[Webkit-unassigned] [Bug 201937] New: [EWS] layout-test results shouldn't be hosted on ews server
bugzilla-daemon at webkit.org
bugzilla-daemon at webkit.org
Wed Sep 18 12:29:49 PDT 2019
https://bugs.webkit.org/show_bug.cgi?id=201937
Bug ID: 201937
Summary: [EWS] layout-test results shouldn't be hosted on ews
server
Product: WebKit
Version: Other
Hardware: Unspecified
OS: Unspecified
Status: NEW
Severity: Normal
Priority: P2
Component: Tools / Tests
Assignee: webkit-unassigned at lists.webkit.org
Reporter: aakash_jain at apple.com
We shouldn't host layout-test results on the ews-build.webkit.org server. Since EWS runs untrusted code, someone might try to exploit XSS vulnerability through these as they are hosted on a webkit.org server.
Potential solution is to host them on S3.
--
You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.webkit.org/pipermail/webkit-unassigned/attachments/20190918/abe8e0d1/attachment.html>
More information about the webkit-unassigned
mailing list