Security/Reviews/B2G: Difference between revisions

From MozillaWiki
Jump to navigation Jump to search
No edit summary
Line 1: Line 1:
==B2G Weekly Security Status==
==B2G Weekly Security Status==
 
[Status - April 4 2012]
 


==B2G Reviews==
==B2G Reviews==

Revision as of 03:45, 4 April 2012

B2G Weekly Security Status

[Status - April 4 2012]

B2G Reviews

The list below outlines the core areas of B2G which need security review.

Created from:

  • B2G Bugs [[1]]
  • B2G Schedule: [[2]]


Permissions Model & Management

  • Summary: Permissions Management in B2G. Everything to grant, read, revoke and manage app permissions for B2G apps. Priority since most other APIs depend on this.
  • Bug: https://bugzilla.mozilla.org/show_bug.cgi?id=707625
  • Permission DB (currently being designed)

Web Contacts

B2G Telephony

SMS

Browser


Network Connectivity

App Management

Installation and management of Web Apps (Open Web Apps for B2G)

Bug (app cache): https://bugzilla.mozilla.org/show_bug.cgi?id=702369

Web Bluetooth

Summary: Bluetooth API for B2G https://bugzilla.mozilla.org/show_bug.cgi?id=727618

Settings API

Summary: API for managing the B2G phone settings Bug: https://bugzilla.mozilla.org/show_bug.cgi?id=678695

Updater

Summary: Gaia and Gecko update mechanisms for B2G

Gaia Apps

All of the following apps will need at least a cursory review

  • Critical to review
    • Settings
    • Marketplace
    • Dialer
    • SMS
  • Non-critical to review
    • Camera
    • Photo Gallery
    • Video player
    • Music player
    • Email
    • Calendar
    • Clock
    • Calculator
    • Notepad
    • Maps