diff options
author | Petr Vobornik <pvoborni@redhat.com> | 2012-10-01 17:25:08 +0200 |
---|---|---|
committer | Rob Crittenden <rcritten@redhat.com> | 2012-10-04 18:07:29 -0400 |
commit | b4e19509c034942a4f6bc99c371774a0944b65eb (patch) | |
tree | 7ac790c547283c1c6b9f5665c208bf93bb02e302 /install/ffextension/chrome.manifest | |
parent | 459c83fb75fd6077ab3e5981f6e04f13ad3379c8 (diff) | |
download | freeipa-b4e19509c034942a4f6bc99c371774a0944b65eb.tar.gz freeipa-b4e19509c034942a4f6bc99c371774a0944b65eb.tar.xz freeipa-b4e19509c034942a4f6bc99c371774a0944b65eb.zip |
Kerberos authentication extension
The extension should replace signed code (configure.jar) used for Firefox configuration. Using privileged code is not possible since Firefox 15 [1] [2]. Extension is bootstrapped which means it can be used without browser restart on Firefox 4 and later.
How it works:
Extension listens on each page's document element for event 'kerberos-auth-config' which should be raised on custom data element. Communication data is transferred through data element's attributes [3]. The only required attribute is 'method'. Currently there are two possible values: 'configure' and 'can_configure'.
'can_configure' method serves for detecting if the extension is installed. 'configure' method does the actual configuration. Possible optional options for 'configure' can be found in kerberosauth.js:kerberosauth.config_options. Currently they are: 'referer', 'native_gss_lib', 'trusted_uris', 'allow_proxies'. Result of a method is stored in data element's 'answer' attribute. When 'configure' method is used, the extension asks the user if he wants to configure the browser, it should prevent silent configuration by malicious pages.
Possible enhancement:
* add UI for manual edit
* more configurations ie. for gss_lib, sspi (good with UI or with enhanced config page)
* introspection of client (read ipa client install config and such)
Ticket: https://fedorahosted.org/freeipa/ticket/3094
[1] https://bugzilla.mozilla.org/show_bug.cgi?id=546848
[2] https://bugzilla.mozilla.org/show_bug.cgi?id=757046
[3] https://developer.mozilla.org/en-US/docs/Code_snippets/Interaction_between_privileged_and_non-privileged_pages
Diffstat (limited to 'install/ffextension/chrome.manifest')
-rw-r--r-- | install/ffextension/chrome.manifest | 4 |
1 files changed, 4 insertions, 0 deletions
diff --git a/install/ffextension/chrome.manifest b/install/ffextension/chrome.manifest new file mode 100644 index 000000000..775d3a338 --- /dev/null +++ b/install/ffextension/chrome.manifest @@ -0,0 +1,4 @@ +content kerberosauth chrome/content/ +resource kerberosauth chrome/content/ +overlay chrome://browser/content/browser.xul resource://kerberosauth/kerberosauth_overlay.xul +locale kerberosauth en-US locale/en-US/
\ No newline at end of file |