Skip to content
GitLab
  • Menu
Projects Groups Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • Trac Trac
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Issues 246
    • Issues 246
    • List
    • Boards
    • Service Desk
    • Milestones
  • Monitor
    • Monitor
    • Metrics
    • Incidents
  • Analytics
    • Analytics
    • Value stream
  • Wiki
    • Wiki
  • Activity
  • Create a new issue
  • Issue Boards
Collapse sidebar
  • Legacy
  • TracTrac
  • Issues
  • #22899
Closed
Open
Created Jul 12, 2017 by Yawning Angel@yawning

`about:addons`'s "Get Addons" pane is unsafe and should be treated as such.

https://github.com/mozilla/addons-frontend/issues/2785

Right now the about:addons page loads an iFrame with content hosted on a Mozilla website ("The Discovery Pane"). This page contains Google Analytics. Because we don't allow add-ons to run on about:* pages, add-ons that would block GA don't work here.

It appears that they are making this DNT based, which is entirely inadequate as any form of user tracking should be explicitly opt-in. My plan unless people tell me otherwise is to totally reject requests to discovery.addons.mozilla.org unless Modifiable Extensions is enabled.

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Assignee
Assign to
Time tracking