewers,places-reviewers,win-reviewers,valentin,mhowell,sgalich,alwu 2023-10-10 08:51:12 +00:00
nsCSPContext.h Bug 1839165 - Throttle the number of CSP reports that are send. r=freddyb 2023-07-24 11:11:58 +00:00
nsCSPParser.cpp Bug 1851802 - Make mixed content upgrade for audio/video/image individually togglable. r=freddyb 2023-09-13 11:27:12 +00:00
nsCSPParser.h Bug 1645745 - Suppress CSP parser errors/warnings in certain cases. r=freddyb 2022-12-19 11:52:45 +00:00
nsCSPService.cpp Backed out changeset 117114b8eb32 (bug 1793560) for causing wpt failures at iframe-all-local-schemes-inherit-self.sub.html CLOSED TREE 2023-07-10 17:54:12 +03:00
nsCSPService.h
nsCSPUtils.cpp Bug 1313937 - CSP: Logging improvements. r=ckerschb 2023-07-24 13:38:25 +00:00
nsCSPUtils.h Bug 1313937 - CSP: Remove aParserCreated. r=freddyb 2023-07-21 17:28:03 +00:00
nsContentSecurityManager.cpp Bug 1722322 - Fix two bugs in nsContentSecurityManager::GetSerializedOrigin r=necko-reviewers,dragana 2023-11-02 20:53:35 +00:00
nsContentSecurityManager.h Bug 1691658 - block http redirects to data: protocol, r=necko-reviewers,ckerschb,valentin 2023-04-12 09:43:00 +00:00
nsContentSecurityUtils.cpp Bug 1840892: Expand the potential crashing behavior to Early Beta as well r=freddyb 2023-10-16 13:36:49 +00:00
nsContentSecurityUtils.h Bug 1629307 - prevent auth prompts (status 401) if XFO checks fails. r=necko-reviewers,valentin,ckerschb 2023-02-15 17:27:46 +00:00
nsHTTPSOnlyStreamListener.cpp Bug 1838183: Include HTTPS-First in current HTTPS-Only exemption options on site identity pane r=freddyb,fluent-reviewers 2023-07-11 11:07:24 +00:00
nsHTTPSOnlyStreamListener.h
nsHTTPSOnlyUtils.cpp Bug 1858565 - Make HTTPS-Only/First handle Superfluos Auth correctly r=freddyb,necko-reviewers,valentin 2023-11-06 09:48:48 +00:00
nsHTTPSOnlyUtils.h Bug 1839612: HTTPS-First: Clear HTTPS_ONLY_EXEMPT on every load r=necko-reviewers,freddyb,kershaw 2023-07-11 11:07:24 +00:00
nsIHttpsOnlyModePermission.idl
nsMixedContentBlocker.cpp Bug 1801501 - Check if rootDoc is secure context for web compat; r=ckerschb 2023-09-27 18:19:23 +00:00
nsMixedContentBlocker.h Bug 1851802 - Make mixed content upgrade for audio/video/image individually togglable. r=freddyb 2023-09-13 11:27:12 +00:00