Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Brave Shields block IPFS Companion's request hand off to localhost gateway #962

Closed
lidel opened this issue Jan 18, 2021 · 2 comments · Fixed by #976
Closed

Brave Shields block IPFS Companion's request hand off to localhost gateway #962

lidel opened this issue Jan 18, 2021 · 2 comments · Fixed by #976
Assignees
Labels
area/brave Issues related to Brave Browser kind/bug A bug in existing code (including security flaws) P0 Critical: Tackled by core team ASAP

Comments

@lidel
Copy link
Member

lidel commented Jan 18, 2021

Filled upstream issue: brave/brave-browser#13641

@lidel lidel added kind/bug A bug in existing code (including security flaws) status/blocked/upstream-bug Blocked by upstream bugs P0 Critical: Tackled by core team ASAP area/brave Issues related to Brave Browser labels Jan 18, 2021
@lidel lidel self-assigned this Jan 18, 2021
@lidel
Copy link
Member Author

lidel commented Jan 20, 2021

Fixed upstream: brave/brave-browser#13641 (comment)

@lidel lidel closed this as completed Jan 20, 2021
@lidel
Copy link
Member Author

lidel commented Jan 21, 2021

Reopening:

This had to be reverted because Brave doesn't allow localhost access for websites, because websites could probe the available services of a user and use that for fingerprinting.
If the fish page was ipfs:// though top level, then it should allow the subresources to show.

We need to disable redirect of subresources on HTTP pages in Brave.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/brave Issues related to Brave Browser kind/bug A bug in existing code (including security flaws) P0 Critical: Tackled by core team ASAP
Projects
None yet
1 participant