Opened 7 years ago

Closed 14 months ago

#9336 closed defect (fixed)

Odd wyswig schemes without isolation for

Reported by: mikeperry Owned by: tbb-team
Priority: High Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: tbb-linkability, tbb-firefox-patch, ff68-esr-will-have
Cc: mcs, brade, gk Actual Points:
Parent ID: Points:
Reviewer: Sponsor: Sponsor44-can

Description causes some odd urls to appear in about:cache without domain isolation.

We should investigate why these urls are not properly isolated, and perhaps where they come from.

Child Tickets

Change History (9)

comment:1 Changed 7 years ago by mcs

After loading, we see the following non-isolated entries (all with scheme wyciwyg):

wyciwyg://3/ (URL truncated)
wyciwyg://4/ (URL truncated)

The wyciwyg scheme is used to keep a copy of content that was modified by JS (probably to support the back button in the browser, etc.) That scheme is not supposed to be accessible by web pages, but isolation might be a good idea.

Mike, did you make the isolation changes for HTTP? The Mozilla file that needs to be patched is probably netwerk/protocol/wyciwyg/nsWyciwygChannel.cpp (see nsWyciwygChannel::OpenCacheEntry(), etc.)

comment:2 Changed 6 years ago by erinn

Keywords: tbb-firefox-patch added

comment:3 Changed 6 years ago by erinn

Component: Firefox Patch IssuesTor Browser
Owner: changed from mikeperry to tbb-team

comment:4 Changed 4 years ago by bugzilla

Severity: Normal

Nice ticket to add to Mozilla first-party isolation effort.

comment:5 Changed 3 years ago by cypherpunks

Seems Mozilla forgot about it:

Key 	Data size 	Fetch count 	Last Modifed 	Expires 	Pinning
wyciwyg://3/ 	1016 bytes 	1 	2017-05-23 15:35:35 	No expiration time 	 

comment:6 Changed 21 months ago by cypherpunks2

This is being used in the wild by a big ad network.

comment:7 Changed 20 months ago by gk

Keywords: ff68-esr-will-have added gets rid of the wyciwyg protocol handler.

comment:8 Changed 15 months ago by pili

Sponsor: Sponsor44-can

Adding Sponsor 44 to ESR68 tickets

comment:9 Changed 14 months ago by gk

Resolution: fixed
Status: newclosed

9.0a6, which is about to get built, is based on ESR 68, so closing.

Note: See TracTickets for help on using tickets.