diff options
author | wolfbeast <mcwerewolf@gmail.com> | 2018-02-08 11:37:12 +0100 |
---|---|---|
committer | wolfbeast <mcwerewolf@gmail.com> | 2018-02-08 11:37:12 +0100 |
commit | b827a3a9cd60b10526e3bc99274a1465f1b6f2d1 (patch) | |
tree | 4de2dee6e80a03a228590cc5fda3014d9e0f3169 /browser/components/extensions/ext-browserAction.js | |
parent | f7f35438f5e257575ea2b7a430c58e458ae56b4e (diff) | |
download | UXP-b827a3a9cd60b10526e3bc99274a1465f1b6f2d1.tar UXP-b827a3a9cd60b10526e3bc99274a1465f1b6f2d1.tar.gz UXP-b827a3a9cd60b10526e3bc99274a1465f1b6f2d1.tar.lz UXP-b827a3a9cd60b10526e3bc99274a1465f1b6f2d1.tar.xz UXP-b827a3a9cd60b10526e3bc99274a1465f1b6f2d1.zip |
Perform LoadURL checks for WebExtensions.
Diffstat (limited to 'browser/components/extensions/ext-browserAction.js')
-rw-r--r-- | browser/components/extensions/ext-browserAction.js | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/browser/components/extensions/ext-browserAction.js b/browser/components/extensions/ext-browserAction.js index 407366e2c..2c82ac701 100644 --- a/browser/components/extensions/ext-browserAction.js +++ b/browser/components/extensions/ext-browserAction.js @@ -497,6 +497,9 @@ extensions.registerSchemaAPI("browserAction", "addon_parent", context => { // For internal consistency, we currently resolve both relative to the // calling context. let url = details.popup && context.uri.resolve(details.popup); + if (url && !context.checkLoadURL(url)) { + return Promise.reject({message: `Access denied for URL ${url}`}); + } BrowserAction.for(extension).setProperty(tab, "popup", url); }, |