Opened 2 months ago

Last modified 6 weeks ago

#34209 merge_ready defect

about:tor and about:tbupdate fail to load in debug build of Tor Browser

Reported by: mcs Owned by: mcs
Priority: Medium Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: TorBrowserTeam202006R
Cc: tbb-team Actual Points:
Parent ID: #33533 Points:
Reviewer: acat Sponsor: Sponsor58-can

Description

When using a debug build based on acat's 33533+5 branch, trying to open about:tor or about:tbupdate leads to an assertion failure and a tab crash:

Assertion failure: foundObjectSrc (about: page must contain a CSP denying object-src), at /.../dom/security/nsContentSecurityUtils.cpp:818

We need to add object-src 'none' to the CSP for those pages.

Child Tickets

Change History (6)

comment:1 Changed 2 months ago by mcs

Parent ID: #33533

comment:2 Changed 2 months ago by mcs

Keywords: TorBrowserTeam202005R added; TorBrowserTeam202005 removed
Status: assignedneeds_review

comment:3 Changed 2 months ago by acat

Looks good and works for me.

comment:4 Changed 8 weeks ago by acat

Status: needs_reviewmerge_ready

comment:5 Changed 8 weeks ago by acat

Reviewer: acat

comment:6 Changed 6 weeks ago by gk

Keywords: TorBrowserTeam202006R added; TorBrowserTeam202005R removed

Moving review tickets.

Note: See TracTickets for help on using tickets.