Ben Newman
|
17eeddcb85
|
Bug 460124. Remove no-longer-needed code, since now we calculate hash values for nsPrincipals in a sane way. r+sr=bzbarsky
|
2008-10-16 10:56:51 -04:00 |
|
Igor Bukanov
|
59702db0da
|
Bug 459656 - Implementing nsIThreadJSContextStack in nsXPConnect. r+sr=mrbkap
|
2008-10-14 16:16:25 +02:00 |
|
Arpad Borsos
|
8b11d938d2
|
Bug 456388 - Remove PR_STATIC_CALLBACK and PR_CALLBACK(_DECL) from the tree; r+sr=brendan
|
2008-10-10 17:04:34 +02:00 |
|
Blake Kaplan
|
64c490b3ef
|
Bug 457299 - nsScriptSecurityManager doesn't suspend the request on the current context when it starts using the safe context. r+sr=bzbarsky
|
2008-10-08 15:05:25 -07:00 |
|
Ben Newman
|
fdede899e6
|
Bug 454850. Make sure that whenever nsPrincipal::Equals would return true for a pair of principals their nsPrincipal::GetHashValue returns are also equal. r+sr=bzbarsky
|
2008-10-08 09:16:27 -04:00 |
|
David Bienvenu
|
aff330072d
|
bug 453943, always disable js for mailnews for 3.0 b1, don't load pref, r=bz, sr=dmose
|
2008-09-21 15:21:07 -07:00 |
|
David Bienvenu
|
4df8ee2c63
|
temporarily disable js in mailnews for 3.0 b1, r=bz, sr=dmose 453943
|
2008-09-20 08:14:14 -07:00 |
|
Arpad Borsos
|
9b6f558fee
|
Bug 398946 - Remove JS_STATIC_DLL_CALLBACK and JS_DLL_CALLBACK from the tree; r=(benjamin + bent.mozilla)
|
2008-09-07 00:21:43 +02:00 |
|
Ben Turner
|
cb1f4f55af
|
Bug 451731 - "Update caps, dom, xpconnect for Bug 451729 (checkObjectAccess moving to the JSContext)". r+sr=jst.
|
2008-09-05 16:26:04 -07:00 |
|
Ben Turner
|
b83ece5423
|
Bug 453720 - "Caps should assert when scripts do not contain principals". r+sr=mrbkap.
|
2008-09-04 15:52:20 -07:00 |
|
Jason Orendorff
|
b94820fbeb
|
Bug 451571 - Delete SetExceptionWasThrown (r=dbradley, sr=jst)
|
2008-08-30 18:58:36 -05:00 |
|
Honza Bambas
|
ec80dcba93
|
Bug 442812: Implement the application cache selection algorithm. r+sr=bz
|
2008-08-27 18:15:32 -07:00 |
|
Dave Camp
|
71de9a78fb
|
Backed out changeset 1e3d4775197a (bug 442812)
|
2008-08-19 22:52:05 -07:00 |
|
Honza Bambas
|
6b04323552
|
Bug 442812: Implement the application cache selection algorithm. r+sr=bz
|
2008-08-19 19:31:08 -07:00 |
|
Boris Zbarsky
|
9ec967babe
|
Bug 434522 follow-up bustage fix.
|
2008-07-28 23:37:58 -07:00 |
|
Boris Zbarsky
|
82e19a7db4
|
Bug 437723. Make sure to look at the nested innermost URI when looking for the origin. r+sr=sicking
|
2008-07-28 23:10:05 -07:00 |
|
Boris Zbarsky
|
563efe0fc5
|
Bug 434522. Make the "Permission denied to access Class.property" mesage more useful. r+sr=jst
|
2008-07-28 23:03:19 -07:00 |
|
jonas@sicking.cc
|
2558cdb12f
|
Followup patch to bug 425201. Make sure to throw if xhr.open is called with an illegal uri. Also restore the nsIScriptSecurityManager.CheckConnect API as soap still uses it
|
2008-04-18 10:35:55 -07:00 |
|
dveditz@cruzio.com
|
8689328ff5
|
bug 292789 prevent use of chrome: URIs from <script>, <img> stylesheets, etc except for chrome packages explicitly marked contentaccessible. r=bzbarsky, sr=jst, a=beltzner
|
2008-04-12 14:26:19 -07:00 |
|
jonas@sicking.cc
|
9b874a6992
|
Allow XMLHttpRequest and document.load load files from subdirectories. r/sr=dveditz
|
2008-04-08 17:38:12 -07:00 |
|
igor@mir2.org
|
c0d5c51190
|
[bug 423874] backing out as a simpler patch would do the job with less code.
|
2008-03-29 03:34:29 -07:00 |
|
igor@mir2.org
|
7598733582
|
[bug 424376] backing out - too much compatibility problems.
|
2008-03-28 15:27:36 -07:00 |
|
bzbarsky@mit.edu
|
2db2275e45
|
Fix bug 421228. r+sr=sicking
|
2008-03-27 20:46:15 -07:00 |
|
igor@mir2.org
|
51dcc8a464
|
bug=424376 r=brendan a1.9b5=beltzner Compile-time function objects are no longer exposed through SpiderMonkey API.
|
2008-03-23 03:16:40 -07:00 |
|
igor@mir2.org
|
eaa513c2f5
|
bug=423874 r=brendan a1.9b5=dsicore Allocating native functions together with JSObject
|
2008-03-21 01:19:23 -07:00 |
|
jst@mozilla.org
|
8b8c02a394
|
Fixing orange from bug 402983. Make file:///foo and file:////foo#bar compare as equal URLs. r+sr=bzbarsky@mit.edu
|
2008-03-20 23:01:55 -07:00 |
|
jst@mozilla.org
|
89acfcbf1a
|
Landing fix for bug 402983. Make security checks on file:// URIs symmetric. Patch by dveditz@cruzio.com, r=jonas@sicking.cc,bzbarsky@mit.edu. jst@mozilla.org
|
2008-03-20 21:39:08 -07:00 |
|
shaver@mozilla.org
|
dfe9ba8c69
|
Bug 246699: report better errors (with stacks) for security denials. r+sr=jst, a=mconnor.
|
2008-03-20 01:19:15 -07:00 |
|
jonas@sicking.cc
|
21fb00611b
|
Bug 413161: Make nsIPrincipal::Origin ignore changes to document.domain. r/sr=dveditz
|
2008-03-18 17:27:56 -07:00 |
|
bzbarsky@mit.edu
|
5383803699
|
Finally kill off CheckSameOriginPrincipal, fix remaining callers to do the checks they really want to be doing. Fix screw-up in nsPrincipal::Equals if one principal has a cert and the other does not. Bug 418996, r=mrbkap,dveditz, sr=jst
|
2008-03-18 14:14:49 -07:00 |
|
gavin@gavinsharp.com
|
b468aa6f00
|
Back out bug 246699 to fix bug 423375, per shaver
|
2008-03-17 07:10:48 -07:00 |
|
timeless@mozdev.org
|
7b35ecf9cb
|
Bug 246699 CAPS security exceptions should throw richer exception info (not just raw string) r=shaver a=shaver
|
2008-03-11 10:30:23 -07:00 |
|
jonas@sicking.cc
|
65f4571f58
|
Bug 416534: Clean up cross-site xmlhttprequest security checks. With fixes to tests this time. r/sr=peterv
|
2008-02-26 19:45:29 -08:00 |
|
myk@mozilla.org
|
b5e898ddd7
|
backing out fix for bug 416534 as potential cause of mochitest failure
|
2008-02-26 19:23:36 -08:00 |
|
jonas@sicking.cc
|
84548acb75
|
Bug 416534: Clean up cross-site xmlhttprequest security checks. r/sr=peterv
|
2008-02-26 18:17:49 -08:00 |
|
Olli.Pettay@helsinki.fi
|
67622f2077
|
Bug 411054, Audit IsNativeAnonymous()/GetBindingParent() uses, r+sr=sicking
|
2008-02-26 04:40:18 -08:00 |
|
jonas@sicking.cc
|
ba446696ec
|
Bug 397878: Send Referer-Root header when doing cross-site access requests. Also update domain pattern matching to spec. Patch by <suryaismail@gmail.com>. r=bent sr=sicking b3a=beltzner
|
2008-01-31 00:16:54 -08:00 |
|
jst@mozilla.org
|
85f3006178
|
Fixing bustage.
|
2008-01-29 13:11:24 -08:00 |
|
jst@mozilla.org
|
6ecbc04940
|
Fixing bug 413767. Make caps use faster JS class/parent/private/proto accessors. r=mrbkap@gmail.com, sr=brendan@mozilla.org
|
2008-01-29 12:51:01 -08:00 |
|
jst@mozilla.org
|
a2481a1918
|
Fixing bug 317240. Re-enabling caps optimization now that a documents principal never changes. r+sr=bzbarsky@mit.edu
|
2008-01-28 09:51:38 -08:00 |
|
jst@mozilla.org
|
0b7afd6193
|
Fixing bug 412691. Remove unnecessary nsCOMPtr's from performance critical code paths. r+sr=jonas@sicking.cc
|
2008-01-16 16:32:26 -08:00 |
|
benjamin@smedbergs.us
|
dfc4cee45d
|
Bug 411327 - nsIXPCNativeCallContext should not inherit from nsISupports, r=mrbkap, a=schrep
|
2008-01-15 07:50:57 -08:00 |
|
dwitte@stanford.edu
|
97a45f037f
|
thoroughly whack mallocfest in nsID/nsJSID and friends. b=410250, r+sr=jst, a=blocking1.9+
|
2008-01-11 20:30:42 -08:00 |
|
dwitte@stanford.edu
|
9d626da131
|
partial backout in an attempt to fix orange.
|
2008-01-11 02:08:58 -08:00 |
|
dwitte@stanford.edu
|
8a6c4d235f
|
relanding bug 410250.
|
2008-01-11 01:13:04 -08:00 |
|
dwitte@stanford.edu
|
d2b6f4f5ed
|
backing out to fix orange.
|
2008-01-10 20:59:44 -08:00 |
|
dwitte@stanford.edu
|
1798542e9f
|
thoroughly whack mallocfest in nsID/nsJSID and friends. b=410250, r+sr=jst, a=blocking1.9+
|
2008-01-10 19:56:00 -08:00 |
|
mrbkap@gmail.com
|
32601361e2
|
Always throw an exception, even if we cannot reach a principal. bug 409514, r+sr+a=jst
|
2008-01-04 17:32:23 -08:00 |
|
jst@mozilla.org
|
41ea116da8
|
Fixing bug 410851. Expose a faster way of getting the subject principal, and use that from performance critical code. r+sr=mrbkap@gmail.com
|
2008-01-04 15:59:12 -08:00 |
|
mrbkap@gmail.com
|
ca0549b22f
|
XPCNativeWrappers can confuse the short-circuiting code. bug 409291, r+sr=jst a=beltzner
|
2007-12-21 11:06:29 -08:00 |
|
jst@mozilla.org
|
17c85fe694
|
Fixing bug 408009. Make doGetObjectPrincipal() faster. r+sr=bzbarsky@mit.edu, r+a=brendan@mozilla.org
|
2007-12-12 15:02:25 -08:00 |
|
philringnalda@gmail.com
|
2970c7f3be
|
Bug 400247 - remove XP_MAC deadcode in nsScriptSecurityManager.cpp, r+sr=bz, a=dsicore
|
2007-11-12 19:23:17 -08:00 |
|
tglek@mozilla.com
|
9c6d7f11a1
|
Bug 398574:Prbool fixes r=bz a=release drivers
|
2007-11-12 13:47:11 -08:00 |
|
jonas@sicking.cc
|
903acf3ee6
|
bug 394390: Don't report bogus warnings to the error console when using cross-site xmlhttprequest. Patch by Surya Ismail <suryaismail@gmail.com>, r/sr=sicking
|
2007-10-26 18:46:09 -07:00 |
|
bzbarsky@mit.edu
|
06f6b88b65
|
Make the "href" property of stylesheets reflect the original URI that was reflected to load the sheet. Bug 397427, r=dbaron,biesi, sr=dbaron, a=dsicore
|
2007-10-23 14:56:41 -07:00 |
|
dveditz@cruzio.com
|
8877000696
|
bugs 230606 and 209234: add options to restrict file: URI same-origin policies, r+sr=jst, blocking+=pavlov
|
2007-09-06 00:02:57 -07:00 |
|
bent.mozilla@gmail.com
|
fd28607fdf
|
Bug 304048 - Backing out patch due to TXUL regression.
|
2007-08-30 17:52:58 -07:00 |
|
bent.mozilla@gmail.com
|
dea35a2d77
|
Bug 304048 - "xpconnect getters/setters don't have principals until after they pass or fail their security check." Patch by jst, sr=bzbarsky, a=jst.
|
2007-08-28 17:16:21 -07:00 |
|
bzbarsky@mit.edu
|
3aad27711a
|
Add some sanity null-checks. Bug 387446, r=dveditz, sr+a=jst
|
2007-08-06 19:09:16 -07:00 |
|
jwalden@mit.edu
|
e3c4baccae
|
Bug 348748 - Replace all instances of NS_STATIC_CAST and friends with C++ casts (and simultaneously bitrot nearly every patch in existence). r=bsmedberg on the script that did this. Tune in next time for Macro Wars: Episode II: Attack on the LL_* Macros.
|
2007-07-08 00:08:04 -07:00 |
|
bzbarsky@mit.edu
|
5eafaa49e5
|
Make security manager API more useful from script. Make more things
scriptable, and add a scriptable method for testing whether a given principal
is the system principal. Bug 383783, r=dveditz, sr=jst
|
2007-06-18 08:12:09 -07:00 |
|
hg@mozilla.com
|
465265d0d4
|
Free the (distributed) Lizard! Automatic merge from CVS: Module mozilla: tag HG_REPO_INITIAL_IMPORT at 22 Mar 2007 10:30 PDT,
|
2007-03-22 10:30:00 -07:00 |
|