jonas@sicking.cc
|
641b42bbcf
|
Bug 397878: Send Referer-Root header when doing cross-site access requests. Also update domain pattern matching to spec. Patch by <suryaismail@gmail.com>. r=bent sr=sicking b3a=beltzner
|
2008-01-31 00:16:54 -08:00 |
jst@mozilla.org
|
73b6de93fa
|
Fixing bustage.
|
2008-01-29 13:11:24 -08:00 |
jst@mozilla.org
|
b8a6474030
|
Fixing bug 413767. Make caps use faster JS class/parent/private/proto accessors. r=mrbkap@gmail.com, sr=brendan@mozilla.org
|
2008-01-29 12:51:01 -08:00 |
jst@mozilla.org
|
0a1e95b8b6
|
Fixing bug 317240. Re-enabling caps optimization now that a documents principal never changes. r+sr=bzbarsky@mit.edu
|
2008-01-28 09:51:38 -08:00 |
jst@mozilla.org
|
dd9c7f529c
|
Fixing bug 412691. Remove unnecessary nsCOMPtr's from performance critical code paths. r+sr=jonas@sicking.cc
|
2008-01-16 16:32:26 -08:00 |
benjamin@smedbergs.us
|
a31eb73709
|
Bug 411327 - nsIXPCNativeCallContext should not inherit from nsISupports, r=mrbkap, a=schrep
|
2008-01-15 07:50:57 -08:00 |
dwitte@stanford.edu
|
ae0034832c
|
thoroughly whack mallocfest in nsID/nsJSID and friends. b=410250, r+sr=jst, a=blocking1.9+
|
2008-01-11 20:30:42 -08:00 |
dwitte@stanford.edu
|
6ba4acd13f
|
partial backout in an attempt to fix orange.
|
2008-01-11 02:08:58 -08:00 |
dwitte@stanford.edu
|
18cd35ef9d
|
relanding bug 410250.
|
2008-01-11 01:13:04 -08:00 |
dwitte@stanford.edu
|
d1d1599403
|
backing out to fix orange.
|
2008-01-10 20:59:44 -08:00 |
dwitte@stanford.edu
|
3aff67fa2b
|
thoroughly whack mallocfest in nsID/nsJSID and friends. b=410250, r+sr=jst, a=blocking1.9+
|
2008-01-10 19:56:00 -08:00 |
timeless@mozdev.org
|
6558516560
|
Bug 334306 useless null check in nsDestroyJSPrincipals r=dbaron sr=dveditz a=mtschrep
|
2008-01-06 06:53:24 -08:00 |
mrbkap@gmail.com
|
b46234fd91
|
Always throw an exception, even if we cannot reach a principal. bug 409514, r+sr+a=jst
|
2008-01-04 17:32:23 -08:00 |
jst@mozilla.org
|
6d7a04555f
|
Fixing bug 410851. Expose a faster way of getting the subject principal, and use that from performance critical code. r+sr=mrbkap@gmail.com
|
2008-01-04 15:59:12 -08:00 |
mrbkap@gmail.com
|
cb4075c49b
|
XPCNativeWrappers can confuse the short-circuiting code. bug 409291, r+sr=jst a=beltzner
|
2007-12-21 11:06:29 -08:00 |
jst@mozilla.org
|
69192344bd
|
Fixing bug 408009. Make doGetObjectPrincipal() faster. r+sr=bzbarsky@mit.edu, r+a=brendan@mozilla.org
|
2007-12-12 15:02:25 -08:00 |
philringnalda@gmail.com
|
59d7e63624
|
Bug 400247 - remove XP_MAC deadcode in nsScriptSecurityManager.cpp, r+sr=bz, a=dsicore
|
2007-11-12 19:23:17 -08:00 |
tglek@mozilla.com
|
8a32454ea9
|
Bug 398574:Prbool fixes r=bz a=release drivers
|
2007-11-12 13:47:11 -08:00 |
jonas@sicking.cc
|
ebee2dc0d9
|
bug 394390: Don't report bogus warnings to the error console when using cross-site xmlhttprequest. Patch by Surya Ismail <suryaismail@gmail.com>, r/sr=sicking
|
2007-10-26 18:46:09 -07:00 |
bzbarsky@mit.edu
|
a892964caa
|
Make the "href" property of stylesheets reflect the original URI that was reflected to load the sheet. Bug 397427, r=dbaron,biesi, sr=dbaron, a=dsicore
|
2007-10-23 14:56:41 -07:00 |
bzbarsky@mit.edu
|
926abc513f
|
Somewhat reduce the amount of memory an nsPrincipal allocates in the common case. Bug 397733, r+sr+a=jst
|
2007-09-28 07:31:04 -07:00 |
bzbarsky@mit.edu
|
1512235b94
|
Make the nsISerializable implementation of nsPrincipal actually work. This makes it possible to save principal objects to a stream and read them back. Bug 369566, r=dveditz+brendan, sr=jst, a=jst
|
2007-09-17 15:18:28 -07:00 |
dveditz@cruzio.com
|
482ae113d1
|
bugs 230606 and 209234: add options to restrict file: URI same-origin policies, r+sr=jst, blocking+=pavlov
|
2007-09-06 00:02:57 -07:00 |
bent.mozilla@gmail.com
|
c454f7fbdc
|
Bug 304048 - Backing out patch due to TXUL regression.
|
2007-08-30 17:52:58 -07:00 |
bent.mozilla@gmail.com
|
6388381ea1
|
Bug 304048 - "xpconnect getters/setters don't have principals until after they pass or fail their security check." Patch by jst, sr=bzbarsky, a=jst.
|
2007-08-28 17:16:21 -07:00 |
bzbarsky@mit.edu
|
6159525ebc
|
Add some sanity null-checks. Bug 387446, r=dveditz, sr+a=jst
|
2007-08-06 19:09:16 -07:00 |
sdwilsh@shawnwilsher.com
|
74c867f860
|
Bustage fix
|
2007-07-11 14:20:11 -07:00 |
jwalden@mit.edu
|
12e960c504
|
Bug 348748 - Replace all instances of NS_STATIC_CAST and friends with C++ casts (and simultaneously bitrot nearly every patch in existence). r=bsmedberg on the script that did this. Tune in next time for Macro Wars: Episode II: Attack on the LL_* Macros.
|
2007-07-08 00:08:04 -07:00 |
bzbarsky@mit.edu
|
2bbf042698
|
Make security manager API more useful from script. Make more things
scriptable, and add a scriptable method for testing whether a given principal
is the system principal. Bug 383783, r=dveditz, sr=jst
|
2007-06-18 08:12:09 -07:00 |
bzbarsky@mit.edu
|
7c3bde0a77
|
Optimize immutability of codebase/domain a little bit. Bug 380475, r=dveditz, sr=biesi
|
2007-06-18 08:07:02 -07:00 |
bzbarsky@mit.edu
|
0466d5d890
|
Make nsPrincipal::Equals compare codebases, not just certs, for certificate
principals. Bug 369201, r=dveditz, sr=jst
|
2007-06-18 08:01:53 -07:00 |
benjamin@smedbergs.us
|
0ab7558e7b
|
Bug 376636 - Building with gcc 4.3 and -pendatic fails due to extra semicolons, patch by Art Haas <ahaas@airmail.net>, rs=me
|
2007-04-23 07:21:53 -07:00 |
dbaron@dbaron.org
|
cb52af13a3
|
Remove GetKeyPointer method from nsTHashtable key types. b=374906 r=bsmedberg
|
2007-03-27 08:34:59 -07:00 |
dbaron@dbaron.org
|
4d961c5c49
|
Remove unused getKey callback from PLDHashTableOps/JSDHashTableOps. b=374906 r=bsmedberg
|
2007-03-27 08:33:38 -07:00 |
roc+@cs.cmu.edu
|
0054412272
|
Bug 374866. Reftests for text-transform. r=dbaron
|
2007-03-22 16:01:14 -07:00 |
jonas%sicking.cc
|
d7ad434701
|
Followup patch to bug 425201. Make sure to throw if xhr.open is called with an illegal uri. Also restore the nsIScriptSecurityManager.CheckConnect API as soap still uses it
|
2008-04-18 17:35:57 +00:00 |
gavin%gavinsharp.com
|
b5be6c4f09
|
Rework test for bug 292789 to try and fix the timeout on qm-centos5-01
|
2008-04-14 08:50:51 +00:00 |
dveditz%cruzio.com
|
afee2a207a
|
tests for bug 292789 -- forgot during checkin
|
2008-04-13 00:55:45 +00:00 |
dveditz%cruzio.com
|
c7990fae19
|
bug 292789 prevent use of chrome: URIs from <script>, <img> stylesheets, etc except for chrome packages explicitly marked contentaccessible. r=bzbarsky, sr=jst, a=beltzner
|
2008-04-12 21:26:19 +00:00 |
jonas%sicking.cc
|
2ec9134081
|
Bug 425201: Allow XMLHttpRequest and document.load load files from subdirectories. r/sr=dveditz
|
2008-04-09 00:38:13 +00:00 |
igor%mir2.org
|
acca7a06be
|
[bug 423874] backing out as a simpler patch would do the job with less code.
|
2008-03-29 10:34:31 +00:00 |
igor%mir2.org
|
b7c7e118a6
|
[bug 424376] backing out - too much compatibility problems.
|
2008-03-28 22:27:37 +00:00 |
bzbarsky%mit.edu
|
8f0b2235c2
|
Fix bug 421228. r+sr=sicking
|
2008-03-28 03:46:15 +00:00 |
igor%mir2.org
|
c819df158f
|
bug=424376 r=brendan a1.9b5=beltzner
Compile-time function objects are no longer exposed through SpiderMonkey API.
|
2008-03-23 10:16:40 +00:00 |
jst%mozilla.org
|
8b559ed068
|
Landing followup fix for bug 402983 and re-enabling the new stricter file URI security policies. r+sr=bzbarsky@mit.edu
|
2008-03-22 16:50:49 +00:00 |
igor%mir2.org
|
5ab7e29428
|
bug=423874 r=brendan a1.9b5=dsicore
Allocating native functions together with JSObject
|
2008-03-21 08:19:27 +00:00 |
jst%mozilla.org
|
f2a32b3bb6
|
Fixing orange from bug 402983. Make file:///foo and file:////foo#bar compare as equal URLs. r+sr=bzbarsky@mit.edu
|
2008-03-21 06:01:55 +00:00 |
jst%mozilla.org
|
7e76d85044
|
Landing fix for bug 402983. Make security checks on file:// URIs symmetric. Patch by dveditz@cruzio.com, r=jonas@sicking.cc,bzbarsky@mit.edu. jst@mozilla.org
|
2008-03-21 04:39:10 +00:00 |
shaver%mozilla.org
|
286f2705e5
|
Bug 246699: report better errors (with stacks) for security denials.
r+sr=jst, a=mconnor.
|
2008-03-20 08:19:15 +00:00 |
shaver%mozilla.org
|
6a50922c3f
|
Test for bug 423379 (content can load chrome and/or resource), r/sr=jst.
|
2008-03-19 22:14:52 +00:00 |