SitePolicies
Fine grained control over policies for specific sites.
Admins can use SitePolicies to apply policies to individual sites rather than the whole browser, for example turning the JIT engine off on untrusted sites, disallowing HTTP downgrades, or isolating sites in their own container.
Values
Section titled “Values”The policy is made up of a list of rules that are evaluated in order. Each rule can contain:
Match: a list of sites. An empty list or missing property means to match all sites.Exceptions: a list of sites which when matched bypasses this set of rules.Policies: an object defining the site policies.
Currently the supported site policies are:
-
DisableJitdisables the JIT engine for the site whentrue. -
HttpsOnlystops the site from being loaded over plain HTTP whentrue. When it isfalse, HTTP is explicitly allowed for the site, which is how you carve a site out of a broader rule. -
DisableServiceWorkersstops the site from registering or using service workers whentrue. Onlyhttpandhttpssites are affected, and sites relying on service workers for offline support or push notifications will lose those features. -
Containerloads the site in a dedicated container, keeping its cookies, storage, and logins separate from the rest of the browser. SettingContainerin a rule turns container support on and locks it, so the user cannot switch it off. (Firefox 158)
Accepts the following values:id: (required) A non-empty identifier you choose for the container. Every rule that uses the sameidshares one container.ephemeral: An optional boolean. Whentrue, the container's data is cleared after its last tab closes, and at shutdown. Defaults tofalse.
Navigating to a matching site loads it in a new tab inside the container. These containers are not listed in the containers UI, they have no colored tab indicator, and the user cannot pick them from the container menu. When a container is no longer named by any rule, Firefox deletes it along with its data.
Examples
Section titled “Examples”{ "policies": { "SitePolicies": [ { "Match": [ "*.example.com" ], "Policies": { "DisableJit": true } }, { "Exceptions": [ "*.example.org" ], "Policies": { "DisableJit": true } }, { "Match": [ "*.example.net" ], "Policies": { "HttpsOnly": true } }, { "Match": [ "*.example.com" ], "Policies": { "Container": { "id": "work" } } } ] }}JSON schema
{ "type": "array", "items": { "type": "object", "properties": { "Match": { "type": "array", "items": { "type": "string" } }, "Exceptions": { "type": "array", "items": { "type": "string" } }, "Policies": { "type": "object", "properties": { "DisableJit": { "type": "boolean" }, "HttpsOnly": { "type": "boolean" }, "DisableServiceWorkers": { "type": "boolean" }, "Container": { "type": "object", "properties": { "id": { "type": "string", "minLength": 1 }, "ephemeral": { "type": "boolean" } }, "required": [ "id" ] } } } }, "required": [ "Policies" ] }}A wildcard * can be used to refer to all sites.
For example this setting would disable the JIT for only *.example.com:
[ { "Match": ["*.example.com"], "Policies": { "DisableJit": true } }]While this setting would disable the JIT on every site except *.example.org:
[ { "Exceptions": ["*.example.org"], "Policies": { "DisableJit": true } }]This setting loads *.example.com in a container whose data is cleared once its last tab closes:
[ { "Match": ["*.example.com"], "Policies": { "Container": { "id": "company", "ephemeral": true } } }]Windows (GPO)
Section titled “Windows (GPO)”Software\Policies\Mozilla\Firefox\SitePolicies (REG_MULTI_SZ) =[ { "Exceptions": ["*.example.com"], "Policies": { "DisableJit": true } }]<dict> <key>SitePolicies</key> <array> <dict> <key>Exceptions</key> <array> <string>*.example.com</string> </array> <key>Policies</key> <dict> <key>DisableJit</key> <true/> </dict> </dict> </array></dict>Compatibility
Section titled “Compatibility”| Firefox | Firefox ESR | Firefox Enterprise |
|---|---|---|
| Available since 150 | Available since 153 | Available since 150 |
CCK2 Equivalent: N/A
OMA-URI: SitePolicies
Preferences Affected: privacy.userContext.enabled, privacy.containers.switchDuringNavigation.enabled (locked on only when a rule uses Container)
See also
Section titled “See also”HttpsOnlyModepolicy covers all browsing and can be configured to let the user turn it off.Containerspolicy sets up the named containers the user sees and can choose between, which are separate from the containersSitePoliciesmanages.