Firefox 3.6/Personas Uplift Security Review: Difference between revisions

Line 57: Line 57:
** no: {{bug|486207}}, {{bug|520173}}
** no: {{bug|486207}}, {{bug|520173}}
* only allow permanently applying a theme at times when popups are allowed (e.g. on click)?
* only allow permanently applying a theme at times when popups are allowed (e.g. on click)?
* Review guidelines for personas are changing, defined later.
* images are limited to JPG and PNG on the personas site (using Image Magic to check the formats).
* the client itself doesn't check.
* client stores the images, but will check for updates.
* When a site installs a persona we bring up an info bar with an undo button
* Sites can be unwhitelisted in site prefs
* unwhitelisted sites get an "allow once" infobar if they try to install a persona
* unwhitelisted sites cannot preview a persona
* update checks should obey the addon update check pref
Bureaucrats, canmove, Confirmed users
645

edits