Commit Graph

5 Commits

Author SHA1 Message Date
NTD 35a65b8507 Make sure the security state is set properly in nsMixedContentBlocker 2018-07-25 06:52:52 +08:00
janekptacijarabaci 7cf33c4329 CORS: A "data:" URL = the same-origin 2018-07-25 06:43:07 +08:00
Pale Moon 53617979da CSP: Insecure HTTP port :80 should also allow secure HTTPS port :443.
- this also splits out port checking to re-order the checking to be more in line with the spec order.
2018-07-25 01:29:18 +08:00
Pale Moon eb6d10adc1 CSP - Bail early if referrer directive has no valid src. 2018-07-25 01:04:18 +08:00
Moonchild baf46a6bf1 Merge pull request #1 from mozilla/esr38: Esr38 upstream pull 2018-07-24 23:04:07 +08:00