⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 196877 in webkit


Ignore:
Timestamp:
Feb 21, 2016, 11:51:43 AM (11 years ago)
Author:
dbates@webkit.org
Message:

CSP: Violation report should include column number
​https://bugs.webkit.org/show_bug.cgi?id=154418
<rdar://problem/24729525>

Reviewed by Brent Fulgham.

Source/WebCore:

Include column-number in the Content Security Policy violation report for the column number
in the source script where the violation occurred (for a script violation) as per section
Reporting of the Content Security Policy 2.0 spec., <​https://www.w3.org/TR/2015/CR-CSP2-20150721/>.

When a CSP report is created for a script violation the source file and line number of the
source code line where the violation occurred are included in the report. We now include
the column number in the source file where the violation occurred so as to help narrow
down the operation that triggered the violation in a complicated source code line.

  • page/csp/ContentSecurityPolicy.cpp:

(WebCore::ContentSecurityPolicy::reportViolation):

LayoutTests:

Update expected results to include source file column information where the violation occurred.

  • http/tests/security/contentSecurityPolicy/report-blocked-file-uri-expected.txt:
  • http/tests/security/contentSecurityPolicy/report-uri-from-inline-javascript-expected.txt:
  • http/tests/security/contentSecurityPolicy/report-uri-from-javascript-expected.txt:
Location:
trunk
Files:
6 edited

Legend:

Unmodified
Added
Removed
  • trunk/LayoutTests/ChangeLog

    r196876 r196877  
     12016-02-21  Daniel Bates  <dabates@apple.com>
     2
     3        CSP: Violation report should include column number
     4        https://bugs.webkit.org/show_bug.cgi?id=154418
     5        <rdar://problem/24729525>
     6
     7        Reviewed by Brent Fulgham.
     8
     9        Update expected results to include source file column information where the violation occurred.
     10
     11        * http/tests/security/contentSecurityPolicy/report-blocked-file-uri-expected.txt:
     12        * http/tests/security/contentSecurityPolicy/report-uri-from-inline-javascript-expected.txt:
     13        * http/tests/security/contentSecurityPolicy/report-uri-from-javascript-expected.txt:
     14
    1152016-02-21  Daniel Bates  <dabates@apple.com>
    216
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/report-blocked-file-uri-expected.txt

    r196876 r196877  
    66REQUEST_METHOD: POST
    77=== POST DATA ===
    8 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-blocked-file-uri.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri resources/save-report.php","blocked-uri":"file","status-code":200,"source-file":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-blocked-file-uri.php","line-number":9}}
     8{"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-blocked-file-uri.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri resources/save-report.php","blocked-uri":"file","status-code":200,"source-file":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-blocked-file-uri.php","line-number":9,"column-number":26}}
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/report-uri-from-inline-javascript-expected.txt

    r196876 r196877  
    66REQUEST_METHOD: POST
    77=== POST DATA ===
    8 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-uri-from-inline-javascript.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri resources/save-report.php","blocked-uri":"http://127.0.0.1:8000/security/resources/abe.png","status-code":200,"source-file":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-uri-from-inline-javascript.php","line-number":7}}
     8{"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-uri-from-inline-javascript.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri resources/save-report.php","blocked-uri":"http://127.0.0.1:8000/security/resources/abe.png","status-code":200,"source-file":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-uri-from-inline-javascript.php","line-number":7,"column-number":10}}
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/report-uri-from-javascript-expected.txt

    r196876 r196877  
    66REQUEST_METHOD: POST
    77=== POST DATA ===
    8 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-uri-from-javascript.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri resources/save-report.php","blocked-uri":"http://127.0.0.1:8000/security/resources/abe.png","status-code":200,"source-file":"http://127.0.0.1:8000/security/contentSecurityPolicy/resources/inject-image.js","line-number":3}}
     8{"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-uri-from-javascript.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri resources/save-report.php","blocked-uri":"http://127.0.0.1:8000/security/resources/abe.png","status-code":200,"source-file":"http://127.0.0.1:8000/security/contentSecurityPolicy/resources/inject-image.js","line-number":3,"column-number":2}}
  • trunk/Source/WebCore/ChangeLog

    r196876 r196877  
     12016-02-21  Daniel Bates  <dabates@apple.com>
     2
     3        CSP: Violation report should include column number
     4        https://bugs.webkit.org/show_bug.cgi?id=154418
     5        <rdar://problem/24729525>
     6
     7        Reviewed by Brent Fulgham.
     8
     9        Include column-number in the Content Security Policy violation report for the column number
     10        in the source script where the violation occurred (for a script violation) as per section
     11        Reporting of the Content Security Policy 2.0 spec., <https://www.w3.org/TR/2015/CR-CSP2-20150721/>.
     12
     13        When a CSP report is created for a script violation the source file and line number of the
     14        source code line where the violation occurred are included in the report. We now include
     15        the column number in the source file where the violation occurred so as to help narrow
     16        down the operation that triggered the violation in a complicated source code line.
     17
     18        * page/csp/ContentSecurityPolicy.cpp:
     19        (WebCore::ContentSecurityPolicy::reportViolation):
     20
    1212016-02-21  Daniel Bates  <dabates@apple.com>
    222
  • trunk/Source/WebCore/page/csp/ContentSecurityPolicy.cpp

    r196876 r196877  
    396396        cspReport->setString(ASCIILiteral("source-file"), stripURLForUseInReport(document, source));
    397397        cspReport->setInteger(ASCIILiteral("line-number"), callFrame->lineNumber());
     398        cspReport->setInteger(ASCIILiteral("column-number"), callFrame->columnNumber());
    398399    }
    399400
Note: See TracChangeset for help on using the changeset viewer.