TPE CONNECTIVITY GROUP/2015-Q2: Difference between revisions

Jump to navigation Jump to search
Line 11: Line 11:


== Engage with new security model priority: p1 ==  
== Engage with new security model priority: p1 ==  
# priority: p1
* priority: p1
# Fix service worker bugs
* Fix service worker bugs
# Fix CSP bugs
* Fix CSP bugs
## {{Bug|959388}} - CSP 1.1: Workers have their own CSP policies, should not inherit from parent document ('''in progress''')
*# {{Bug|959388}} - CSP 1.1: Workers have their own CSP policies, should not inherit from parent document ('''in progress''')
## {{Bug|881509}} - Content Security Policy ShouldLoad and ShouldProcess do not use request principal (blocks 959388)
*# {{Bug|881509}} - Content Security Policy ShouldLoad and ShouldProcess do not use request principal (blocks 959388)
## {{Bug|908933}} - CSP does not block cross-domain applets with object-src 'self
*# {{Bug|908933}} - CSP does not block cross-domain applets with object-src 'self
## {{Bug|1030936}} - [CSP] remove fast-path for certified apps once the C++ backend is activated
*# {{Bug|1030936}} - [CSP] remove fast-path for certified apps once the C++ backend is activated


# Fix same origin and cookie jars bugs
* Fix same origin and cookie jars bugs
## https://github.com/allstarschh/b2gSecurity/blob/master/origin.md
*# https://github.com/allstarschh/b2gSecurity/blob/master/origin.md
## Intro for the origin in new security model - http://bit.ly/1AbTqvQ
*# Intro for the origin in new security model - http://bit.ly/1AbTqvQ


== RTSP client/server refactor ==
== RTSP client/server refactor ==
Confirmed users
373

edits

Navigation menu