Closed Bug 1527882 Opened 5 years ago Closed 5 years ago

Enable the blocking of external protocol URLs in iframes

Categories

(Core :: DOM: Core & HTML, enhancement, P2)

enhancement

Tracking

()

RESOLVED FIXED
mozilla67
Tracking Status
firefox67 --- fixed

People

(Reporter: baku, Assigned: baku)

References

(Regressed 1 open bug)

Details

(Keywords: dev-doc-complete, site-compat)

Attachments

(1 file)

dom.block_external_protocol_in_iframes is currently set to true only in nightly.
There are no reasons to block the shipping of this feature.

Priority: -- → P2
Pushed by amarchesini@mozilla.com:
https://hg.mozilla.org/integration/autoland/rev/bf504227f362
Enable the blocking of external protocol URLs in iframes, r=smaug
Status: NEW → RESOLVED
Closed: 5 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla67
Component: DOM → DOM: Core & HTML

Note to MDN writers: note added to Fx67 rel notes about this: https://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Releases/67#Security

In terms of other docs, you may want to consider adding BCD about this, or writing it up in a bit more detail on the <iframe> page.

I decided to just add a BCD data point for this: https://github.com/mdn/browser-compat-data/pull/4089

I think the docs are complete.

Regressions: 1563030
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: