Bug 1956215 - Default "Free Content" bookmark "Open Clip Art" links to an invalid URL
Description Christoph Jerolimov 2021-05-03 08:35:36 UTC
Description of problem:
When using the latest Firefox 88 on Fedora workspace 33 and 34 it automatically provides some default bookmarks like "Fedora Docs", "Fedora Magazine", ... and "Free Content". The free content folder contains a link "Open Clip Art" which links to https://www.openclipart.org/

When open this page Firefox shows an "Warning: Potential Security Risk Ahead" because the SSL certificate is only valid for https://openclipart.org/ (without www.) This invalid suffix should be removed in the default bookmarks.

Version-Release number of selected component (if applicable):
firefox.x86_64                               88.0-5.fc34
firefox-pkcs11-loader.x86_64                 3.13.6-5.fc34
firefox-testresults.x86_64                   88.0-5.fc34
firefox-wayland.x86_64                       88.0-5.fc34
firefox-x11.x86_64                           88.0-5.fc34

(This may affect also older versions.)

How reproducible:

Steps to Reproduce:
1. Restore the default bookmarks. For example by resetting all Firefox settings (DANGEROUS!! Do this only if you use Firefox only for testing: rm -rf ~/.cache/mozilla/firefox ~/.mozilla/firefox)
2. Open Firefox
3. Open the bookmark "Free Content" -> "Open Clip Art"

Actual results:
Opens https://www.openclipart.org/ with "Warning: Potential Security Risk Ahead"

Expected results:
Opens https://openclipart.org/ without a warning.

Additional info:

Comment 1 Christoph Jerolimov 2021-05-03 08:38:53 UTC
I found that this invalid URL is part of the file /usr/lib64/firefox/browser/omni.ja. Unfortunately, I could not find which repository is responsible for this values so that I can provide a patch. If you guide me with some more infos I could try to provide a patch. If you just want to fix this yourself because this is much quicker, I'm also fine with this. :)

Comment 2 Martin Stransky 2021-05-03 09:22:00 UTC
Hi, it's stored at 'fedora-bookmarks' package, there's only one html file with bookmarks. Don't forget to update timestamp.

Comment 3 Christoph Jerolimov 2021-05-03 23:10:49 UTC
Thanks Martin for the quick response and hint how to fix this.

(I was unable to push directly to a repo fork on https://src.fedoraproject.org/, but I could create a PR with a remote git repo.)

Here is a PR to fix this URL in the default-bookmarks.html: https://src.fedoraproject.org/rpms/fedora-bookmarks/pull-request/6

I hope this helps. I don't updated the changelog in fedora-bookmarks.spec. Let me know if I should update this file as well.

