[Webkit-unassigned] [Bug 63145] filesystem URLs shouldn't trigger mixed content warnings

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Mon Nov 16 06:15:29 PST 2020


https://bugs.webkit.org/show_bug.cgi?id=63145

Frédéric Wang (:fredw) <fred.wang at free.fr> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |fred.wang at free.fr
             Blocks|                            |140625

--- Comment #7 from Frédéric Wang (:fredw) <fred.wang at free.fr> ---
These are the relevant links in the current spec:

https://w3c.github.io/webappsec-mixed-content/#mixed-content
https://w3c.github.io/webappsec-mixed-content/#a-priori-authenticated-url
https://w3c.github.io/webappsec-secure-contexts/#potentially-trustworthy-url

> "Return the result of executing § 3.2 Is origin potentially trustworthy? on url’s origin."
> Note: The origin of blob: and filesystem: URLs is the origin of the context in which they were created. Therefore, blobs created in a trustworthy origin will themselves be potentially trustworthy.


Referenced Bugs:

https://bugs.webkit.org/show_bug.cgi?id=140625
[Bug 140625] Support mixed content blocking
-- 
You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.webkit.org/pipermail/webkit-unassigned/attachments/20201116/a2d0bc30/attachment.htm>


More information about the webkit-unassigned mailing list