mirror of
https://github.com/mozilla/gecko-dev.git
synced 2025-02-26 04:09:50 +00:00

As for document.fonts, I don't think we intentionally meant to apply CSP to User/UserAgent fonts. The document certainly has no authority to block those from loading. (We already have a separate principal for these which is further evidence that this was unintentional and we can use the same bit (mUseOriginPrincipal) to avoid CSP.) Differential Revision: https://phabricator.services.mozilla.com/D111695