Changeset 197007 in webkit
- Timestamp:
- Feb 23, 2016, 4:53:29 PM (11 years ago)
- Location:
- trunk
- Files:
-
- 8 added
- 8 edited
- 1 copied
-
LayoutTests/ChangeLog (modified) (1 diff)
-
LayoutTests/TestExpectations (modified) (2 diffs)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/base-uri-default-ignored-expected.txt (added)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/base-uri-default-ignored.html (added)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/base-uri-deny-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/base-uri-deny.html (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/resources (added)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/resources/base-href (added)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/resources/base-href/resources (added)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/resources/base-href/resources/safe-script.js (added)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/resources/safe-script.js (added)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-base-uri-deny-expected.txt (copied) (copied from trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/base-uri-deny-expected.txt )
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-base-uri-deny.html (added)
-
LayoutTests/http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon.html (modified) (1 diff)
-
Source/WebCore/ChangeLog (modified) (1 diff)
-
Source/WebCore/page/csp/ContentSecurityPolicyDirectiveList.cpp (modified) (3 diffs)
Legend:
- Unmodified
- Added
- Removed
-
trunk/LayoutTests/ChangeLog
r196998 r197007 1 2016-02-23 Daniel Bates <dabates@apple.com> 2 3 CSP: Enable base-uri directive by default 4 https://bugs.webkit.org/show_bug.cgi?id=154521 5 <rdar://problem/24762032> 6 7 Reviewed by Brent Fulgham. 8 9 Copy test http/tests/security/contentSecurityPolicy/1.1/base-uri-deny.html to 10 http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-base-uri-deny.html, 11 making some minor stylistic changes, and update TestExpectations to skip it because it depends 12 on the firing of event SecurityPolicyViolationEvent, which is disabled as of the time of writing. 13 We will enable the firing of this event in <https://bugs.webkit.org/show_bug.cgi?id=154522>. 14 Repurpose test name base-uri-deny.html to test that the base-uri directive prevents the use of 15 document base URL without depending on the firing of event SecurityPolicyViolationEvent. 16 17 Additionally, add test http/tests/security/contentSecurityPolicy/1.1/base-uri-default-ignored.html 18 to ensure that we do not fall back to enforcing the default-src directive in absence of 19 a base-uri directive as per section base-uri of the Content Security Policy 2.0 spec., 20 <https://www.w3.org/TR/2015/CR-CSP2-20150721/>. 21 22 * TestExpectations: 23 * http/tests/security/contentSecurityPolicy/1.1/base-uri-default-ignored-expected.txt: Added. 24 * http/tests/security/contentSecurityPolicy/1.1/base-uri-default-ignored.html: Added. 25 * http/tests/security/contentSecurityPolicy/1.1/base-uri-deny-expected.txt: 26 * http/tests/security/contentSecurityPolicy/1.1/base-uri-deny.html: Repurpose test. 27 * http/tests/security/contentSecurityPolicy/1.1/resources/base-href/resources/safe-script.js: Added. 28 * http/tests/security/contentSecurityPolicy/1.1/resources/safe-script.js: Added. 29 * http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-base-uri-deny-expected.txt: Copied from LayoutTests/http/tests/security/contentSecurityPolicy/1.1/base-uri-deny-expected.txt. 30 * http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-base-uri-deny.html: Copied from LayoutTests/http/tests/security/contentSecurityPolicy/1.1/base-uri-deny.html. 31 * http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon-expected.txt: Update expected result based on change to test (below). 32 * http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon.html: Modified to test that we emit 33 a console warning when base-uri is used as a source expression. 34 1 35 2016-02-22 Ryosuke Niwa <rniwa@webkit.org> 2 36 -
trunk/LayoutTests/TestExpectations
r196892 r197007 811 811 http/tests/security/contentSecurityPolicy/1.1/form-action-src-javascript-blocked.html [ Pass ] 812 812 http/tests/security/contentSecurityPolicy/1.1/form-action-src-redirect-blocked.html [ Pass ] 813 http/tests/security/contentSecurityPolicy/1.1/base-uri-allow.html [ Pass ] 814 http/tests/security/contentSecurityPolicy/1.1/base-uri-default-ignored.html [ Pass ] 815 http/tests/security/contentSecurityPolicy/1.1/base-uri-deny.html [ Pass ] 813 816 http/tests/security/contentSecurityPolicy/1.1/report-uri-effective-directive.php [ Pass ] 814 817 webkit.org/b/154203 http/tests/security/contentSecurityPolicy/1.1/frame-ancestors/frame-ancestors-overrides-xfo.html … … 837 840 webkit.org/b/153162 http/tests/security/contentSecurityPolicy/report-multiple-violations-01.html [ Failure ] 838 841 webkit.org/b/153162 http/tests/security/contentSecurityPolicy/report-multiple-violations-02.html [ Failure ] 842 webkit.org/b/154522 http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-base-uri-deny.html 839 843 http/tests/security/contentSecurityPolicy/script-src-blocked-error-event.html [ Pass Failure ] 840 844 -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/base-uri-deny-expected.txt
r146886 r197007 1 CONSOLE MESSAGE: Refused to set the document's base URI to 'http:// example.com/' because it violates the following Content Security Policy directive: "base-uri 'self'".1 CONSOLE MESSAGE: Refused to set the document's base URI to 'http://127.0.0.1:8000/security/contentSecurityPolicy/1.1/resources/base-href/' because it violates the following Content Security Policy directive: "base-uri 'none'". 2 2 3 Check that base URIs cannot be set if they violate the page's policy.3 ALERT: This is a safe script. 4 4 5 On success, you will see a series of "PASS" messages, followed by "TEST COMPLETE".6 7 8 Kicking off the tests:9 PASS document.baseURI is document.location.href10 PASS window.e.documentURI is "http://127.0.0.1:8000/security/contentSecurityPolicy/1.1/base-uri-deny.html"11 PASS window.e.referrer is ""12 PASS window.e.blockedURI is "http://example.com"13 PASS window.e.violatedDirective is "base-uri 'self'"14 PASS window.e.effectiveDirective is "base-uri"15 PASS window.e.originalPolicy is "base-uri 'self'"16 PASS window.e.sourceFile is "http://127.0.0.1:8000/security/contentSecurityPolicy/1.1/base-uri-deny.html"17 PASS window.e.lineNumber is 2418 PASS successfullyParsed is true19 20 TEST COMPLETE21 -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/base-uri-deny.html
r146886 r197007 2 2 <html> 3 3 <head> 4 <meta http-equiv="Content-Security-Policy" content="base-uri 'self'"> 5 <script src="http://localhost:8000/js-test-resources/js-test-pre.js"></script> 6 <script src="http://localhost:8000/security/contentSecurityPolicy/resources/securitypolicyviolation-test.js"></script> 7 <script> 8 description('Check that base URIs cannot be set if they violate the page\'s policy.'); 9 10 var expectations = { 11 'documentURI': document.location.toString(), 12 'referrer': document.referrer, 13 'blockedURI': 'http://example.com', 14 'violatedDirective': 'base-uri \'self\'', 15 'effectiveDirective': 'base-uri', 16 'originalPolicy': 'base-uri \'self\'', 17 'sourceFile': document.location.toString(), 18 'lineNumber': 24 19 }; 20 21 function run() { 22 var base = document.createElement('base'); 23 base.href = 'http://example.com/'; 24 document.head.appendChild(base); 25 26 shouldBe('document.baseURI', 'document.location.href'); 27 } 28 </script> 29 <script src="http://localhost:8000/js-test-resources/js-test-post.js"></script> 4 <script> 5 if (window.testRunner) 6 testRunner.dumpAsText(); 7 </script> 8 <meta http-equiv="Content-Security-Policy" content="base-uri 'none'"> 9 <base href="http://127.0.0.1:8000/security/contentSecurityPolicy/1.1/resources/base-href/"> 10 <script src="resources/safe-script.js"></script> 30 11 </head> 31 <body>32 </body>33 12 </html> -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon-expected.txt
r196992 r197007 3 3 CONSOLE MESSAGE: The Content Security Policy directive 'script-src' contains 'style-src' as a source expression. Did you mean 'script-src ...; style-src...' (note the semicolon)? 4 4 CONSOLE MESSAGE: The Content Security Policy directive 'script-src' contains 'form-action' as a source expression. Did you mean 'script-src ...; form-action...' (note the semicolon)? 5 CONSOLE MESSAGE: The Content Security Policy directive 'script-src' contains 'base-uri' as a source expression. Did you mean 'script-src ...; base-uri...' (note the semicolon)? 5 6 If a web author forgets a semicolon, we should do our best to warn them that the policy they've defined is probably not what they intended. 6 7 -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon.html
r196992 r197007 6 6 var tests = [ 7 7 ['yes', 'default-src \'self\' script-src example.com', 'resources/script.js'], 8 ['yes', "script-src 'self' object-src 'self' style-src * form-action 'self' ", 'resources/script.js'],8 ['yes', "script-src 'self' object-src 'self' style-src * form-action 'self' base-uri 'self'", 'resources/script.js'], 9 9 ]; 10 10 </script> -
trunk/Source/WebCore/ChangeLog
r197006 r197007 1 2016-02-23 Daniel Bates <dabates@apple.com> 2 3 CSP: Enable base-uri directive by default 4 https://bugs.webkit.org/show_bug.cgi?id=154521 5 <rdar://problem/24762032> 6 7 Reviewed by Brent Fulgham. 8 9 Tests: http/tests/security/contentSecurityPolicy/1.1/base-uri-default-ignored.html 10 http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-base-uri-deny.html 11 12 * page/csp/ContentSecurityPolicyDirectiveList.cpp: 13 (WebCore::isExperimentalDirectiveName): Move base-uri from the directives considered 14 experimental to... 15 (WebCore::isCSPDirectiveName): ...the list of standard directives. 16 (WebCore::ContentSecurityPolicyDirectiveList::addDirective): Move logic to parse the base-uri 17 directive outside the ENABLE(CSP_NEXT) macro guarded section/experimental feature runtime flag. 18 1 19 2016-02-23 Gavin Barraclough <barraclough@apple.com> 2 20 -
trunk/Source/WebCore/page/csp/ContentSecurityPolicyDirectiveList.cpp
r196992 r197007 60 60 static inline bool isExperimentalDirectiveName(const String& name) 61 61 { 62 return equalLettersIgnoringASCIICase(name, pluginTypes) || equalLettersIgnoringASCIICase(name, reflectedXSS); 63 } 64 65 #else 66 67 static inline bool isExperimentalDirectiveName(const String&) 68 { 69 return false; 70 } 71 72 #endif 73 74 bool isCSPDirectiveName(const String& name) 75 { 62 76 return equalLettersIgnoringASCIICase(name, baseURI) 63 || equalLettersIgnoringASCIICase(name, pluginTypes) 64 || equalLettersIgnoringASCIICase(name, reflectedXSS); 65 } 66 67 #else 68 69 static inline bool isExperimentalDirectiveName(const String&) 70 { 71 return false; 72 } 73 74 #endif 75 76 bool isCSPDirectiveName(const String& name) 77 { 78 return equalLettersIgnoringASCIICase(name, connectSrc) 77 || equalLettersIgnoringASCIICase(name, connectSrc) 79 78 || equalLettersIgnoringASCIICase(name, defaultSrc) 80 79 || equalLettersIgnoringASCIICase(name, fontSrc) … … 602 601 else if (equalLettersIgnoringASCIICase(name, formAction)) 603 602 setCSPDirective<ContentSecurityPolicySourceListDirective>(name, value, m_formAction); 603 else if (equalLettersIgnoringASCIICase(name, baseURI)) 604 setCSPDirective<ContentSecurityPolicySourceListDirective>(name, value, m_baseURI); 604 605 else if (equalLettersIgnoringASCIICase(name, sandbox)) 605 606 applySandboxPolicy(name, value); … … 608 609 #if ENABLE(CSP_NEXT) 609 610 else if (m_policy.experimentalFeaturesEnabled()) { 610 if (equalLettersIgnoringASCIICase(name, baseURI)) 611 setCSPDirective<ContentSecurityPolicySourceListDirective>(name, value, m_baseURI); 612 else if (equalLettersIgnoringASCIICase(name, pluginTypes)) 611 if (equalLettersIgnoringASCIICase(name, pluginTypes)) 613 612 setCSPDirective<ContentSecurityPolicyMediaListDirective>(name, value, m_pluginTypes); 614 613 else if (equalLettersIgnoringASCIICase(name, reflectedXSS))
Note:
See TracChangeset
for help on using the changeset viewer.