Sat, 03 Jan 2015 20:18:00 +0100
Conditionally enable double key logic according to:
private browsing mode or privacy.thirdparty.isolate preference and
implement in GetCookieStringCommon and FindCookie where it counts...
With some reservations of how to convince FindCookie users to test
condition and pass a nullptr when disabling double key logic.
1 /* This Source Code Form is subject to the terms of the Mozilla Public
2 * License, v. 2.0. If a copy of the MPL was not distributed with this
3 * file, You can obtain one at http://mozilla.org/MPL/2.0/. */
5 /* See https://bugzilla.mozilla.org/show_bug.cgi?id=813901 */
7 const Cu = Components.utils;
9 // Make sure that we can't inject __exposedProps__ via the proto of a COW-ed object.
11 function checkThrows(expression, sb, regexp) {
12 var result = Cu.evalInSandbox('(function() { try { ' + expression + '; return "allowed"; } catch (e) { return e.toString(); }})();', sb);
13 dump('result: ' + result + '\n\n\n');
14 do_check_true(!!regexp.exec(result));
15 }
17 function run_test() {
19 var sb = new Cu.Sandbox('http://www.example.org');
20 sb.obj = {foo: 2};
21 checkThrows('obj.foo = 3;', sb, /denied/);
22 Cu.evalInSandbox("var p = {__exposedProps__: {foo: 'rw'}};", sb);
23 sb.obj.__proto__ = sb.p;
24 checkThrows('obj.foo = 4;', sb, /__exposedProps__/);
25 }