Changeset 197038 in webkit
- Timestamp:
- Feb 24, 2016, 10:51:58 AM (11 years ago)
- Location:
- trunk
- Files:
-
- 19 edited
-
LayoutTests/ChangeLog (modified) (1 diff)
-
LayoutTests/TestExpectations (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-invalid-expected.txt (modified) (2 diffs)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-invalid.html (modified) (2 diffs)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-mismatched-data.html (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-mismatched-url.html (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-data.html (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-url-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-url.html (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-nourl-allowed.html (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-nourl-blocked.html (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-url-01.html (modified) (2 diffs)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-url-02.html (modified) (2 diffs)
-
LayoutTests/http/tests/security/contentSecurityPolicy/resources/echo-object-data.pl (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/resources/multiple-iframe-plugin-test.js (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon.html (modified) (1 diff)
-
Source/WebCore/ChangeLog (modified) (1 diff)
-
Source/WebCore/page/csp/ContentSecurityPolicyDirectiveList.cpp (modified) (4 diffs)
Legend:
- Unmodified
- Added
- Removed
-
trunk/LayoutTests/ChangeLog
r197036 r197038 1 2016-02-24 Daniel Bates <dabates@apple.com> 2 3 CSP: Enable plugin-types directive by default 4 https://bugs.webkit.org/show_bug.cgi?id=154420 5 <rdar://problem/24730322> 6 7 Reviewed by Brent Fulgham. 8 9 * TestExpectations: Mark http/tests/security/contentSecurityPolicy/1.1/plugintypes*.html tests as PASS so that we run them. 10 * http/tests/security/contentSecurityPolicy/1.1/plugintypes-invalid-expected.txt: Update expected result. 11 * http/tests/security/contentSecurityPolicy/1.1/plugintypes-invalid.html: Call runTests() following changes to multiple-iframe-plugin-test.js. 12 Also add closing tags for <body> and <html> to make the document well-formed. 13 * http/tests/security/contentSecurityPolicy/1.1/plugintypes-mismatched-data.html: Substitute "Content-Security-Policy" for "X-WebKit-CSP"; 14 no behavior change. 15 * http/tests/security/contentSecurityPolicy/1.1/plugintypes-mismatched-url.html: Ditto. 16 * http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-data.html: Ditto. 17 * http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-url-expected.txt: Update expected result. 18 * http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-url.html: Substitute "Content-Security-Policy" for "X-WebKit-CSP"; 19 no behavior change. 20 * http/tests/security/contentSecurityPolicy/1.1/plugintypes-nourl-allowed.html: Ditto. 21 * http/tests/security/contentSecurityPolicy/1.1/plugintypes-nourl-blocked.html: Ditto. 22 * http/tests/security/contentSecurityPolicy/1.1/plugintypes-url-01.html: Call runTests() following changes to multiple-iframe-plugin-test.js. 23 Also add closing tags for <body> and <html> to make the document well-formed. 24 * http/tests/security/contentSecurityPolicy/1.1/plugintypes-url-02.html: Ditto. 25 * http/tests/security/contentSecurityPolicy/resources/echo-object-data.pl: Remove logic to support Content Security Policy header X-WebKit-CSP 26 as it is sufficient to make use of the standardized header Content-Security-Policy. 27 * http/tests/security/contentSecurityPolicy/resources/multiple-iframe-plugin-test.js: Simplify code now that we do not pass query string parameter 28 experimental to script echo-object-data.pl. 29 (runTests): Runs all the sub-tests. 30 (runNextTest.iframe.onload): Formerly named testImpl.iframe.onload. 31 (runNextTest): Formerly named testImpl. Runs the next sub-test. 32 (testExperimentalPolicy): Deleted. 33 (test): Deleted. 34 (testImpl.iframe.onload): Deleted. 35 (testImpl): Deleted. 36 (finishTesting): Deleted. 37 * http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon-expected.txt: Update expected result based on change to test (below). 38 * http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon.html: Modified to test that we emit 39 a console warning when plugin-types is used as a source expression. 40 1 41 2016-02-24 Ryan Haddad <ryanhaddad@apple.com> 2 42 -
trunk/LayoutTests/TestExpectations
r197007 r197038 818 818 webkit.org/b/154203 http/tests/security/contentSecurityPolicy/1.1/scripthash-default-src.html 819 819 webkit.org/b/154203 http/tests/security/contentSecurityPolicy/1.1/stylehash-default-src.html 820 http/tests/security/contentSecurityPolicy/1.1/plugintypes-affects-child.html [ Pass ] 821 http/tests/security/contentSecurityPolicy/1.1/plugintypes-invalid.html [ Pass ] 822 http/tests/security/contentSecurityPolicy/1.1/plugintypes-mismatched-data.html [ Pass ] 823 http/tests/security/contentSecurityPolicy/1.1/plugintypes-mismatched-url.html [ Pass ] 824 http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-data.html [ Pass ] 825 http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-url.html [ Pass ] 826 http/tests/security/contentSecurityPolicy/1.1/plugintypes-nourl-allowed.html [ Pass ] 827 http/tests/security/contentSecurityPolicy/1.1/plugintypes-nourl-blocked.html [ Pass ] 828 http/tests/security/contentSecurityPolicy/1.1/plugintypes-url-01.html [ Pass ] 829 http/tests/security/contentSecurityPolicy/1.1/plugintypes-url-02.html [ Pass ] 820 830 webkit.org/b/111869 http/tests/security/contentSecurityPolicy/eval-blocked-and-sends-report.html 821 831 webkit.org/b/115700 http/tests/security/contentSecurityPolicy/inline-event-handler-blocked-after-injecting-meta.html [ Failure ] -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-invalid-expected.txt
r125531 r197038 6 6 7 7 CONSOLE MESSAGE: Refused to load 'data:application/x-webkit-test-netscape,logifloaded' (MIME type 'application/x-webkit-test-netscape') because it violates the following Content Security Policy Directive: 'plugin-types '. 8 9 CONSOLE MESSAGE: Invalid plugin type in 'plugin-types' Content Security Policy directive: ''none''. 10 11 CONSOLE MESSAGE: Refused to load 'data:application/x-webkit-test-netscape,logifloaded' (MIME type 'application/x-webkit-test-netscape') because it violates the following Content Security Policy Directive: 'plugin-types 'none''. 8 12 9 13 CONSOLE MESSAGE: Invalid plugin type in 'plugin-types' Content Security Policy directive: 'text'. … … 71 75 Frame: '<!--framePath //<!--frame7-->-->' 72 76 -------- 77 78 79 -------- 80 Frame: '<!--framePath //<!--frame8-->-->' 81 -------- 73 82 PASS. 74 83 -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-invalid.html
r195367 r197038 17 17 </script> 18 18 </head> 19 <body onload=" testExperimentalPolicy()">19 <body onload="runTests()"> 20 20 <p> 21 21 This tests our handling of invalid `plugin-types` CSP directives. … … 23 23 either "PASS" or no text at all. 24 24 </p> 25 </body> 26 </html> -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-mismatched-data.html
r125531 r197038 8 8 } 9 9 </script> 10 <meta http-equiv=" X-WebKit-CSP" content="plugin-types application/x-invalid-type">10 <meta http-equiv="Content-Security-Policy" content="plugin-types application/x-invalid-type"> 11 11 </head> 12 12 <body> -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-mismatched-url.html
r125531 r197038 9 9 </script> 10 10 <script src="/plugins/resources/mock-plugin-logger.js"></script> 11 <meta http-equiv=" X-WebKit-CSP" content="plugin-types application/x-invalid-type">11 <meta http-equiv="Content-Security-Policy" content="plugin-types application/x-invalid-type"> 12 12 </head> 13 13 <body> -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-data.html
r169475 r197038 12 12 </script> 13 13 <script src="/plugins/resources/mock-plugin-logger.js"></script> 14 <meta http-equiv=" X-WebKit-CSP" content="plugin-types application/x-invalid-type">14 <meta http-equiv="Content-Security-Policy" content="plugin-types application/x-invalid-type"> 15 15 </head> 16 16 <body> -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-url-expected.txt
r126047 r197038 2 2 3 3 Given a `plugin-types` directive, plugins have to declare a type explicitly. No declared type, no load. This test passes if there's a console message above. 4 5 --------6 Frame: '<!--framePath //<!--frame0-->-->'7 --------8 -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-url.html
r125531 r197038 8 8 } 9 9 </script> 10 <meta http-equiv=" X-WebKit-CSP" content="plugin-types application/x-invalid-type">10 <meta http-equiv="Content-Security-Policy" content="plugin-types application/x-invalid-type"> 11 11 </head> 12 12 <body> -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-nourl-allowed.html
r125531 r197038 6 6 testRunner.dumpAsText(); 7 7 </script> 8 <meta http-equiv=" X-WebKit-CSP" content="plugin-types application/x-webkit-test-netscape">8 <meta http-equiv="Content-Security-Policy" content="plugin-types application/x-webkit-test-netscape"> 9 9 </head> 10 10 <body> -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-nourl-blocked.html
r169475 r197038 9 9 runAfterPluginLoad(null, NotifyDone); 10 10 </script> 11 <meta http-equiv=" X-WebKit-CSP" content="plugin-types text/plain">11 <meta http-equiv="Content-Security-Policy" content="plugin-types text/plain"> 12 12 </head> 13 13 <body> -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-url-01.html
r133095 r197038 12 12 </script> 13 13 </head> 14 <body onload= "testExperimentalPolicy()">14 <body onload='runTests()'> 15 15 <p> 16 16 This tests our handling of `data:` URLs, given a `plugin-types` CSP … … 18 18 contains "PASS" or no text at all, and no console warnings appear above. 19 19 </p> 20 </body> 21 </html> -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-url-02.html
r133095 r197038 11 11 </script> 12 12 </head> 13 <body onload= "testExperimentalPolicy()">13 <body onload='runTests()'> 14 14 <p> 15 15 This tests our handling of non-`data:` URLs, given a `plugin-types` CSP … … 17 17 contains "FAIL" and four sets of console logs appear above. 18 18 </p> 19 </body> 20 </html> -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/resources/echo-object-data.pl
r153953 r197038 6 6 7 7 print "Content-Type: text/html; charset=UTF-8\n"; 8 my $experimental = $cgi->param('experimental') || ""; 9 if ($experimental eq 'true') { 10 print "X-WebKit-CSP: " . $cgi->param('csp') . "\n\n"; 11 } else { 12 print "Content-Security-Policy: " . $cgi->param('csp') . "\n\n"; 13 } 8 print "Content-Security-Policy: " . $cgi->param('csp') . "\n\n"; 14 9 15 10 print "<!DOCTYPE html>\n"; -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/resources/multiple-iframe-plugin-test.js
r169475 r197038 5 5 } 6 6 7 function testExperimentalPolicy() { 8 testImpl(true); 7 function runTests() 8 { 9 runNextTest(); 9 10 } 10 11 11 function test() { 12 testImpl(false); 13 } 14 15 function testImpl(experimental) { 16 if (tests.length === 0) 17 return finishTesting(); 18 var baseURL = "/security/contentSecurityPolicy/"; 19 var current = tests.shift(); 20 var iframe = document.createElement("iframe"); 21 iframe.src = baseURL + "resources/echo-object-data.pl?" + 22 "experimental=" + (experimental ? "true" : "false") + 23 "&csp=" + escape(current[1]); 24 25 if (current[0]) 26 iframe.src += "&log=PASS."; 27 else 28 iframe.src += "&log=FAIL."; 29 30 if (current[2]) 31 iframe.src += "&plugin=" + escape(current[2]); 32 else { 33 iframe.src += "&plugin=data:application/x-webkit-test-netscape,logifloaded"; 12 function runNextTest() 13 { 14 var currentTest = tests.shift(); 15 if (!currentTest) { 16 if (window.testRunner) 17 setTimeout("testRunner.notifyDone()", 0); 18 return; 34 19 } 35 20 36 if (current[3] !== undefined) 37 iframe.src += "&type=" + escape(current[3]); 38 else 39 iframe.src += "&type=application/x-webkit-test-netscape"; 40 21 var iframe = document.createElement("iframe"); 41 22 iframe.onload = function() { 42 23 if (window.internals) 43 24 internals.updateLayoutIgnorePendingStylesheetsAndRunPostLayoutTasks(iframe); 44 testImpl(experimental);25 runNextTest(); 45 26 }; 27 var url = "/security/contentSecurityPolicy/resources/echo-object-data.pl?csp=" + encodeURIComponent(currentTest[1]); 28 url += "&log=" + (currentTest[0] ? "PASS." : "FAIL."); 29 url += "&plugin=" + (currentTest[2] ? encodeURIComponent(currentTest[2]) : "data:application/x-webkit-test-netscape,logifloaded"); 30 url += "&type=" + (currentTest[3] !== undefined ? encodeURIComponent(currentTest[3]) : "application/x-webkit-test-netscape"); 31 iframe.src = url; 46 32 document.body.appendChild(iframe); 47 33 } 48 49 function finishTesting() {50 if (window.testRunner) {51 setTimeout("testRunner.notifyDone()", 0);52 }53 return true;54 } -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon-expected.txt
r197007 r197038 4 4 CONSOLE MESSAGE: The Content Security Policy directive 'script-src' contains 'form-action' as a source expression. Did you mean 'script-src ...; form-action...' (note the semicolon)? 5 5 CONSOLE MESSAGE: The Content Security Policy directive 'script-src' contains 'base-uri' as a source expression. Did you mean 'script-src ...; base-uri...' (note the semicolon)? 6 CONSOLE MESSAGE: The Content Security Policy directive 'script-src' contains 'plugin-types' as a source expression. Did you mean 'script-src ...; plugin-types...' (note the semicolon)? 6 7 If a web author forgets a semicolon, we should do our best to warn them that the policy they've defined is probably not what they intended. 7 8 -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon.html
r197007 r197038 6 6 var tests = [ 7 7 ['yes', 'default-src \'self\' script-src example.com', 'resources/script.js'], 8 ['yes', "script-src 'self' object-src 'self' style-src * form-action 'self' base-uri 'self' ", 'resources/script.js'],8 ['yes', "script-src 'self' object-src 'self' style-src * form-action 'self' base-uri 'self' plugin-types application/x-webkit-test-netscape", 'resources/script.js'], 9 9 ]; 10 10 </script> -
trunk/Source/WebCore/ChangeLog
r197032 r197038 1 2016-02-24 Daniel Bates <dabates@apple.com> 2 3 CSP: Enable plugin-types directive by default 4 https://bugs.webkit.org/show_bug.cgi?id=154420 5 <rdar://problem/24730322> 6 7 Reviewed by Brent Fulgham. 8 9 * page/csp/ContentSecurityPolicyDirectiveList.cpp: 10 (WebCore::isExperimentalDirectiveName): Move plugin-types from the directives considered 11 experimental to... 12 (WebCore::isCSPDirectiveName): ...the list of standard directives. 13 (WebCore::ContentSecurityPolicyDirectiveList::addDirective): Move logic to parse the plugin-types 14 directive outside the ENABLE(CSP_NEXT) macro guarded section/experimental feature runtime flag. 15 1 16 2016-02-24 Ryan Haddad <ryanhaddad@apple.com> 2 17 -
trunk/Source/WebCore/page/csp/ContentSecurityPolicyDirectiveList.cpp
r197007 r197038 60 60 static inline bool isExperimentalDirectiveName(const String& name) 61 61 { 62 return equalLettersIgnoringASCIICase(name, pluginTypes) || equalLettersIgnoringASCIICase(name,reflectedXSS);62 return equalLettersIgnoringASCIICase(name, reflectedXSS); 63 63 } 64 64 … … 83 83 || equalLettersIgnoringASCIICase(name, mediaSrc) 84 84 || equalLettersIgnoringASCIICase(name, objectSrc) 85 || equalLettersIgnoringASCIICase(name, pluginTypes) 85 86 || equalLettersIgnoringASCIICase(name, reportURI) 86 87 || equalLettersIgnoringASCIICase(name, sandbox) … … 603 604 else if (equalLettersIgnoringASCIICase(name, baseURI)) 604 605 setCSPDirective<ContentSecurityPolicySourceListDirective>(name, value, m_baseURI); 606 else if (equalLettersIgnoringASCIICase(name, pluginTypes)) 607 setCSPDirective<ContentSecurityPolicyMediaListDirective>(name, value, m_pluginTypes); 605 608 else if (equalLettersIgnoringASCIICase(name, sandbox)) 606 609 applySandboxPolicy(name, value); … … 609 612 #if ENABLE(CSP_NEXT) 610 613 else if (m_policy.experimentalFeaturesEnabled()) { 611 if (equalLettersIgnoringASCIICase(name, pluginTypes)) 612 setCSPDirective<ContentSecurityPolicyMediaListDirective>(name, value, m_pluginTypes); 613 else if (equalLettersIgnoringASCIICase(name, reflectedXSS)) 614 if (equalLettersIgnoringASCIICase(name, reflectedXSS)) 614 615 parseReflectedXSS(name, value); 615 616 else
Note:
See TracChangeset
for help on using the changeset viewer.