зеркало из https://github.com/mozilla/gecko-dev.git
63b07e7115
The removal of the second CSP check is fixing a regression introduced in bug 965637. See https://github.com/whatwg/html/issues/4651#issuecomment-495050351 for details. We may want to re-introduce that check depending on the outcome of that issue, but if so we should do that only if the target document's principal subsumes our triggering principal. This commit will not allow bookmarklets to access subresources that CSP blocks, but will at least allow them to run. Differential Revision: https://phabricator.services.mozilla.com/D33047 --HG-- extra : moz-landing-system : lando |
||
---|---|---|
.. | ||
crashtests | ||
test | ||
moz.build | ||
nsJSProtocolHandler.cpp | ||
nsJSProtocolHandler.h |