⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 196892 in webkit


Ignore:
Timestamp:
Feb 21, 2016, 9:26:17 PM (11 years ago)
Author:
dbates@webkit.org
Message:

CSP: Enable form-action directive by default
​https://bugs.webkit.org/show_bug.cgi?id=154520
<rdar://problem/24762029>

Reviewed by Sam Weinig.

Source/WebCore:

  • page/csp/ContentSecurityPolicyDirectiveList.cpp:

(WebCore::ContentSecurityPolicyDirectiveList::addDirective): Move logic to parse the form-action
directive outside the ENABLE(CSP_NEXT) macro guarded section/experimental feature runtime flag.
(WebCore::isExperimentalDirectiveName): Remove form-action from the directives considered
experimental.

LayoutTests:

Mark form-action tests as Pass so that we run them.

Location:
trunk
Files:
4 edited

Legend:

Unmodified
Added
Removed
  • trunk/LayoutTests/ChangeLog

    r196890 r196892  
     12016-02-21  Daniel Bates  <dabates@apple.com>
     2
     3        CSP: Enable form-action directive by default
     4        https://bugs.webkit.org/show_bug.cgi?id=154520
     5        <rdar://problem/24762029>
     6
     7        Reviewed by Sam Weinig.
     8
     9        Mark form-action tests as Pass so that we run them.
     10
     11        * TestExpectations:
     12
    1132016-02-21  Chris Dumez  <cdumez@apple.com>
    214
  • trunk/LayoutTests/TestExpectations

    r196876 r196892  
    804804webkit.org/b/85558 http/tests/security/contentSecurityPolicy/1.1
    805805http/tests/security/contentSecurityPolicy/1.1/child-src [ Pass ]
     806http/tests/security/contentSecurityPolicy/1.1/form-action-src-allowed.html [ Pass ]
     807http/tests/security/contentSecurityPolicy/1.1/form-action-src-blocked.html [ Pass ]
     808http/tests/security/contentSecurityPolicy/1.1/form-action-src-default-ignored.html [ Pass ]
     809http/tests/security/contentSecurityPolicy/1.1/form-action-src-get-allowed.html [ Pass ]
     810http/tests/security/contentSecurityPolicy/1.1/form-action-src-get-blocked.html [ Pass ]
     811http/tests/security/contentSecurityPolicy/1.1/form-action-src-javascript-blocked.html [ Pass ]
     812http/tests/security/contentSecurityPolicy/1.1/form-action-src-redirect-blocked.html [ Pass ]
    806813http/tests/security/contentSecurityPolicy/1.1/report-uri-effective-directive.php [ Pass ]
    807814webkit.org/b/154203 http/tests/security/contentSecurityPolicy/1.1/frame-ancestors/frame-ancestors-overrides-xfo.html
  • trunk/Source/WebCore/ChangeLog

    r196890 r196892  
     12016-02-21  Daniel Bates  <dabates@apple.com>
     2
     3        CSP: Enable form-action directive by default
     4        https://bugs.webkit.org/show_bug.cgi?id=154520
     5        <rdar://problem/24762029>
     6
     7        Reviewed by Sam Weinig.
     8
     9        * page/csp/ContentSecurityPolicyDirectiveList.cpp:
     10        (WebCore::ContentSecurityPolicyDirectiveList::addDirective): Move logic to parse the form-action
     11        directive outside the ENABLE(CSP_NEXT) macro guarded section/experimental feature runtime flag.
     12        (WebCore::isExperimentalDirectiveName): Remove form-action from the directives considered
     13        experimental.
     14
    1152016-02-21  Chris Dumez  <cdumez@apple.com>
    216
  • trunk/Source/WebCore/page/csp/ContentSecurityPolicyDirectiveList.cpp

    r196875 r196892  
    6161{
    6262    return equalLettersIgnoringASCIICase(name, baseURI)
    63         || equalLettersIgnoringASCIICase(name, formAction)
    6463        || equalLettersIgnoringASCIICase(name, pluginTypes)
    6564        || equalLettersIgnoringASCIICase(name, reflectedXSS);
    … …  
    600599    else if (equalLettersIgnoringASCIICase(name, childSrc))
    601600        setCSPDirective<ContentSecurityPolicySourceListDirective>(name, value, m_childSrc);
     601    else if (equalLettersIgnoringASCIICase(name, formAction))
     602        setCSPDirective<ContentSecurityPolicySourceListDirective>(name, value, m_formAction);
    602603    else if (equalLettersIgnoringASCIICase(name, sandbox))
    603604        applySandboxPolicy(name, value);
    … …  
    608609        if (equalLettersIgnoringASCIICase(name, baseURI))
    609610            setCSPDirective<ContentSecurityPolicySourceListDirective>(name, value, m_baseURI);
    610         else if (equalLettersIgnoringASCIICase(name, formAction))
    611             setCSPDirective<ContentSecurityPolicySourceListDirective>(name, value, m_formAction);
    612611        else if (equalLettersIgnoringASCIICase(name, pluginTypes))
    613612            setCSPDirective<ContentSecurityPolicyMediaListDirective>(name, value, m_pluginTypes);
Note: See TracChangeset for help on using the changeset viewer.