ssl written iframes are affected by about:blank permissions

Bug reports and enhancement requests
Post Reply
al_9x
Master Bug Buster
Posts: 931
Joined: Thu Mar 19, 2009 4:52 pm

ssl written iframes are affected by about:blank permissions

Post by al_9x »

A written iframe takes on the URL of the parent and should be allowed if the parent is allowed, and should not be affected by about:blank permissions.

NS 2.0.9.4rc1, Fx 3.6.13, new profile, remove (msn.com, about:blank) from the whitelist.
  1. login to https hotmail: https://mail.live.com/
  2. once you get to the inbox, you'll see that the two ad iframes (1 - lower left, 2 - right column) are untrusted. They both have the url of their parent (InboxLight.aspx), which is trusted.
  3. add about:blank back to the whitelist and refresh, the iframes now appear to be trusted
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
User avatar
Giorgio Maone
Site Admin
Posts: 9527
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: ssl written iframes are affected by about:blank permissi

Post by Giorgio Maone »

Investigating, thanks.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
al_9x
Master Bug Buster
Posts: 931
Joined: Thu Mar 19, 2009 4:52 pm

Re: ssl written iframes are affected by about:blank permissi

Post by al_9x »

Another example of this is on the Amazon homepage. The dynamically added (via DOM it seems) iframe should be allowed, since amazon.com is, but isn't Image when about:blank is not whitelisted.

This started in 2.0.9.2. Can you repro?
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
al_9x
Master Bug Buster
Posts: 931
Joined: Thu Mar 19, 2009 4:52 pm

Re: ssl written iframes are affected by about:blank permissi

Post by al_9x »

fixed in a latter build
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.14) Gecko/20110218 Firefox/3.6.14
Post Reply