Commit Graph

319 Commits

Author SHA1 Message Date
smolnar
012ee113e6 Backed out changeset 444a2f3a9e10 (bug 1958801) for causing reftest failures. CLOSED TREE 2025-04-15 01:10:59 +03:00
Simon Friedberger
239abe0cfc Bug 1958801: Add CSP to geckoview.xhtml r=geckoview-reviewers,nalexander
Differential Revision: https://phabricator.services.mozilla.com/D245441
2025-04-14 21:20:55 +00:00
Tom Schuster
0df57346c2 Bug 1960351 - Add a CSP to removemp.xhtml. r=simonf,settings-reviewers,Gijs
Differential Revision: https://phabricator.services.mozilla.com/D245426
2025-04-14 15:00:42 +00:00
Simon Friedberger
e3652e1e4d Bug 1958804: Add CSP to appPicker.xhtml r=tschuster,mossop
Differential Revision: https://phabricator.services.mozilla.com/D244837
2025-04-14 08:10:53 +00:00
Tom Schuster
a5e6ce2f4e Bug 1958232 - Allow eval in browser.xhtml and other priviliged contexts with a special pref. r=tjr
Differential Revision: https://phabricator.services.mozilla.com/D244306
2025-04-11 14:46:11 +00:00
Simon Friedberger
1b675b2aed Bug 1958802: Add CSP to alert.xhtml r=emilio
Differential Revision: https://phabricator.services.mozilla.com/D245073
2025-04-10 19:45:20 +00:00
Simon Friedberger
3eeac6b6e5 Bug 1958805. Add CSP to megalist.html r=tschuster,credential-management-reviewers,mtigley
Differential Revision: https://phabricator.services.mozilla.com/D244844
2025-04-09 14:47:31 +00:00
Tom Schuster
cdc567e2fc Bug 1958797 - Add a CSP to default-bookmarks.html. r=places-reviewers,Standard8
This seems to be only used as a data document, so we can use a very strict
CSP.

Differential Revision: https://phabricator.services.mozilla.com/D244916
2025-04-09 14:46:38 +00:00
Tom Schuster
357d0e78d6 Bug 1958798 - Actually apply the CSP in the interactions viewer. r=simonf,jteow
Differential Revision: https://phabricator.services.mozilla.com/D244889
2025-04-09 14:08:13 +00:00
Tom Schuster
5fdd3e29eb Bug 1957869 - Add a CSP to backgroundPageThumbs.xhtml. r=Gijs
I also replaced the usage of data: URLs for passing image data to
instead using ArrayBuffers. This removes an undeeded <img> load.

Differential Revision: https://phabricator.services.mozilla.com/D244134
2025-04-09 10:13:18 +00:00
Tom Schuster
221c0e04ef Bug 1803607 - Allow using https: hosts for connect-src in CSP validation r=simonf
Differential Revision: https://phabricator.services.mozilla.com/D243676
2025-04-09 10:04:12 +00:00
Tom Schuster
adea12eaba Bug 1956572 - Add a CSP to the extension HiddenXULWindow dummy.xhtml. r=extension-reviewers,robwu
We only seem to use this document to create <browser> elements. These
elements are not influnced by the CSP, so it should be fine to disallow
everything else.

Differential Revision: https://phabricator.services.mozilla.com/D243291
2025-04-08 16:12:00 +00:00
Tom Schuster
2545f263ae Bug 1955954 - Add a CSP to webext-panels.html. r=extension-reviewers,robwu
Differential Revision: https://phabricator.services.mozilla.com/D242724
2025-04-08 07:21:40 +00:00
Simon Friedberger
059d788a56 Bug 1956804. Remove CSP exception for selectDialog.xhtml r=tschuster
Differential Revision: https://phabricator.services.mozilla.com/D244343
2025-04-07 08:12:01 +00:00
Simon Friedberger
ba25883f84 Bug 1956801. Add CSP to win.xhtml r=mossop
Differential Revision: https://phabricator.services.mozilla.com/D243580
2025-04-03 10:04:57 +00:00
Simon Friedberger
c3f11a58b2 Bug 1956782. Add CSP to layoutdebug.xhtml r=emilio
Differential Revision: https://phabricator.services.mozilla.com/D243308
2025-04-03 10:04:56 +00:00
Tom Schuster
80bd058669 Bug 1957071 - Add a CSP to safeMode.xhtml. r=firefox-desktop-core-reviewers ,Gijs
Differential Revision: https://phabricator.services.mozilla.com/D243479
2025-04-01 13:53:37 +00:00
Tom Schuster
afe8db14f8 Bug 1953866 - Allow moz-src: by default in our CSPs for chrome:/resource: documents. r=simonf
Differential Revision: https://phabricator.services.mozilla.com/D242903
2025-03-31 13:42:37 +00:00
Tom Schuster
f29db34c67 Bug 1956277 - Add a CSP to webrtcIndicator.xhtml. r=mconley
Differential Revision: https://phabricator.services.mozilla.com/D243094
2025-03-31 07:55:03 +00:00
Simon Friedberger
1c040bac76 Bug 1955438. Add CSP to setp12password.xhtml r=tschuster
Depends on D242484

Differential Revision: https://phabricator.services.mozilla.com/D242485
2025-03-25 22:20:23 +00:00
Simon Friedberger
09106e88cb Bug 1954940. Add CSP to exceptionDialog.xhtml r=tschuster
Differential Revision: https://phabricator.services.mozilla.com/D242484
2025-03-25 22:20:23 +00:00
Tom Schuster
830653872b Bug 1950311 - Add CSP to devtool's webextension-fallback.html. r=devtools-reviewers,extension-reviewers,ochameau,robwu
Differential Revision: https://phabricator.services.mozilla.com/D242342
2025-03-24 17:36:39 +00:00
Tom Schuster
48b7f596bb Bug 1955926 - Stop loading a chrome: CSS file during testing as a document. r=firefox-desktop-core-reviewers ,Gijs
Differential Revision: https://phabricator.services.mozilla.com/D242704
2025-03-24 13:59:44 +00:00
Tom Schuster
885e81d9b1 Bug 1950311 - Don't load an internal SVG as a document during testing. r=devtools-reviewers,jdescottes
This is maybe a bit confusing. We allow SVGs to load as documents without a CSP that are part of the test suite, but not those that are a normal part of Firefox.

Differential Revision: https://phabricator.services.mozilla.com/D242571
2025-03-24 10:15:35 +00:00
Tom Schuster
ff5cf2172e Bug 1954773 - Explicitly include data: in additon to the wildcard in CSP sources for chrome: pages. r=simonf
Differential Revision: https://phabricator.services.mozilla.com/D242567
2025-03-24 09:54:09 +00:00
Goloman Adrian
7d7daf8766 Backed out 2 changesets (bug 1954940, bug 1955438) for causing bc failures @exceptionDialog.xhtml. CLOSED TREE
Backed out changeset cbf1b21a62af (bug 1955438)
Backed out changeset e77512e4c8fb (bug 1954940)
2025-03-24 11:54:54 +02:00
Simon Friedberger
7e9c3ea41f Bug 1955438. Add CSP to setp12password.xhtml r=tschuster
Differential Revision: https://phabricator.services.mozilla.com/D242485
2025-03-24 08:16:46 +00:00
Simon Friedberger
9b7d342ea0 Bug 1954940. Add CSP to exceptionDialog.xhtml r=tschuster
Differential Revision: https://phabricator.services.mozilla.com/D242484
2025-03-24 08:16:46 +00:00
Tom Schuster
60c67b2c5e Bug 1950311 - Add CSP to devtool's toolbox-window.xhtml. r=devtools-reviewers,bomsy
Differential Revision: https://phabricator.services.mozilla.com/D242302
2025-03-21 15:36:32 +00:00
Tom Schuster
3dbf8b9461 Bug 1950311 - Add CSP to devtool's browser-toolbox/window.html. r=devtools-reviewers,bomsy
Differential Revision: https://phabricator.services.mozilla.com/D242301
2025-03-21 15:36:32 +00:00
Tom Schuster
dfe30b186f Bug 1950311 - Add CSP to devtool's toolbox-options.html. r=devtools-reviewers,bomsy
Differential Revision: https://phabricator.services.mozilla.com/D242300
2025-03-21 15:36:32 +00:00
Simon Friedberger
800cf9b049 Bug 1954941. Add CSP to load_device.xhtml r=tschuster
Differential Revision: https://phabricator.services.mozilla.com/D242286
2025-03-21 07:35:19 +00:00
Simon Friedberger
6e778f18da Bug 1954939. Add CSP to editcacert.xhtml r=tschuster
Differential Revision: https://phabricator.services.mozilla.com/D242285
2025-03-20 15:30:10 +00:00
Simon Friedberger
dc32a811fb Bug 1954869. Add CSP to downloadcert.xhtml r=tschuster
Differential Revision: https://phabricator.services.mozilla.com/D242069
2025-03-19 16:44:45 +00:00
Simon Friedberger
7093ec86e9 Bug 1954868. Add CSP to device_manager.xhtml r=tschuster
Differential Revision: https://phabricator.services.mozilla.com/D242068
2025-03-19 16:44:44 +00:00
Simon Friedberger
2c4e9ceddb Bug 1954850. Add CSP to deletecert.html r=tschuster
Differential Revision: https://phabricator.services.mozilla.com/D242067
2025-03-19 16:44:44 +00:00
Tom Schuster
0b7b527c3d Bug 1950311 - Add CSP to devtool's cmiframe.html. r=devtools-reviewers,nchevobbe
Differential Revision: https://phabricator.services.mozilla.com/D241620
2025-03-19 15:28:16 +00:00
Simon Friedberger
48f24beead Bug 1954507. Add CSP to clientauthask.xhtml r=tschuster
Differential Revision: https://phabricator.services.mozilla.com/D241836
2025-03-18 19:25:01 +00:00
Tom Schuster
d0c3021d3c Bug 1954706 - Allow inline styles in inspector/markup/markup.xhtml. r=devtools-reviewers,nchevobbe
Differential Revision: https://phabricator.services.mozilla.com/D241989
2025-03-18 14:56:17 +00:00
Simon Friedberger
a676799496 Bug 1953908. Add CSP to certManager.xhtml r=application-update-reviewers,bytesized
Differential Revision: https://phabricator.services.mozilla.com/D241619
2025-03-18 07:02:10 +00:00
Simon Friedberger
803a46a02e Bug 1953289. Add CSP to gfx sanity check files r=tschuster
Differential Revision: https://phabricator.services.mozilla.com/D241111
2025-03-18 06:53:13 +00:00
Simon Friedberger
28e06b1d69 Bug 1953816. Add CSP for updateElevation.xhtml r=tschuster,application-update-reviewers,bytesized
Differential Revision: https://phabricator.services.mozilla.com/D241617
2025-03-17 08:23:19 +00:00
Simon Friedberger
1f1b921d1d Bug 1950799. Remove eventhandler and add CSP for unknownContentType.xhtml r=tschuster,Gijs
Differential Revision: https://phabricator.services.mozilla.com/D239859
2025-03-13 12:52:25 +00:00
Stanca Serban
43e1bf3b83 Backed out changeset 831824b00936 (bug 1950799) for causing CSP related failures. CLOSED TREE 2025-03-13 12:58:59 +02:00
Simon Friedberger
a97ebf892b Bug 1950799. Remove eventhandler and add CSP for unknownContentType.xhtml r=tschuster,Gijs
Differential Revision: https://phabricator.services.mozilla.com/D239859
2025-03-13 09:07:10 +00:00
Tom Schuster
e8a8d4c104 Bug 1950311 - Add CSP to devtool's Performance tab. r=profiler-reviewers,canaltinova
Differential Revision: https://phabricator.services.mozilla.com/D241181
2025-03-13 07:29:13 +00:00
Simon Friedberger
013860c3ee Bug 1953583. Add CSP for history.xhtml r=application-update-reviewers,bytesized
Differential Revision: https://phabricator.services.mozilla.com/D241279
2025-03-12 20:05:26 +00:00
Tom Schuster
3b1674d412 Bug 1953374 - Improve the classification of userChromeJS files for telemetry (part 2). r=simonf
Differential Revision: https://phabricator.services.mozilla.com/D241165
2025-03-12 11:38:51 +00:00
Simon Friedberger
38a6b051ae Bug 1952930. Add CSP for createProfileWizard.xhtml r=tschuster,profiles-reviewers,mossop
Differential Revision: https://phabricator.services.mozilla.com/D240901
2025-03-12 11:13:06 +00:00
Simon Friedberger
072397e757 Bug 1953013. CSP for profile selection dialog r=tschuster,profiles-reviewers,mossop
Differential Revision: https://phabricator.services.mozilla.com/D241013
2025-03-12 11:13:06 +00:00