1
0

2671 svg.disabled-> inactive for FF53+

This commit is contained in:
Thorin-Oakenpants 2017-04-15 12:27:41 +12:00 committed by GitHub
parent a8cfe7f06f
commit 551427fccc

View File

@ -1220,8 +1220,9 @@ user_pref("network.proxy.autoconfig_url.include_path", false);
user_pref("security.block_script_with_wrong_mime", true); user_pref("security.block_script_with_wrong_mime", true);
/* 2671: disable in-content SVG (Scalable Vector Graphics) (FF53+) /* 2671: disable in-content SVG (Scalable Vector Graphics) (FF53+)
* [WARNING] SVG is fairly common (~15% of the top 10K sites), so will cause some breakage * [WARNING] SVG is fairly common (~15% of the top 10K sites), so will cause some breakage
* including youtube player controls. Best left for "hardened" or specific profiles.
* [1] https://bugzilla.mozilla.org/show_bug.cgi?id=1216893 ***/ * [1] https://bugzilla.mozilla.org/show_bug.cgi?id=1216893 ***/
user_pref("svg.disabled", true); // user_pref("svg.disabled", true);
/* 2672: force Punycode for Internationalized Domain Names to eliminate possible spoofing security risk /* 2672: force Punycode for Internationalized Domain Names to eliminate possible spoofing security risk
* Firefox has *some* protections to mitigate the risk, but it is better to be safe * Firefox has *some* protections to mitigate the risk, but it is better to be safe
* than sorry. The downside: it will also display legitimate IDN's punycoded, which * than sorry. The downside: it will also display legitimate IDN's punycoded, which