Skip to content
GitLab
Projects Groups Topics Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • Trac Trac
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Issues 246
    • Issues 246
    • List
    • Boards
    • Service Desk
    • Milestones
  • Monitor
    • Monitor
    • Incidents
  • Analytics
    • Analytics
    • Value stream
  • Wiki
    • Wiki
  • Activity
  • Create a new issue
  • Issue Boards
Collapse sidebar
  • Legacy
  • TracTrac
  • Issues
  • #17759
Closed (moved) (moved)
Open
Issue created Dec 06, 2015 by Arthur Edelstein@arthuredelstein

font whitelist fails to stop local fonts in @font-face

In #13313 (moved), we introduced a font whitelist pref. John Daggett pointed out in https://bugzilla.mozilla.org/show_bug.cgi?id=1121643#c6 that a CSS rule like:

   @font-face {
     font-family: "MyTimes";
     src: local("Times");
   }

allows content to use "Times" even if it is not in our whitelist.

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Assignee
Assign to
Time tracking