Extension Developers - Unbreaking News, Part 2
I love reporting “unbreaking news” and I have some report. I posted about a security change (bug 418356) to mozIJSSubScriptLoader that broke loading scripts from any non-chrome URI. An alternate fix has landed that allows file: and resource: URIs to be loaded by the subscript loader again.
Therefore, this will continue to work:
var obj = {};
var loader = Components.classes["@mozilla.org/moz/jssubscript-loader;1"]
.getService(Components.interfaces.mozIJSSubScriptLoader);
loader.loadSubScript("file:///blah.js", obj);
Unfortunately, data: URIs are harder to secure and will not work with the subscript loader. Fortunately, there are workarounds for data: URIs - you can save the script to a file and use file: or you can use evalInSandbox to evaluate the script.
Thanks to Boris Zbarsky and Johnny Stenbeck for the more robust fix.