Changeset 196874 in webkit
- Timestamp:
- Feb 21, 2016, 10:52:51 AM (11 years ago)
- Location:
- trunk
- Files:
-
- 6 added
- 6 deleted
- 7 edited
- 2 moved
-
LayoutTests/ChangeLog (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/sandbox-allow-scripts-in-http-header2-expected.txt (moved) (moved from trunk/LayoutTests/http/tests/security/contentSecurityPolicy/sandbox-allow-scripts-expected.txt )
-
LayoutTests/http/tests/security/contentSecurityPolicy/sandbox-allow-scripts-in-http-header2.php (moved) (moved from trunk/LayoutTests/http/tests/security/contentSecurityPolicy/sandbox-allow-scripts.html ) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/sandbox-allow-scripts-subframe-expected.txt (deleted)
-
LayoutTests/http/tests/security/contentSecurityPolicy/sandbox-allow-scripts-subframe.html (deleted)
-
LayoutTests/http/tests/security/contentSecurityPolicy/sandbox-empty-expected.txt (deleted)
-
LayoutTests/http/tests/security/contentSecurityPolicy/sandbox-empty-in-http-header-expected.txt (added)
-
LayoutTests/http/tests/security/contentSecurityPolicy/sandbox-empty-in-http-header-inherited-by-subframe-expected.txt (added)
-
LayoutTests/http/tests/security/contentSecurityPolicy/sandbox-empty-in-http-header-inherited-by-subframe.php (added)
-
LayoutTests/http/tests/security/contentSecurityPolicy/sandbox-empty-in-http-header.php (added)
-
LayoutTests/http/tests/security/contentSecurityPolicy/sandbox-empty-subframe-expected.txt (deleted)
-
LayoutTests/http/tests/security/contentSecurityPolicy/sandbox-empty-subframe.html (deleted)
-
LayoutTests/http/tests/security/contentSecurityPolicy/sandbox-empty.html (deleted)
-
LayoutTests/http/tests/security/contentSecurityPolicy/sandbox-in-meta-tag-ignored-expected.txt (added)
-
LayoutTests/http/tests/security/contentSecurityPolicy/sandbox-in-meta-tag-ignored.html (added)
-
Source/WebCore/ChangeLog (modified) (1 diff)
-
Source/WebCore/dom/Document.cpp (modified) (1 diff)
-
Source/WebCore/page/csp/ContentSecurityPolicy.cpp (modified) (4 diffs)
-
Source/WebCore/page/csp/ContentSecurityPolicy.h (modified) (3 diffs)
-
Source/WebCore/page/csp/ContentSecurityPolicyDirectiveList.cpp (modified) (3 diffs)
-
Source/WebCore/page/csp/ContentSecurityPolicyDirectiveList.h (modified) (2 diffs)
Legend:
- Unmodified
- Added
- Removed
-
trunk/LayoutTests/ChangeLog
r196872 r196874 1 2016-02-21 Daniel Bates <dabates@apple.com> 2 3 CSP: sandbox directive should be ignored when contained in a policy defined via a meta element 4 https://bugs.webkit.org/show_bug.cgi?id=154299 5 <rdar://problem/24680433> 6 7 Reviewed by Brent Fulgham. 8 9 Add test http/tests/security/contentSecurityPolicy/sandbox-in-meta-tag-ignored.html to ensure that we ignore 10 the sandbox directive when delivered via an HTML meta element and log a message to the Web Inspector console. 11 12 Remove tests http/tests/security/contentSecurityPolicy/sandbox-{allow-scripts-subframe, empty, empty-subframe}.html 13 that are no longer meaningful now that we ignore the sandbox directive when delivered via an HTML meta element and 14 create analogous tests for when the sandbox directive is delivered via an HTTP header. 15 16 * http/tests/security/contentSecurityPolicy/sandbox-allow-scripts-in-http-header2-expected.txt: Renamed from LayoutTests/http/tests/security/contentSecurityPolicy/sandbox-allow-scripts-expected.txt. 17 * http/tests/security/contentSecurityPolicy/sandbox-allow-scripts-in-http-header2.php: Renamed from LayoutTests/http/tests/security/contentSecurityPolicy/sandbox-allow-scripts.html. 18 19 * http/tests/security/contentSecurityPolicy/sandbox-allow-scripts-subframe-expected.txt: Removed. 20 * http/tests/security/contentSecurityPolicy/sandbox-allow-scripts-subframe.html: Removed. 21 This test is no longer meaningful now that we ignore the sandbox directive when delivered via an HTML meta element. 22 An analogous test for when the directive is delivered via an HTTP header is http/tests/security/contentSecurityPolicy//sandbox-allow-scripts-in-http-header.html. 23 24 * http/tests/security/contentSecurityPolicy/sandbox-empty-in-http-header-inherited-by-subframe-expected.txt: Added. 25 * http/tests/security/contentSecurityPolicy/sandbox-empty-in-http-header-inherited-by-subframe.php: Added. Derived from test http/tests/security/contentSecurityPolicy/sandbox-empty-subframe.html. 26 27 * http/tests/security/contentSecurityPolicy/sandbox-empty-in-http-header-expected.txt: Added. 28 * http/tests/security/contentSecurityPolicy/sandbox-empty-in-http-header.php: Added. Derived from test http/tests/security/contentSecurityPolicy/sandbox-empty.html. 29 30 * http/tests/security/contentSecurityPolicy/sandbox-empty-subframe-expected.txt: Removed. 31 * http/tests/security/contentSecurityPolicy/sandbox-empty-subframe.html: Removed. 32 This test is no longer meaningful now that we ignore the sandbox directive when delivered via an HTML meta element. 33 The analogous test for when the directive is delivered via an HTTP header is http/tests/security/contentSecurityPolicy/sandbox-empty-in-http-header-inherited-by-subframe.php. 34 35 * http/tests/security/contentSecurityPolicy/sandbox-empty-expected.txt: Removed. 36 * http/tests/security/contentSecurityPolicy/sandbox-empty.html: Removed. 37 This test is no longer meaningful now that we ignore the sandbox directive when delivered via an HTML meta element. 38 The analogous test for when the directive is delivered via an HTTP header is http/tests/security/contentSecurityPolicy/sandbox-empty-in-http-header.php. 39 40 * http/tests/security/contentSecurityPolicy/sandbox-in-meta-tag-ignored-expected.txt: Added. 41 * http/tests/security/contentSecurityPolicy/sandbox-in-meta-tag-ignored.html: Added. 42 1 43 2016-02-21 Commit Queue <commit-queue@webkit.org> 2 44 -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/sandbox-allow-scripts-in-http-header2.php
r196873 r196874 1 <?php 2 header("Content-Security-Policy: sandbox allow-scripts"); 3 ?> 4 <!DOCTYPE html> 5 <html> 6 <body> 1 7 <script> 2 8 if (window.testRunner) 3 9 testRunner.dumpAsText(); 4 10 </script> 5 <meta http-equiv="Content-Security-Policy" content="sandbox allow-scripts">6 11 This test passes if it does alert pass. 7 12 <script> 8 13 alert('PASS'); 9 14 </script> 15 </body> 16 </html> -
trunk/Source/WebCore/ChangeLog
r196872 r196874 1 2016-02-21 Daniel Bates <dabates@apple.com> 2 3 CSP: sandbox directive should be ignored when contained in a policy defined via a meta element 4 https://bugs.webkit.org/show_bug.cgi?id=154299 5 <rdar://problem/24680433> 6 7 Reviewed by Brent Fulgham. 8 9 The Content Security Policy sandbox directive should only be honored when enforcing a policy 10 defined via an HTTP header as per section sandbox of the Content Security Policy 2.0 spec., 11 <https://www.w3.org/TR/2015/CR-CSP2-20150721/>. 12 13 Currently we honor the sandbox directive when enforcing a policy defined either via an HTML 14 meta element or an HTTP header. Instead we should only honor this directive when defined 15 via an HTTP header and log a message to the Web Inspector console to explain that the directive 16 was ignored as suggested in <https://www.w3.org/TR/2015/CR-CSP2-20150721/#delivery-html-meta-element>. 17 18 Tests: http/tests/security/contentSecurityPolicy/sandbox-allow-scripts-in-http-header2.php 19 http/tests/security/contentSecurityPolicy/sandbox-empty-in-http-header-inherited-by-subframe.php 20 http/tests/security/contentSecurityPolicy/sandbox-empty-in-http-header.php 21 http/tests/security/contentSecurityPolicy/sandbox-in-meta-tag-ignored.html 22 23 * dom/Document.cpp: 24 (WebCore::Document::processHttpEquiv): Substitute ContentSecurityPolicy::processHTTPEquiv() for 25 ContentSecurityPolicy::didReceiveHeader() as the latter was made private. 26 * page/csp/ContentSecurityPolicy.cpp: 27 (WebCore::ContentSecurityPolicy::copyStateFrom): Updated as needed based on ContentSecurityPolicy::didReceiveHeader() change below. 28 (WebCore::ContentSecurityPolicy::didReceiveHeaders): Ditto. 29 (WebCore::ContentSecurityPolicy::didReceiveHeader): Modified to take argument of type ContentSecurityPolicy::PolicyFrom 30 and pass it through to ContentSecurityPolicyDirectiveList::create(). 31 (WebCore::ContentSecurityPolicy::reportInvalidDirectiveInHTTPEquivMeta): Logs a message to the Web Inspector console 32 that the specified directive was ignored because it was delivered via an HTML meta element. 33 * page/csp/ContentSecurityPolicy.h: Made member function ContentSecurityPolicy::didReceiveHeader() private. Defined 34 enum class PolicyFrom to represent the source of the Content Security Policy: HTTP equiv meta element, HTTP header, or 35 inherited from another ContentSecurityPolicy object (this value is only used by ContentSecurityPolicy::copyStateFrom()). 36 (WebCore::ContentSecurityPolicy::processHTTPEquiv): Added; turns around and calls ContentSecurityPolicy::didReceiveHeader(). 37 The name of this function better describes its purpose - to handle the processing of a Content Security Policy 38 delivered via <meta http-equiv="Content-Security-Policy" content="...">. 39 * page/csp/ContentSecurityPolicyDirectiveList.cpp: 40 (WebCore::ContentSecurityPolicyDirectiveList::create): Modified to take argument of type ContentSecurityPolicy::PolicyFrom 41 as pass it through to ContentSecurityPolicyDirectiveList::parse(). 42 (WebCore::ContentSecurityPolicyDirectiveList::parse): Modified to ignore the directive sandbox when the Content Security 43 Policy came from an HTML meta element. 44 * page/csp/ContentSecurityPolicyDirectiveList.h: 45 1 46 2016-02-21 Commit Queue <commit-queue@webkit.org> 2 47 -
trunk/Source/WebCore/dom/Document.cpp
r196807 r196874 3272 3272 3273 3273 case HTTPHeaderName::ContentSecurityPolicy: 3274 contentSecurityPolicy()-> didReceiveHeader(content, ContentSecurityPolicyHeaderType::Enforce);3274 contentSecurityPolicy()->processHTTPEquiv(content, ContentSecurityPolicyHeaderType::Enforce); 3275 3275 break; 3276 3276 3277 3277 case HTTPHeaderName::ContentSecurityPolicyReportOnly: 3278 contentSecurityPolicy()-> didReceiveHeader(content, ContentSecurityPolicyHeaderType::Report);3278 contentSecurityPolicy()->processHTTPEquiv(content, ContentSecurityPolicyHeaderType::Report); 3279 3279 break; 3280 3280 3281 3281 case HTTPHeaderName::XWebKitCSP: 3282 contentSecurityPolicy()-> didReceiveHeader(content, ContentSecurityPolicyHeaderType::PrefixedEnforce);3282 contentSecurityPolicy()->processHTTPEquiv(content, ContentSecurityPolicyHeaderType::PrefixedEnforce); 3283 3283 break; 3284 3284 3285 3285 case HTTPHeaderName::XWebKitCSPReportOnly: 3286 contentSecurityPolicy()-> didReceiveHeader(content, ContentSecurityPolicyHeaderType::PrefixedReport);3286 contentSecurityPolicy()->processHTTPEquiv(content, ContentSecurityPolicyHeaderType::PrefixedReport); 3287 3287 break; 3288 3288 -
trunk/Source/WebCore/page/csp/ContentSecurityPolicy.cpp
r196664 r196874 79 79 ASSERT(m_policies.isEmpty()); 80 80 for (auto& policy : other->m_policies) 81 didReceiveHeader(policy->header(), policy->headerType() );81 didReceiveHeader(policy->header(), policy->headerType(), ContentSecurityPolicy::PolicyFrom::Inherited); 82 82 } 83 83 … … 94 94 { 95 95 for (auto& header : headers.m_headers) 96 didReceiveHeader(header.first, header.second );97 } 98 99 void ContentSecurityPolicy::didReceiveHeader(const String& header, ContentSecurityPolicyHeaderType type )96 didReceiveHeader(header.first, header.second, ContentSecurityPolicy::PolicyFrom::HTTPHeader); 97 } 98 99 void ContentSecurityPolicy::didReceiveHeader(const String& header, ContentSecurityPolicyHeaderType type, ContentSecurityPolicy::PolicyFrom policyFrom) 100 100 { 101 101 // RFC2616, section 4.2 specifies that headers appearing multiple times can … … 111 111 // header1,header2 OR header1 112 112 // ^ ^ 113 std::unique_ptr<ContentSecurityPolicyDirectiveList> policy = ContentSecurityPolicyDirectiveList::create(*this, String(begin, position - begin), type );113 std::unique_ptr<ContentSecurityPolicyDirectiveList> policy = ContentSecurityPolicyDirectiveList::create(*this, String(begin, position - begin), type, policyFrom); 114 114 if (!policy->allowEval(0, ContentSecurityPolicy::ReportingStatus::SuppressReport)) 115 115 m_lastPolicyEvalDisabledErrorMessage = policy->evalDisabledErrorMessage(); … … 458 458 } 459 459 460 void ContentSecurityPolicy::reportInvalidDirectiveInHTTPEquivMeta(const String& directiveName) const 461 { 462 logToConsole("The Content Security Policy directive '" + directiveName + "' is ignored when delivered via an HTML meta element."); 463 } 464 460 465 void ContentSecurityPolicy::reportInvalidDirectiveValueCharacter(const String& directiveName, const String& value) const 461 466 { -
trunk/Source/WebCore/page/csp/ContentSecurityPolicy.h
r196582 r196874 68 68 ReflectedXSSDisposition reflectedXSSDisposition() const; 69 69 70 enum class PolicyFrom { 71 HTTPEquivMeta, 72 HTTPHeader, 73 Inherited, 74 }; 70 75 ContentSecurityPolicyResponseHeaders responseHeaders() const; 71 76 void didReceiveHeaders(const ContentSecurityPolicyResponseHeaders&); 72 void didReceiveHeader(const String&, ContentSecurityPolicyHeaderType);77 void processHTTPEquiv(const String& content, ContentSecurityPolicyHeaderType type) { didReceiveHeader(content, type, ContentSecurityPolicy::PolicyFrom::HTTPEquivMeta); } 73 78 74 79 enum class ReportingStatus { … … 124 129 void reportInvalidReflectedXSS(const String&) const; 125 130 void reportInvalidDirectiveInReportOnlyMode(const String&) const; 131 void reportInvalidDirectiveInHTTPEquivMeta(const String&) const; 126 132 void reportMissingReportURI(const String&) const; 127 133 void reportUnsupportedDirective(const String&) const; … … 137 143 void applyPolicyToScriptExecutionContext(); 138 144 145 void didReceiveHeader(const String&, ContentSecurityPolicyHeaderType, ContentSecurityPolicy::PolicyFrom); 146 139 147 ScriptExecutionContext* m_scriptExecutionContext { nullptr }; 140 148 std::unique_ptr<ContentSecurityPolicySource> m_selfSource; -
trunk/Source/WebCore/page/csp/ContentSecurityPolicyDirectiveList.cpp
r196582 r196874 116 116 } 117 117 118 std::unique_ptr<ContentSecurityPolicyDirectiveList> ContentSecurityPolicyDirectiveList::create(ContentSecurityPolicy& policy, const String& header, ContentSecurityPolicyHeaderType type )118 std::unique_ptr<ContentSecurityPolicyDirectiveList> ContentSecurityPolicyDirectiveList::create(ContentSecurityPolicy& policy, const String& header, ContentSecurityPolicyHeaderType type, ContentSecurityPolicy::PolicyFrom from) 119 119 { 120 120 auto directives = std::make_unique<ContentSecurityPolicyDirectiveList>(policy, type); 121 directives->parse(header );121 directives->parse(header, from); 122 122 123 123 if (!directives->checkEval(directives->operativeDirective(directives->m_scriptSrc.get()))) { … … 390 390 // directive-list = [ directive *( ";" [ directive ] ) ] 391 391 // 392 void ContentSecurityPolicyDirectiveList::parse(const String& policy )392 void ContentSecurityPolicyDirectiveList::parse(const String& policy, ContentSecurityPolicy::PolicyFrom policyFrom) 393 393 { 394 394 m_header = policy; … … 407 407 if (parseDirective(directiveBegin, position, name, value)) { 408 408 ASSERT(!name.isEmpty()); 409 addDirective(name, value); 409 switch (policyFrom) { 410 case ContentSecurityPolicy::PolicyFrom::HTTPEquivMeta: 411 // FIXME: We also need to ignore directive report-uri (https://bugs.webkit.org/show_bug.cgi?id=154307). 412 if (equalLettersIgnoringASCIICase(name, sandbox)) { 413 m_policy.reportInvalidDirectiveInHTTPEquivMeta(name); 414 break; 415 } 416 FALLTHROUGH; 417 default: 418 addDirective(name, value); 419 break; 420 } 410 421 } 411 422 -
trunk/Source/WebCore/page/csp/ContentSecurityPolicyDirectiveList.h
r196526 r196874 42 42 WTF_MAKE_NONCOPYABLE(ContentSecurityPolicyDirectiveList) 43 43 public: 44 static std::unique_ptr<ContentSecurityPolicyDirectiveList> create(ContentSecurityPolicy&, const String&, ContentSecurityPolicyHeaderType );44 static std::unique_ptr<ContentSecurityPolicyDirectiveList> create(ContentSecurityPolicy&, const String&, ContentSecurityPolicyHeaderType, ContentSecurityPolicy::PolicyFrom); 45 45 ContentSecurityPolicyDirectiveList(ContentSecurityPolicy&, ContentSecurityPolicyHeaderType); 46 46 … … 73 73 74 74 private: 75 void parse(const String& );75 void parse(const String&, ContentSecurityPolicy::PolicyFrom); 76 76 77 77 bool parseDirective(const UChar* begin, const UChar* end, String& name, String& value);
Note:
See TracChangeset
for help on using the changeset viewer.