334 Commits

Author SHA1 Message Date
Rob Wu
fff97f3ade Bug 1970075 - Relax img-src CSP in alert.xhtml + tests a=pascalc
Original Revision: https://phabricator.services.mozilla.com/D253561

Differential Revision: https://phabricator.services.mozilla.com/D253828
2025-07-02 12:21:49 +00:00
Fred Chasen
2c849fd24c Bug 1964835 - Part 3: Remove about:shoppingsidebar. r=shopping-reviewers,desktop-theme-reviewers,urlbar-reviewers,emilio,adw,kpatenio
Differential Revision: https://phabricator.services.mozilla.com/D248333
2025-05-22 18:04:27 +00:00
Tom Schuster
3f48655456 Bug 1967417 - Create a fallible LoadInfo factory. r=smaug,necko-reviewers,places-reviewers,kershaw
Differential Revision: https://phabricator.services.mozilla.com/D250182
2025-05-21 15:21:52 +00:00
Serban Stanca
071240c3d9 Revert "Bug 1967417 - Create a fallible LoadInfo factory. r=smaug,necko-reviewers,places-reviewers,kershaw" for causing multiple failures.
This reverts commit b9a9491a35.
2025-05-21 13:34:54 +00:00
Tom Schuster
b9a9491a35 Bug 1967417 - Create a fallible LoadInfo factory. r=smaug,necko-reviewers,places-reviewers,kershaw
Differential Revision: https://phabricator.services.mozilla.com/D250182
2025-05-21 12:24:10 +00:00
Nick Grato
f5dd74f34d Bug 1947198: show model details including name, purpose, usage, etc. r=rpl,fluent-reviewers,bolsson,Mardak
Adding addition data points to the detials view

Differential Revision: https://phabricator.services.mozilla.com/D247193
2025-05-14 04:16:11 +00:00
Narcis Beleuzu
a062ca7b42 Revert "Bug 1947198: show model details including name, purpose, usage, etc. r=rpl,fluent-reviewers,bolsson,Mardak" for causing mochitests failures in browser_extension_sideloading.js
This reverts commit 2113c93770.
2025-05-13 23:09:11 +00:00
Nick Grato
2113c93770 Bug 1947198: show model details including name, purpose, usage, etc. r=rpl,fluent-reviewers,bolsson,Mardak
Adding addition data points to the detials view

Differential Revision: https://phabricator.services.mozilla.com/D247193
2025-05-13 21:30:14 +00:00
Simon Friedberger
863f891de6 Bug 1960586: Remove testing exceptions for internal CSPs r=tschuster
Differential Revision: https://phabricator.services.mozilla.com/D246406
2025-04-24 09:16:53 +00:00
Tom Schuster
952381c40b Bug 1961592 - Allow data: images in webext-panels.xhtml. r=robwu
Differential Revision: https://phabricator.services.mozilla.com/D246223
2025-04-22 15:02:17 +00:00
Simon Friedberger
d7c4ef10ff Bug 1958801: Add CSP to geckoview.xhtml r=geckoview-reviewers,nalexander
Differential Revision: https://phabricator.services.mozilla.com/D245441
2025-04-17 20:44:26 +00:00
Stanca Serban
cb3237c607 Backed out changeset e51b81a587db (bug 1958801) for causing multiple Android failures. CLOSED TREE 2025-04-16 12:47:57 +03:00
Simon Friedberger
078d0745ed Bug 1958801: Add CSP to geckoview.xhtml r=geckoview-reviewers,nalexander
Differential Revision: https://phabricator.services.mozilla.com/D245441
2025-04-16 08:17:09 +00:00
Tom Schuster
9b5fbf703e Bug 1960359 - Add a CSP to changepassword.xhtml. r=simonf
Differential Revision: https://phabricator.services.mozilla.com/D245538
2025-04-16 07:09:13 +00:00
Simon Friedberger
00edc48f61 Bug 1958799: Add CSP to review-checker.xhtml r=tschuster,fchasen
Differential Revision: https://phabricator.services.mozilla.com/D244969
2025-04-15 05:37:46 +00:00
smolnar
012ee113e6 Backed out changeset 444a2f3a9e10 (bug 1958801) for causing reftest failures. CLOSED TREE 2025-04-15 01:10:59 +03:00
Simon Friedberger
239abe0cfc Bug 1958801: Add CSP to geckoview.xhtml r=geckoview-reviewers,nalexander
Differential Revision: https://phabricator.services.mozilla.com/D245441
2025-04-14 21:20:55 +00:00
Tom Schuster
0df57346c2 Bug 1960351 - Add a CSP to removemp.xhtml. r=simonf,settings-reviewers,Gijs
Differential Revision: https://phabricator.services.mozilla.com/D245426
2025-04-14 15:00:42 +00:00
Simon Friedberger
e3652e1e4d Bug 1958804: Add CSP to appPicker.xhtml r=tschuster,mossop
Differential Revision: https://phabricator.services.mozilla.com/D244837
2025-04-14 08:10:53 +00:00
Tom Schuster
a5e6ce2f4e Bug 1958232 - Allow eval in browser.xhtml and other priviliged contexts with a special pref. r=tjr
Differential Revision: https://phabricator.services.mozilla.com/D244306
2025-04-11 14:46:11 +00:00
Simon Friedberger
1b675b2aed Bug 1958802: Add CSP to alert.xhtml r=emilio
Differential Revision: https://phabricator.services.mozilla.com/D245073
2025-04-10 19:45:20 +00:00
Simon Friedberger
3eeac6b6e5 Bug 1958805. Add CSP to megalist.html r=tschuster,credential-management-reviewers,mtigley
Differential Revision: https://phabricator.services.mozilla.com/D244844
2025-04-09 14:47:31 +00:00
Tom Schuster
cdc567e2fc Bug 1958797 - Add a CSP to default-bookmarks.html. r=places-reviewers,Standard8
This seems to be only used as a data document, so we can use a very strict
CSP.

Differential Revision: https://phabricator.services.mozilla.com/D244916
2025-04-09 14:46:38 +00:00
Tom Schuster
357d0e78d6 Bug 1958798 - Actually apply the CSP in the interactions viewer. r=simonf,jteow
Differential Revision: https://phabricator.services.mozilla.com/D244889
2025-04-09 14:08:13 +00:00
Tom Schuster
5fdd3e29eb Bug 1957869 - Add a CSP to backgroundPageThumbs.xhtml. r=Gijs
I also replaced the usage of data: URLs for passing image data to
instead using ArrayBuffers. This removes an undeeded <img> load.

Differential Revision: https://phabricator.services.mozilla.com/D244134
2025-04-09 10:13:18 +00:00
Tom Schuster
221c0e04ef Bug 1803607 - Allow using https: hosts for connect-src in CSP validation r=simonf
Differential Revision: https://phabricator.services.mozilla.com/D243676
2025-04-09 10:04:12 +00:00
Tom Schuster
adea12eaba Bug 1956572 - Add a CSP to the extension HiddenXULWindow dummy.xhtml. r=extension-reviewers,robwu
We only seem to use this document to create <browser> elements. These
elements are not influnced by the CSP, so it should be fine to disallow
everything else.

Differential Revision: https://phabricator.services.mozilla.com/D243291
2025-04-08 16:12:00 +00:00
Tom Schuster
2545f263ae Bug 1955954 - Add a CSP to webext-panels.html. r=extension-reviewers,robwu
Differential Revision: https://phabricator.services.mozilla.com/D242724
2025-04-08 07:21:40 +00:00
Simon Friedberger
059d788a56 Bug 1956804. Remove CSP exception for selectDialog.xhtml r=tschuster
Differential Revision: https://phabricator.services.mozilla.com/D244343
2025-04-07 08:12:01 +00:00
Simon Friedberger
ba25883f84 Bug 1956801. Add CSP to win.xhtml r=mossop
Differential Revision: https://phabricator.services.mozilla.com/D243580
2025-04-03 10:04:57 +00:00
Simon Friedberger
c3f11a58b2 Bug 1956782. Add CSP to layoutdebug.xhtml r=emilio
Differential Revision: https://phabricator.services.mozilla.com/D243308
2025-04-03 10:04:56 +00:00
Tom Schuster
80bd058669 Bug 1957071 - Add a CSP to safeMode.xhtml. r=firefox-desktop-core-reviewers ,Gijs
Differential Revision: https://phabricator.services.mozilla.com/D243479
2025-04-01 13:53:37 +00:00
Tom Schuster
afe8db14f8 Bug 1953866 - Allow moz-src: by default in our CSPs for chrome:/resource: documents. r=simonf
Differential Revision: https://phabricator.services.mozilla.com/D242903
2025-03-31 13:42:37 +00:00
Tom Schuster
f29db34c67 Bug 1956277 - Add a CSP to webrtcIndicator.xhtml. r=mconley
Differential Revision: https://phabricator.services.mozilla.com/D243094
2025-03-31 07:55:03 +00:00
Simon Friedberger
1c040bac76 Bug 1955438. Add CSP to setp12password.xhtml r=tschuster
Depends on D242484

Differential Revision: https://phabricator.services.mozilla.com/D242485
2025-03-25 22:20:23 +00:00
Simon Friedberger
09106e88cb Bug 1954940. Add CSP to exceptionDialog.xhtml r=tschuster
Differential Revision: https://phabricator.services.mozilla.com/D242484
2025-03-25 22:20:23 +00:00
Tom Schuster
830653872b Bug 1950311 - Add CSP to devtool's webextension-fallback.html. r=devtools-reviewers,extension-reviewers,ochameau,robwu
Differential Revision: https://phabricator.services.mozilla.com/D242342
2025-03-24 17:36:39 +00:00
Tom Schuster
48b7f596bb Bug 1955926 - Stop loading a chrome: CSS file during testing as a document. r=firefox-desktop-core-reviewers ,Gijs
Differential Revision: https://phabricator.services.mozilla.com/D242704
2025-03-24 13:59:44 +00:00
Tom Schuster
885e81d9b1 Bug 1950311 - Don't load an internal SVG as a document during testing. r=devtools-reviewers,jdescottes
This is maybe a bit confusing. We allow SVGs to load as documents without a CSP that are part of the test suite, but not those that are a normal part of Firefox.

Differential Revision: https://phabricator.services.mozilla.com/D242571
2025-03-24 10:15:35 +00:00
Tom Schuster
ff5cf2172e Bug 1954773 - Explicitly include data: in additon to the wildcard in CSP sources for chrome: pages. r=simonf
Differential Revision: https://phabricator.services.mozilla.com/D242567
2025-03-24 09:54:09 +00:00
Goloman Adrian
7d7daf8766 Backed out 2 changesets (bug 1954940, bug 1955438) for causing bc failures @exceptionDialog.xhtml. CLOSED TREE
Backed out changeset cbf1b21a62af (bug 1955438)
Backed out changeset e77512e4c8fb (bug 1954940)
2025-03-24 11:54:54 +02:00
Simon Friedberger
7e9c3ea41f Bug 1955438. Add CSP to setp12password.xhtml r=tschuster
Differential Revision: https://phabricator.services.mozilla.com/D242485
2025-03-24 08:16:46 +00:00
Simon Friedberger
9b7d342ea0 Bug 1954940. Add CSP to exceptionDialog.xhtml r=tschuster
Differential Revision: https://phabricator.services.mozilla.com/D242484
2025-03-24 08:16:46 +00:00
Tom Schuster
60c67b2c5e Bug 1950311 - Add CSP to devtool's toolbox-window.xhtml. r=devtools-reviewers,bomsy
Differential Revision: https://phabricator.services.mozilla.com/D242302
2025-03-21 15:36:32 +00:00
Tom Schuster
3dbf8b9461 Bug 1950311 - Add CSP to devtool's browser-toolbox/window.html. r=devtools-reviewers,bomsy
Differential Revision: https://phabricator.services.mozilla.com/D242301
2025-03-21 15:36:32 +00:00
Tom Schuster
dfe30b186f Bug 1950311 - Add CSP to devtool's toolbox-options.html. r=devtools-reviewers,bomsy
Differential Revision: https://phabricator.services.mozilla.com/D242300
2025-03-21 15:36:32 +00:00
Simon Friedberger
800cf9b049 Bug 1954941. Add CSP to load_device.xhtml r=tschuster
Differential Revision: https://phabricator.services.mozilla.com/D242286
2025-03-21 07:35:19 +00:00
Simon Friedberger
6e778f18da Bug 1954939. Add CSP to editcacert.xhtml r=tschuster
Differential Revision: https://phabricator.services.mozilla.com/D242285
2025-03-20 15:30:10 +00:00
Simon Friedberger
dc32a811fb Bug 1954869. Add CSP to downloadcert.xhtml r=tschuster
Differential Revision: https://phabricator.services.mozilla.com/D242069
2025-03-19 16:44:45 +00:00
Simon Friedberger
7093ec86e9 Bug 1954868. Add CSP to device_manager.xhtml r=tschuster
Differential Revision: https://phabricator.services.mozilla.com/D242068
2025-03-19 16:44:44 +00:00