Let Cross-Origin-Resource-Policy ride the trains
Categories
(Core :: DOM: Networking, task, P2)
Tracking
()
Tracking | Status | |
---|---|---|
firefox74 | --- | fixed |
People
(Reporter: annevk, Assigned: valentin)
References
Details
(Keywords: dev-doc-complete, Whiteboard: [necko-triaged])
Attachments
(2 files)
I think it would be good to let this ride the trains so we can remove browser.tabs.remote.useCORP
and reduce the number of features simultaneously in flight for "resab" somewhat.
What's needed:
- An intent to ship.
Guarding the "cross-origin" value behindbrowser.tabs.remote.useCrossOriginEmbedderPolicy
if that isn't the case already.- A follow-up bug to remove
browser.tabs.remote.useCORP
after 1 or 2 releases.
Valentin, is this something you'd be interested in? (If there are any reasons this hasn't shipped yet that I might not know about, please do let me know. I'm not entirely sure why this wasn't shipped directly.)
Assignee | ||
Comment 1•4 years ago
|
||
(In reply to Anne (:annevk) from comment #0)
Valentin, is this something you'd be interested in? (If there are any reasons this hasn't shipped yet that I might not know about, please do let me know. I'm not entirely sure why this wasn't shipped directly.)
I don't have time for it this week, and I go on PTO next week. If it's OK I can get on this on Jan 6th.
There aren't any blockers to this from what I know.
Reporter | ||
Comment 2•4 years ago
|
||
That seems fine to me, thanks!
Assignee | ||
Updated•4 years ago
|
Assignee | ||
Comment 3•4 years ago
|
||
(In reply to Anne (:annevk) from comment #0)
- Guarding the "cross-origin" value behind
browser.tabs.remote.useCrossOriginEmbedderPolicy
if that isn't the case already.
Uh, can you specify what you mean by this? Currently we do this
For cross-origin or null (or invalid content) we just let the request pass through (https://mikewest.github.io/corpp/#corp-check step 7)
Reporter | ||
Comment 4•4 years ago
|
||
Oh I see, I forgot how that was put together. Sorry! I've crossed out 2 in comment 0.
Assignee | ||
Comment 5•4 years ago
|
||
Assignee | ||
Comment 6•4 years ago
|
||
MDN needs to be updated to reflect that we're shipping this is Fx74
Pushed by valentin.gosu@gmail.com: https://hg.mozilla.org/integration/autoland/rev/79bce5e9d341 Let Cross-Origin-Resource-Policy ride the trains r=annevk
Comment 8•4 years ago
|
||
bugherder |
Assignee | ||
Comment 9•4 years ago
|
||
Comment 10•4 years ago
|
||
Pushed by valentin.gosu@gmail.com: https://hg.mozilla.org/integration/autoland/rev/e656a857b8c6 Also pref on Cross-Origin-Resource-Policy for Android r=annevk
Comment 11•4 years ago
|
||
bugherder |
Comment 12•4 years ago
|
||
https://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Releases/74#HTTP
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cross-Origin-Resource-Policy
Description
•