Closed
Bug 13024
Opened 25 years ago
Closed 25 years ago
Disable XUL download
Categories
(Core :: Networking, defect, P3)
Tracking
()
VERIFIED
INVALID
M13
People
(Reporter: norrisboyd, Assigned: norrisboyd)
Details
We need to disable the ability to download XUL files to prevent a host of
security exploits. See 10725 and 11457 for examples.
Updated•25 years ago
|
Assignee: gagan → rpotts
Summary: Disable XUL download → Disable XUL download
Target Milestone: M14
Comment 1•25 years ago
|
||
This doesn't seem like a necko issue. Maybe the docloader or something.
Assignee | ||
Comment 2•25 years ago
|
||
Followup on warren's comment above: are you the right owner for this?
This is required for beta. M14 is too late.
Assignee | ||
Comment 3•25 years ago
|
||
cc'ing jevering as per our meeting today
Bulk move of all Necko (to be deleted component) bugs to new Networking
component.
Comment 5•25 years ago
|
||
Moving Rick's M14 bugs to M13 (since he won't be here for M14). He can triage
them to M15 as appropriate.
Updated•25 years ago
|
Assignee: rpotts → norris
Comment 6•25 years ago
|
||
I don't see where the networking library can do anything about this. It has to
be dealt with at a higher level. Maybe the docshell.
Assignee | ||
Updated•25 years ago
|
Status: NEW → RESOLVED
Closed: 25 years ago
Resolution: --- → INVALID
Assignee | ||
Comment 7•25 years ago
|
||
I think we can now allow XUL download. XUL files that don't come from chrome:
URIs don't have any special privileges.
Comment 8•25 years ago
|
||
Verified invalid.
You need to log in
before you can comment on or make changes to this bug.
Description
•