Bug 1125891 - Enable the no-admin sandbox for Flash, r=bobowen
authorBenjamin Smedberg <benjamin@smedbergs.us>
Mon, 26 Jan 2015 13:25:15 -0500
changeset 239135 88534cb4094a483e1916e740510b027e3e5f02ee
parent 239134 ec1efe1d6f420394d36660cee2fed49ac2704a12
child 239136 114d75337bedcb8f0ddb14baca393916094663d1
push id487
push userbcampen@mozilla.com
push dateMon, 26 Jan 2015 23:32:56 +0000
reviewersbobowen
bugs1125891
milestone38.0a1
Bug 1125891 - Enable the no-admin sandbox for Flash, r=bobowen
browser/app/profile/firefox.js
--- a/browser/app/profile/firefox.js
+++ b/browser/app/profile/firefox.js
@@ -1181,17 +1181,17 @@ pref("browser.tabs.remote.desktopbehavio
 // process and also if they are subsequently allowed by the broker process.
 // This will require a restart.
 pref("security.sandbox.windows.log", false);
 
 // Controls whether the Windows NPAPI plugin process is sandboxed by default.
 // To get a different setting for a particular plugin replace "default", with
 // the plugin's nice file name, see: nsPluginTag::GetNiceFileName.
 pref("dom.ipc.plugins.sandbox.default", false);
-pref("dom.ipc.plugins.sandbox.flash", false);
+pref("dom.ipc.plugins.sandbox.flash", true);
 
 #if defined(MOZ_CONTENT_SANDBOX)
 // This controls whether the Windows content process sandbox is using a more
 // strict sandboxing policy.  This will require a restart.
 pref("security.sandbox.windows.content.moreStrict", false);
 
 #if defined(MOZ_STACKWALKING)
 // This controls the depth of stack trace that is logged when Windows sandbox