⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 197007 in webkit


Ignore:
Timestamp:
Feb 23, 2016, 4:53:29 PM (11 years ago)
Author:
dbates@webkit.org
Message:

CSP: Enable base-uri directive by default
​https://bugs.webkit.org/show_bug.cgi?id=154521
<rdar://problem/24762032>

Reviewed by Brent Fulgham.

Source/WebCore:

Tests: http/tests/security/contentSecurityPolicy/1.1/base-uri-default-ignored.html

http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-base-uri-deny.html

  • page/csp/ContentSecurityPolicyDirectiveList.cpp:

(WebCore::isExperimentalDirectiveName): Move base-uri from the directives considered
experimental to...
(WebCore::isCSPDirectiveName): ...the list of standard directives.
(WebCore::ContentSecurityPolicyDirectiveList::addDirective): Move logic to parse the base-uri
directive outside the ENABLE(CSP_NEXT) macro guarded section/experimental feature runtime flag.

LayoutTests:

Copy test http/tests/security/contentSecurityPolicy/1.1/base-uri-deny.html to
http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-base-uri-deny.html,
making some minor stylistic changes, and update TestExpectations to skip it because it depends
on the firing of event SecurityPolicyViolationEvent, which is disabled as of the time of writing.
We will enable the firing of this event in <​https://bugs.webkit.org/show_bug.cgi?id=154522>.
Repurpose test name base-uri-deny.html to test that the base-uri directive prevents the use of
document base URL without depending on the firing of event SecurityPolicyViolationEvent.

Additionally, add test http/tests/security/contentSecurityPolicy/1.1/base-uri-default-ignored.html
to ensure that we do not fall back to enforcing the default-src directive in absence of
a base-uri directive as per section base-uri of the Content Security Policy 2.0 spec.,
<​https://www.w3.org/TR/2015/CR-CSP2-20150721/>.

  • TestExpectations:
  • http/tests/security/contentSecurityPolicy/1.1/base-uri-default-ignored-expected.txt: Added.
  • http/tests/security/contentSecurityPolicy/1.1/base-uri-default-ignored.html: Added.
  • http/tests/security/contentSecurityPolicy/1.1/base-uri-deny-expected.txt:
  • http/tests/security/contentSecurityPolicy/1.1/base-uri-deny.html: Repurpose test.
  • http/tests/security/contentSecurityPolicy/1.1/resources/base-href/resources/safe-script.js: Added.
  • http/tests/security/contentSecurityPolicy/1.1/resources/safe-script.js: Added.
  • http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-base-uri-deny-expected.txt: Copied from LayoutTests/http/tests/security/contentSecurityPolicy/1.1/base-uri-deny-expected.txt.
  • http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-base-uri-deny.html: Copied from LayoutTests/http/tests/security/contentSecurityPolicy/1.1/base-uri-deny.html.
  • http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon-expected.txt: Update expected result based on change to test (below).
  • http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon.html: Modified to test that we emit

a console warning when base-uri is used as a source expression.

Location:
trunk
Files:
8 added
8 edited
1 copied

Legend:

Unmodified
Added
Removed
  • trunk/LayoutTests/ChangeLog

    r196998 r197007  
     12016-02-23  Daniel Bates  <dabates@apple.com>
     2
     3        CSP: Enable base-uri directive by default
     4        https://bugs.webkit.org/show_bug.cgi?id=154521
     5        <rdar://problem/24762032>
     6
     7        Reviewed by Brent Fulgham.
     8
     9        Copy test http/tests/security/contentSecurityPolicy/1.1/base-uri-deny.html to
     10        http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-base-uri-deny.html,
     11        making some minor stylistic changes, and update TestExpectations to skip it because it depends
     12        on the firing of event SecurityPolicyViolationEvent, which is disabled as of the time of writing.
     13        We will enable the firing of this event in <https://bugs.webkit.org/show_bug.cgi?id=154522>.
     14        Repurpose test name base-uri-deny.html to test that the base-uri directive prevents the use of
     15        document base URL without depending on the firing of event SecurityPolicyViolationEvent.
     16
     17        Additionally, add test http/tests/security/contentSecurityPolicy/1.1/base-uri-default-ignored.html
     18        to ensure that we do not fall back to enforcing the default-src directive in absence of
     19        a base-uri directive as per section base-uri of the Content Security Policy 2.0 spec.,
     20        <https://www.w3.org/TR/2015/CR-CSP2-20150721/>.
     21
     22        * TestExpectations:
     23        * http/tests/security/contentSecurityPolicy/1.1/base-uri-default-ignored-expected.txt: Added.
     24        * http/tests/security/contentSecurityPolicy/1.1/base-uri-default-ignored.html: Added.
     25        * http/tests/security/contentSecurityPolicy/1.1/base-uri-deny-expected.txt:
     26        * http/tests/security/contentSecurityPolicy/1.1/base-uri-deny.html: Repurpose test.
     27        * http/tests/security/contentSecurityPolicy/1.1/resources/base-href/resources/safe-script.js: Added.
     28        * http/tests/security/contentSecurityPolicy/1.1/resources/safe-script.js: Added.
     29        * http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-base-uri-deny-expected.txt: Copied from LayoutTests/http/tests/security/contentSecurityPolicy/1.1/base-uri-deny-expected.txt.
     30        * http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-base-uri-deny.html: Copied from LayoutTests/http/tests/security/contentSecurityPolicy/1.1/base-uri-deny.html.
     31        * http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon-expected.txt: Update expected result based on change to test (below).
     32        * http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon.html: Modified to test that we emit
     33        a console warning when base-uri is used as a source expression.
     34
    1352016-02-22  Ryosuke Niwa  <rniwa@webkit.org>
    236
  • trunk/LayoutTests/TestExpectations

    r196892 r197007  
    811811http/tests/security/contentSecurityPolicy/1.1/form-action-src-javascript-blocked.html [ Pass ]
    812812http/tests/security/contentSecurityPolicy/1.1/form-action-src-redirect-blocked.html [ Pass ]
     813http/tests/security/contentSecurityPolicy/1.1/base-uri-allow.html [ Pass ]
     814http/tests/security/contentSecurityPolicy/1.1/base-uri-default-ignored.html [ Pass ]
     815http/tests/security/contentSecurityPolicy/1.1/base-uri-deny.html [ Pass ]
    813816http/tests/security/contentSecurityPolicy/1.1/report-uri-effective-directive.php [ Pass ]
    814817webkit.org/b/154203 http/tests/security/contentSecurityPolicy/1.1/frame-ancestors/frame-ancestors-overrides-xfo.html
    … …  
    837840webkit.org/b/153162 http/tests/security/contentSecurityPolicy/report-multiple-violations-01.html [ Failure ]
    838841webkit.org/b/153162 http/tests/security/contentSecurityPolicy/report-multiple-violations-02.html [ Failure ]
     842webkit.org/b/154522 http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-base-uri-deny.html
    839843http/tests/security/contentSecurityPolicy/script-src-blocked-error-event.html [ Pass Failure ]
    840844
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/base-uri-deny-expected.txt

    r146886 r197007  
    1 CONSOLE MESSAGE: Refused to set the document's base URI to 'http://example.com/' because it violates the following Content Security Policy directive: "base-uri 'self'".
     1CONSOLE MESSAGE: Refused to set the document's base URI to 'http://127.0.0.1:8000/security/contentSecurityPolicy/1.1/resources/base-href/' because it violates the following Content Security Policy directive: "base-uri 'none'".
    22
    3 Check that base URIs cannot be set if they violate the page's policy.
     3ALERT: This is a safe script.
    44
    5 On success, you will see a series of "PASS" messages, followed by "TEST COMPLETE".
    6 
    7 
    8 Kicking off the tests:
    9 PASS document.baseURI is document.location.href
    10 PASS window.e.documentURI is "http://127.0.0.1:8000/security/contentSecurityPolicy/1.1/base-uri-deny.html"
    11 PASS window.e.referrer is ""
    12 PASS window.e.blockedURI is "http://example.com"
    13 PASS window.e.violatedDirective is "base-uri 'self'"
    14 PASS window.e.effectiveDirective is "base-uri"
    15 PASS window.e.originalPolicy is "base-uri 'self'"
    16 PASS window.e.sourceFile is "http://127.0.0.1:8000/security/contentSecurityPolicy/1.1/base-uri-deny.html"
    17 PASS window.e.lineNumber is 24
    18 PASS successfullyParsed is true
    19 
    20 TEST COMPLETE
    21 
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/base-uri-deny.html

    r146886 r197007  
    22<html>
    33<head>
    4     <meta http-equiv="Content-Security-Policy" content="base-uri 'self'">
    5     <script src="http://localhost:8000/js-test-resources/js-test-pre.js"></script>
    6     <script src="http://localhost:8000/security/contentSecurityPolicy/resources/securitypolicyviolation-test.js"></script>
    7     <script>
    8         description('Check that base URIs cannot be set if they violate the page\'s policy.');
    9 
    10         var expectations = {
    11             'documentURI': document.location.toString(),
    12             'referrer': document.referrer,
    13             'blockedURI': 'http://example.com',
    14             'violatedDirective': 'base-uri \'self\'',
    15             'effectiveDirective': 'base-uri',
    16             'originalPolicy': 'base-uri \'self\'',
    17             'sourceFile': document.location.toString(),
    18             'lineNumber': 24
    19         };
    20 
    21         function run() {
    22             var base = document.createElement('base');
    23             base.href = 'http://example.com/';
    24             document.head.appendChild(base);
    25 
    26             shouldBe('document.baseURI', 'document.location.href');
    27         }
    28     </script>
    29     <script src="http://localhost:8000/js-test-resources/js-test-post.js"></script>
     4<script>
     5if (window.testRunner)
     6    testRunner.dumpAsText();
     7</script>
     8<meta http-equiv="Content-Security-Policy" content="base-uri 'none'">
     9<base href="http://127.0.0.1:8000/security/contentSecurityPolicy/1.1/resources/base-href/">
     10<script src="resources/safe-script.js"></script>
    3011</head>
    31 <body>
    32 </body>
    3312</html>
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon-expected.txt

    r196992 r197007  
    33CONSOLE MESSAGE: The Content Security Policy directive 'script-src' contains 'style-src' as a source expression. Did you mean 'script-src ...; style-src...' (note the semicolon)?
    44CONSOLE MESSAGE: The Content Security Policy directive 'script-src' contains 'form-action' as a source expression. Did you mean 'script-src ...; form-action...' (note the semicolon)?
     5CONSOLE MESSAGE: The Content Security Policy directive 'script-src' contains 'base-uri' as a source expression. Did you mean 'script-src ...; base-uri...' (note the semicolon)?
    56If a web author forgets a semicolon, we should do our best to warn them that the policy they've defined is probably not what they intended.
    67
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon.html

    r196992 r197007  
    66var tests = [
    77    ['yes', 'default-src \'self\' script-src example.com', 'resources/script.js'],
    8     ['yes', "script-src 'self' object-src 'self' style-src * form-action 'self'", 'resources/script.js'],
     8    ['yes', "script-src 'self' object-src 'self' style-src * form-action 'self' base-uri 'self'", 'resources/script.js'],
    99];
    1010</script>
  • trunk/Source/WebCore/ChangeLog

    r197006 r197007  
     12016-02-23  Daniel Bates  <dabates@apple.com>
     2
     3        CSP: Enable base-uri directive by default
     4        https://bugs.webkit.org/show_bug.cgi?id=154521
     5        <rdar://problem/24762032>
     6
     7        Reviewed by Brent Fulgham.
     8
     9        Tests: http/tests/security/contentSecurityPolicy/1.1/base-uri-default-ignored.html
     10               http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-base-uri-deny.html
     11
     12        * page/csp/ContentSecurityPolicyDirectiveList.cpp:
     13        (WebCore::isExperimentalDirectiveName): Move base-uri from the directives considered
     14        experimental to...
     15        (WebCore::isCSPDirectiveName): ...the list of standard directives.
     16        (WebCore::ContentSecurityPolicyDirectiveList::addDirective): Move logic to parse the base-uri
     17        directive outside the ENABLE(CSP_NEXT) macro guarded section/experimental feature runtime flag.
     18
    1192016-02-23  Gavin Barraclough  <barraclough@apple.com>
    220
  • trunk/Source/WebCore/page/csp/ContentSecurityPolicyDirectiveList.cpp

    r196992 r197007  
    6060static inline bool isExperimentalDirectiveName(const String& name)
    6161{
     62    return equalLettersIgnoringASCIICase(name, pluginTypes) || equalLettersIgnoringASCIICase(name, reflectedXSS);
     63}
     64
     65#else
     66
     67static inline bool isExperimentalDirectiveName(const String&)
     68{
     69    return false;
     70}
     71
     72#endif
     73
     74bool isCSPDirectiveName(const String& name)
     75{
    6276    return equalLettersIgnoringASCIICase(name, baseURI)
    63         || equalLettersIgnoringASCIICase(name, pluginTypes)
    64         || equalLettersIgnoringASCIICase(name, reflectedXSS);
    65 }
    66 
    67 #else
    68 
    69 static inline bool isExperimentalDirectiveName(const String&)
    70 {
    71     return false;
    72 }
    73 
    74 #endif
    75 
    76 bool isCSPDirectiveName(const String& name)
    77 {
    78     return equalLettersIgnoringASCIICase(name, connectSrc)
     77        || equalLettersIgnoringASCIICase(name, connectSrc)
    7978        || equalLettersIgnoringASCIICase(name, defaultSrc)
    8079        || equalLettersIgnoringASCIICase(name, fontSrc)
    … …  
    602601    else if (equalLettersIgnoringASCIICase(name, formAction))
    603602        setCSPDirective<ContentSecurityPolicySourceListDirective>(name, value, m_formAction);
     603    else if (equalLettersIgnoringASCIICase(name, baseURI))
     604        setCSPDirective<ContentSecurityPolicySourceListDirective>(name, value, m_baseURI);
    604605    else if (equalLettersIgnoringASCIICase(name, sandbox))
    605606        applySandboxPolicy(name, value);
    … …  
    608609#if ENABLE(CSP_NEXT)
    609610    else if (m_policy.experimentalFeaturesEnabled()) {
    610         if (equalLettersIgnoringASCIICase(name, baseURI))
    611             setCSPDirective<ContentSecurityPolicySourceListDirective>(name, value, m_baseURI);
    612         else if (equalLettersIgnoringASCIICase(name, pluginTypes))
     611        if (equalLettersIgnoringASCIICase(name, pluginTypes))
    613612            setCSPDirective<ContentSecurityPolicyMediaListDirective>(name, value, m_pluginTypes);
    614613        else if (equalLettersIgnoringASCIICase(name, reflectedXSS))
Note: See TracChangeset for help on using the changeset viewer.