Page MenuHomePhabricator

Block use of "<base />" in the Content Security Policy
ClosedPublic

Authored by epriestley on Mar 1 2018, 2:54 AM.
Tags
None
Referenced Files
F15389000: D19158.diff
Sat, Mar 15, 4:48 AM
F15385356: D19158.id45894.diff
Fri, Mar 14, 10:20 PM
F15380622: D19158.diff
Fri, Mar 14, 3:53 AM
F15376252: D19158.id45894.diff
Thu, Mar 13, 2:29 AM
F15337020: D19158.diff
Sun, Mar 9, 3:39 AM
F15333964: D19158.diff
Sat, Mar 8, 5:57 AM
Unknown Object (File)
Wed, Feb 26, 7:46 AM
Unknown Object (File)
Sat, Feb 22, 3:14 PM
Subscribers
None

Details

Summary

Ref T4340. We don't use "<base />" so we can safely block it.

Test Plan

Injected "<base />" into a page, saw an error in the console showing that the browser had blocked it.

Diff Detail

Repository
rP Phabricator
Branch
csp6
Lint
Lint Passed
Unit
Tests Passed
Build Status
Buildable 19704
Build 26686: Run Core Tests
Build 26685: arc lint + arc unit

Event Timeline

This revision was not accepted when it landed; it landed in state Needs Review.Mar 1 2018, 2:55 AM
epriestley requested review of this revision.
This revision was automatically updated to reflect the committed changes.