Changeset 196892 in webkit
- Timestamp:
- Feb 21, 2016, 9:26:17 PM (11 years ago)
- Location:
- trunk
- Files:
-
- 4 edited
-
LayoutTests/ChangeLog (modified) (1 diff)
-
LayoutTests/TestExpectations (modified) (1 diff)
-
Source/WebCore/ChangeLog (modified) (1 diff)
-
Source/WebCore/page/csp/ContentSecurityPolicyDirectiveList.cpp (modified) (3 diffs)
Legend:
- Unmodified
- Added
- Removed
-
trunk/LayoutTests/ChangeLog
r196890 r196892 1 2016-02-21 Daniel Bates <dabates@apple.com> 2 3 CSP: Enable form-action directive by default 4 https://bugs.webkit.org/show_bug.cgi?id=154520 5 <rdar://problem/24762029> 6 7 Reviewed by Sam Weinig. 8 9 Mark form-action tests as Pass so that we run them. 10 11 * TestExpectations: 12 1 13 2016-02-21 Chris Dumez <cdumez@apple.com> 2 14 -
trunk/LayoutTests/TestExpectations
r196876 r196892 804 804 webkit.org/b/85558 http/tests/security/contentSecurityPolicy/1.1 805 805 http/tests/security/contentSecurityPolicy/1.1/child-src [ Pass ] 806 http/tests/security/contentSecurityPolicy/1.1/form-action-src-allowed.html [ Pass ] 807 http/tests/security/contentSecurityPolicy/1.1/form-action-src-blocked.html [ Pass ] 808 http/tests/security/contentSecurityPolicy/1.1/form-action-src-default-ignored.html [ Pass ] 809 http/tests/security/contentSecurityPolicy/1.1/form-action-src-get-allowed.html [ Pass ] 810 http/tests/security/contentSecurityPolicy/1.1/form-action-src-get-blocked.html [ Pass ] 811 http/tests/security/contentSecurityPolicy/1.1/form-action-src-javascript-blocked.html [ Pass ] 812 http/tests/security/contentSecurityPolicy/1.1/form-action-src-redirect-blocked.html [ Pass ] 806 813 http/tests/security/contentSecurityPolicy/1.1/report-uri-effective-directive.php [ Pass ] 807 814 webkit.org/b/154203 http/tests/security/contentSecurityPolicy/1.1/frame-ancestors/frame-ancestors-overrides-xfo.html -
trunk/Source/WebCore/ChangeLog
r196890 r196892 1 2016-02-21 Daniel Bates <dabates@apple.com> 2 3 CSP: Enable form-action directive by default 4 https://bugs.webkit.org/show_bug.cgi?id=154520 5 <rdar://problem/24762029> 6 7 Reviewed by Sam Weinig. 8 9 * page/csp/ContentSecurityPolicyDirectiveList.cpp: 10 (WebCore::ContentSecurityPolicyDirectiveList::addDirective): Move logic to parse the form-action 11 directive outside the ENABLE(CSP_NEXT) macro guarded section/experimental feature runtime flag. 12 (WebCore::isExperimentalDirectiveName): Remove form-action from the directives considered 13 experimental. 14 1 15 2016-02-21 Chris Dumez <cdumez@apple.com> 2 16 -
trunk/Source/WebCore/page/csp/ContentSecurityPolicyDirectiveList.cpp
r196875 r196892 61 61 { 62 62 return equalLettersIgnoringASCIICase(name, baseURI) 63 || equalLettersIgnoringASCIICase(name, formAction)64 63 || equalLettersIgnoringASCIICase(name, pluginTypes) 65 64 || equalLettersIgnoringASCIICase(name, reflectedXSS); … … 600 599 else if (equalLettersIgnoringASCIICase(name, childSrc)) 601 600 setCSPDirective<ContentSecurityPolicySourceListDirective>(name, value, m_childSrc); 601 else if (equalLettersIgnoringASCIICase(name, formAction)) 602 setCSPDirective<ContentSecurityPolicySourceListDirective>(name, value, m_formAction); 602 603 else if (equalLettersIgnoringASCIICase(name, sandbox)) 603 604 applySandboxPolicy(name, value); … … 608 609 if (equalLettersIgnoringASCIICase(name, baseURI)) 609 610 setCSPDirective<ContentSecurityPolicySourceListDirective>(name, value, m_baseURI); 610 else if (equalLettersIgnoringASCIICase(name, formAction))611 setCSPDirective<ContentSecurityPolicySourceListDirective>(name, value, m_formAction);612 611 else if (equalLettersIgnoringASCIICase(name, pluginTypes)) 613 612 setCSPDirective<ContentSecurityPolicyMediaListDirective>(name, value, m_pluginTypes);
Note:
See TracChangeset
for help on using the changeset viewer.