summaryrefslogtreecommitdiffstats
path: root/dom/security/test
Commit message (Expand)AuthorAgeLines
* backport mozbug 1334776 - CVE-2017-7797 Header name interning leaks across or...Gaming4JC2018-09-25-1/+1
* Bug 1469150 - Tests added to check scripts with valid nonce is allowed if URL...janekptacijarabaci2018-06-23-0/+0
* Bug 1469150 - CSP: Scripts with valid nonce get blocked if URL redirectsjanekptacijarabaci2018-06-21-0/+98
* Remove support and tests for HSTS priming from the tree. Fixes #384Gaming4JC2018-05-26-721/+0
* Bug 1329288 - Test ContentPolicy blocks opening a new windowjanekptacijarabaci2018-04-22-0/+1
* moebius#230: Consider blocking top level window data: URIs (part 3/3 without ...janekptacijarabaci2018-04-22-0/+45
* moebius#226: Consider blocking top level window data: URIs (part 2/2 without ...janekptacijarabaci2018-04-22-18/+124
* moebius#223: Consider blocking top level window data: URIs (part 1/3 without ...janekptacijarabaci2018-04-22-0/+387
* moebius#159: CSP - support for "frame-ancestors" in "Content-Security-Policy-...janekptacijarabaci2018-04-14-0/+74
* Bug 1288768 - Better error reporting for network errors in workersjanekptacijarabaci2018-04-04-11/+2
* Add support for CSP v3 "worker-src" directivewolfbeast2018-03-03-3/+327
* CSP: connect-src 'self' should always include https: and wss: schemesjanekptacijarabaci2018-02-22-0/+135
* CSP: Support IDNs in connect-srcjanekptacijarabaci2018-02-22-0/+133
* CSP: Ignore nonces on <img> per specjanekptacijarabaci2018-02-22-0/+104
* CSP: Upgrade SO navigational requests per spec.janekptacijarabaci2018-02-22-0/+184
* CSP 2 - ignore (x-)frame-options if CSP with frame-ancestors directive existsjanekptacijarabaci2018-02-22-0/+90
* Add m-esr52 at 52.6.0Matt A. Tobin2018-02-02-0/+22274