[tor-bugs] #18913 [Applications/Torbutton]: about:tor should not have chrome privileges
Tor Bug Tracker & Wiki
blackhole at torproject.org
Wed Apr 27 14:45:20 UTC 2016
#18913: about:tor should not have chrome privileges
----------------------------------------+-----------------
Reporter: mcs | Owner: mcs
Type: defect | Status: new
Priority: Medium | Milestone:
Component: Applications/Torbutton | Version:
Severity: Normal | Keywords:
Actual Points: | Parent ID:
Points: | Reviewer:
Sponsor: |
----------------------------------------+-----------------
We should ensure that about:tor runs with only content privileges.
Changing the getURIFlags() function in src/components/aboutTor.js to
include {{{Ci.nsIAboutModule.URI_SAFE_FOR_UNTRUSTED_CONTENT}}} in the
value returned should do the trick, but other things will need to be fixed
as a result of that change.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/18913>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list