⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 197038 in webkit


Ignore:
Timestamp:
Feb 24, 2016, 10:51:58 AM (11 years ago)
Author:
dbates@webkit.org
Message:

CSP: Enable plugin-types directive by default
​https://bugs.webkit.org/show_bug.cgi?id=154420
<rdar://problem/24730322>

Reviewed by Brent Fulgham.

Source/WebCore:

  • page/csp/ContentSecurityPolicyDirectiveList.cpp:

(WebCore::isExperimentalDirectiveName): Move plugin-types from the directives considered
experimental to...
(WebCore::isCSPDirectiveName): ...the list of standard directives.
(WebCore::ContentSecurityPolicyDirectiveList::addDirective): Move logic to parse the plugin-types
directive outside the ENABLE(CSP_NEXT) macro guarded section/experimental feature runtime flag.

LayoutTests:

  • TestExpectations: Mark http/tests/security/contentSecurityPolicy/1.1/plugintypes*.html tests as PASS so that we run them.
  • http/tests/security/contentSecurityPolicy/1.1/plugintypes-invalid-expected.txt: Update expected result.
  • http/tests/security/contentSecurityPolicy/1.1/plugintypes-invalid.html: Call runTests() following changes to multiple-iframe-plugin-test.js.

Also add closing tags for <body> and <html> to make the document well-formed.

  • http/tests/security/contentSecurityPolicy/1.1/plugintypes-mismatched-data.html: Substitute "Content-Security-Policy" for "X-WebKit-CSP";

no behavior change.

  • http/tests/security/contentSecurityPolicy/1.1/plugintypes-mismatched-url.html: Ditto.
  • http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-data.html: Ditto.
  • http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-url-expected.txt: Update expected result.
  • http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-url.html: Substitute "Content-Security-Policy" for "X-WebKit-CSP";

no behavior change.

  • http/tests/security/contentSecurityPolicy/1.1/plugintypes-nourl-allowed.html: Ditto.
  • http/tests/security/contentSecurityPolicy/1.1/plugintypes-nourl-blocked.html: Ditto.
  • http/tests/security/contentSecurityPolicy/1.1/plugintypes-url-01.html: Call runTests() following changes to multiple-iframe-plugin-test.js.

Also add closing tags for <body> and <html> to make the document well-formed.

  • http/tests/security/contentSecurityPolicy/1.1/plugintypes-url-02.html: Ditto.
  • http/tests/security/contentSecurityPolicy/resources/echo-object-data.pl: Remove logic to support Content Security Policy header X-WebKit-CSP

as it is sufficient to make use of the standardized header Content-Security-Policy.

  • http/tests/security/contentSecurityPolicy/resources/multiple-iframe-plugin-test.js: Simplify code now that we do not pass query string parameter

experimental to script echo-object-data.pl.
(runTests): Runs all the sub-tests.
(runNextTest.iframe.onload): Formerly named testImpl.iframe.onload.
(runNextTest): Formerly named testImpl. Runs the next sub-test.
(testExperimentalPolicy): Deleted.
(test): Deleted.
(testImpl.iframe.onload): Deleted.
(testImpl): Deleted.
(finishTesting): Deleted.

  • http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon-expected.txt: Update expected result based on change to test (below).
  • http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon.html: Modified to test that we emit

a console warning when plugin-types is used as a source expression.

Location:
trunk
Files:
19 edited

Legend:

Unmodified
Added
Removed
  • trunk/LayoutTests/ChangeLog

    r197036 r197038  
     12016-02-24  Daniel Bates  <dabates@apple.com>
     2
     3        CSP: Enable plugin-types directive by default
     4        https://bugs.webkit.org/show_bug.cgi?id=154420
     5        <rdar://problem/24730322>
     6
     7        Reviewed by Brent Fulgham.
     8
     9        * TestExpectations: Mark http/tests/security/contentSecurityPolicy/1.1/plugintypes*.html tests as PASS so that we run them.
     10        * http/tests/security/contentSecurityPolicy/1.1/plugintypes-invalid-expected.txt: Update expected result.
     11        * http/tests/security/contentSecurityPolicy/1.1/plugintypes-invalid.html: Call runTests() following changes to multiple-iframe-plugin-test.js.
     12        Also add closing tags for <body> and <html> to make the document well-formed.
     13        * http/tests/security/contentSecurityPolicy/1.1/plugintypes-mismatched-data.html: Substitute "Content-Security-Policy" for "X-WebKit-CSP";
     14        no behavior change.
     15        * http/tests/security/contentSecurityPolicy/1.1/plugintypes-mismatched-url.html: Ditto.
     16        * http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-data.html: Ditto.
     17        * http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-url-expected.txt: Update expected result.
     18        * http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-url.html: Substitute "Content-Security-Policy" for "X-WebKit-CSP";
     19        no behavior change.
     20        * http/tests/security/contentSecurityPolicy/1.1/plugintypes-nourl-allowed.html: Ditto.
     21        * http/tests/security/contentSecurityPolicy/1.1/plugintypes-nourl-blocked.html: Ditto.
     22        * http/tests/security/contentSecurityPolicy/1.1/plugintypes-url-01.html: Call runTests() following changes to multiple-iframe-plugin-test.js.
     23        Also add closing tags for <body> and <html> to make the document well-formed.
     24        * http/tests/security/contentSecurityPolicy/1.1/plugintypes-url-02.html: Ditto.
     25        * http/tests/security/contentSecurityPolicy/resources/echo-object-data.pl: Remove logic to support Content Security Policy header X-WebKit-CSP
     26        as it is sufficient to make use of the standardized header Content-Security-Policy.
     27        * http/tests/security/contentSecurityPolicy/resources/multiple-iframe-plugin-test.js: Simplify code now that we do not pass query string parameter
     28        experimental to script echo-object-data.pl.
     29        (runTests): Runs all the sub-tests.
     30        (runNextTest.iframe.onload): Formerly named testImpl.iframe.onload.
     31        (runNextTest): Formerly named testImpl. Runs the next sub-test.
     32        (testExperimentalPolicy): Deleted.
     33        (test): Deleted.
     34        (testImpl.iframe.onload): Deleted.
     35        (testImpl): Deleted.
     36        (finishTesting): Deleted.
     37        * http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon-expected.txt: Update expected result based on change to test (below).
     38        * http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon.html: Modified to test that we emit
     39        a console warning when plugin-types is used as a source expression.
     40
    1412016-02-24  Ryan Haddad  <ryanhaddad@apple.com>
    242
  • trunk/LayoutTests/TestExpectations

    r197007 r197038  
    818818webkit.org/b/154203 http/tests/security/contentSecurityPolicy/1.1/scripthash-default-src.html
    819819webkit.org/b/154203 http/tests/security/contentSecurityPolicy/1.1/stylehash-default-src.html
     820http/tests/security/contentSecurityPolicy/1.1/plugintypes-affects-child.html [ Pass ]
     821http/tests/security/contentSecurityPolicy/1.1/plugintypes-invalid.html [ Pass ]
     822http/tests/security/contentSecurityPolicy/1.1/plugintypes-mismatched-data.html [ Pass ]
     823http/tests/security/contentSecurityPolicy/1.1/plugintypes-mismatched-url.html [ Pass ]
     824http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-data.html [ Pass ]
     825http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-url.html [ Pass ]
     826http/tests/security/contentSecurityPolicy/1.1/plugintypes-nourl-allowed.html [ Pass ]
     827http/tests/security/contentSecurityPolicy/1.1/plugintypes-nourl-blocked.html [ Pass ]
     828http/tests/security/contentSecurityPolicy/1.1/plugintypes-url-01.html [ Pass ]
     829http/tests/security/contentSecurityPolicy/1.1/plugintypes-url-02.html [ Pass ]
    820830webkit.org/b/111869 http/tests/security/contentSecurityPolicy/eval-blocked-and-sends-report.html
    821831webkit.org/b/115700 http/tests/security/contentSecurityPolicy/inline-event-handler-blocked-after-injecting-meta.html [ Failure ]
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-invalid-expected.txt

    r125531 r197038  
    66
    77CONSOLE MESSAGE: Refused to load 'data:application/x-webkit-test-netscape,logifloaded' (MIME type 'application/x-webkit-test-netscape') because it violates the following Content Security Policy Directive: 'plugin-types '.
     8
     9CONSOLE MESSAGE: Invalid plugin type in 'plugin-types' Content Security Policy directive: ''none''.
     10
     11CONSOLE MESSAGE: Refused to load 'data:application/x-webkit-test-netscape,logifloaded' (MIME type 'application/x-webkit-test-netscape') because it violates the following Content Security Policy Directive: 'plugin-types 'none''.
    812
    913CONSOLE MESSAGE: Invalid plugin type in 'plugin-types' Content Security Policy directive: 'text'.
    … …  
    7175Frame: '<!--framePath //<!--frame7-->-->'
    7276--------
     77
     78
     79--------
     80Frame: '<!--framePath //<!--frame8-->-->'
     81--------
    7382PASS.
    7483
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-invalid.html

    r195367 r197038  
    1717</script>
    1818</head>
    19 <body onload="testExperimentalPolicy()">
     19<body onload="runTests()">
    2020    <p>
    2121        This tests our handling of invalid `plugin-types` CSP directives.
    … …  
    2323        either "PASS" or no text at all.
    2424    </p>
     25</body>
     26</html>
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-mismatched-data.html

    r125531 r197038  
    88}
    99</script>
    10 <meta http-equiv="X-WebKit-CSP" content="plugin-types application/x-invalid-type">
     10<meta http-equiv="Content-Security-Policy" content="plugin-types application/x-invalid-type">
    1111</head>
    1212<body>
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-mismatched-url.html

    r125531 r197038  
    99</script>
    1010<script src="/plugins/resources/mock-plugin-logger.js"></script>
    11 <meta http-equiv="X-WebKit-CSP" content="plugin-types application/x-invalid-type">
     11<meta http-equiv="Content-Security-Policy" content="plugin-types application/x-invalid-type">
    1212</head>
    1313<body>
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-data.html

    r169475 r197038  
    1212</script>
    1313<script src="/plugins/resources/mock-plugin-logger.js"></script>
    14 <meta http-equiv="X-WebKit-CSP" content="plugin-types application/x-invalid-type">
     14<meta http-equiv="Content-Security-Policy" content="plugin-types application/x-invalid-type">
    1515</head>
    1616<body>
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-url-expected.txt

    r126047 r197038  
    22
    33Given a `plugin-types` directive, plugins have to declare a type explicitly. No declared type, no load. This test passes if there's a console message above. 
    4 
    5 --------
    6 Frame: '<!--framePath //<!--frame0-->-->'
    7 --------
    8 
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-notype-url.html

    r125531 r197038  
    88}
    99</script>
    10 <meta http-equiv="X-WebKit-CSP" content="plugin-types application/x-invalid-type">
     10<meta http-equiv="Content-Security-Policy" content="plugin-types application/x-invalid-type">
    1111</head>
    1212<body>
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-nourl-allowed.html

    r125531 r197038  
    66    testRunner.dumpAsText();
    77</script>
    8 <meta http-equiv="X-WebKit-CSP" content="plugin-types application/x-webkit-test-netscape">
     8<meta http-equiv="Content-Security-Policy" content="plugin-types application/x-webkit-test-netscape">
    99</head>
    1010<body>
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-nourl-blocked.html

    r169475 r197038  
    99    runAfterPluginLoad(null, NotifyDone);
    1010</script>
    11 <meta http-equiv="X-WebKit-CSP" content="plugin-types text/plain">
     11<meta http-equiv="Content-Security-Policy" content="plugin-types text/plain">
    1212</head>
    1313<body>
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-url-01.html

    r133095 r197038  
    1212</script>
    1313</head>
    14 <body onload="testExperimentalPolicy()">
     14<body onload='runTests()'>
    1515    <p>
    1616        This tests our handling of `data:` URLs, given a `plugin-types` CSP
    … …  
    1818        contains "PASS" or no text at all, and no console warnings appear above.
    1919    </p>
     20</body>
     21</html>
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/plugintypes-url-02.html

    r133095 r197038  
    1111</script>
    1212</head>
    13 <body onload="testExperimentalPolicy()">
     13<body onload='runTests()'>
    1414    <p>
    1515        This tests our handling of non-`data:` URLs, given a `plugin-types` CSP
    … …  
    1717        contains "FAIL" and four sets of console logs appear above.
    1818    </p>
     19</body>
     20</html>
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/resources/echo-object-data.pl

    r153953 r197038  
    66
    77print "Content-Type: text/html; charset=UTF-8\n";
    8 my $experimental = $cgi->param('experimental') || "";
    9 if ($experimental eq 'true') {
    10     print "X-WebKit-CSP: " . $cgi->param('csp') . "\n\n";
    11 } else {
    12     print "Content-Security-Policy: " . $cgi->param('csp') . "\n\n";
    13 }
     8print "Content-Security-Policy: " . $cgi->param('csp') . "\n\n";
    149
    1510print "<!DOCTYPE html>\n";
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/resources/multiple-iframe-plugin-test.js

    r169475 r197038  
    55}
    66
    7 function testExperimentalPolicy() {
    8     testImpl(true);
     7function runTests()
     8{
     9    runNextTest();
    910}
    1011
    11 function test() {
    12     testImpl(false);
    13 }
    14 
    15 function testImpl(experimental) {
    16     if (tests.length === 0)
    17         return finishTesting();
    18     var baseURL = "/security/contentSecurityPolicy/";
    19     var current = tests.shift();
    20     var iframe = document.createElement("iframe");
    21     iframe.src = baseURL + "resources/echo-object-data.pl?" +
    22                  "experimental=" + (experimental ? "true" : "false") +
    23                  "&csp=" + escape(current[1]);
    24 
    25     if (current[0])
    26         iframe.src += "&log=PASS.";
    27     else
    28         iframe.src += "&log=FAIL.";
    29 
    30     if (current[2])
    31         iframe.src += "&plugin=" + escape(current[2]);
    32     else {
    33         iframe.src += "&plugin=data:application/x-webkit-test-netscape,logifloaded";
     12function runNextTest()
     13{
     14    var currentTest = tests.shift();
     15    if (!currentTest) {
     16        if (window.testRunner)
     17            setTimeout("testRunner.notifyDone()", 0);
     18        return;
    3419    }
    3520
    36     if (current[3] !== undefined)
    37         iframe.src += "&type=" + escape(current[3]);
    38     else
    39         iframe.src += "&type=application/x-webkit-test-netscape";
    40 
     21    var iframe = document.createElement("iframe");
    4122    iframe.onload = function() {
    4223        if (window.internals)
    4324            internals.updateLayoutIgnorePendingStylesheetsAndRunPostLayoutTasks(iframe);
    44         testImpl(experimental);
     25        runNextTest();
    4526    };
     27    var url = "/security/contentSecurityPolicy/resources/echo-object-data.pl?csp=" + encodeURIComponent(currentTest[1]);
     28    url += "&log=" + (currentTest[0] ? "PASS." : "FAIL.");
     29    url += "&plugin=" + (currentTest[2] ? encodeURIComponent(currentTest[2]) : "data:application/x-webkit-test-netscape,logifloaded");
     30    url += "&type=" + (currentTest[3] !== undefined ? encodeURIComponent(currentTest[3]) : "application/x-webkit-test-netscape");
     31    iframe.src = url;
    4632    document.body.appendChild(iframe);
    4733}
    48 
    49 function finishTesting() {
    50     if (window.testRunner) {
    51         setTimeout("testRunner.notifyDone()", 0);
    52     }
    53     return true;
    54 }
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon-expected.txt

    r197007 r197038  
    44CONSOLE MESSAGE: The Content Security Policy directive 'script-src' contains 'form-action' as a source expression. Did you mean 'script-src ...; form-action...' (note the semicolon)?
    55CONSOLE MESSAGE: The Content Security Policy directive 'script-src' contains 'base-uri' as a source expression. Did you mean 'script-src ...; base-uri...' (note the semicolon)?
     6CONSOLE MESSAGE: The Content Security Policy directive 'script-src' contains 'plugin-types' as a source expression. Did you mean 'script-src ...; plugin-types...' (note the semicolon)?
    67If a web author forgets a semicolon, we should do our best to warn them that the policy they've defined is probably not what they intended.
    78
  • trunk/LayoutTests/http/tests/security/contentSecurityPolicy/source-list-parsing-no-semicolon.html

    r197007 r197038  
    66var tests = [
    77    ['yes', 'default-src \'self\' script-src example.com', 'resources/script.js'],
    8     ['yes', "script-src 'self' object-src 'self' style-src * form-action 'self' base-uri 'self'", 'resources/script.js'],
     8    ['yes', "script-src 'self' object-src 'self' style-src * form-action 'self' base-uri 'self' plugin-types application/x-webkit-test-netscape", 'resources/script.js'],
    99];
    1010</script>
  • trunk/Source/WebCore/ChangeLog

    r197032 r197038  
     12016-02-24  Daniel Bates  <dabates@apple.com>
     2
     3        CSP: Enable plugin-types directive by default
     4        https://bugs.webkit.org/show_bug.cgi?id=154420
     5        <rdar://problem/24730322>
     6
     7        Reviewed by Brent Fulgham.
     8
     9        * page/csp/ContentSecurityPolicyDirectiveList.cpp:
     10        (WebCore::isExperimentalDirectiveName): Move plugin-types from the directives considered
     11        experimental to...
     12        (WebCore::isCSPDirectiveName): ...the list of standard directives.
     13        (WebCore::ContentSecurityPolicyDirectiveList::addDirective): Move logic to parse the plugin-types
     14        directive outside the ENABLE(CSP_NEXT) macro guarded section/experimental feature runtime flag.
     15
    1162016-02-24  Ryan Haddad  <ryanhaddad@apple.com>
    217
  • trunk/Source/WebCore/page/csp/ContentSecurityPolicyDirectiveList.cpp

    r197007 r197038  
    6060static inline bool isExperimentalDirectiveName(const String& name)
    6161{
    62     return equalLettersIgnoringASCIICase(name, pluginTypes) || equalLettersIgnoringASCIICase(name, reflectedXSS);
     62    return equalLettersIgnoringASCIICase(name, reflectedXSS);
    6363}
    6464
    … …  
    8383        || equalLettersIgnoringASCIICase(name, mediaSrc)
    8484        || equalLettersIgnoringASCIICase(name, objectSrc)
     85        || equalLettersIgnoringASCIICase(name, pluginTypes)
    8586        || equalLettersIgnoringASCIICase(name, reportURI)
    8687        || equalLettersIgnoringASCIICase(name, sandbox)
    … …  
    603604    else if (equalLettersIgnoringASCIICase(name, baseURI))
    604605        setCSPDirective<ContentSecurityPolicySourceListDirective>(name, value, m_baseURI);
     606    else if (equalLettersIgnoringASCIICase(name, pluginTypes))
     607        setCSPDirective<ContentSecurityPolicyMediaListDirective>(name, value, m_pluginTypes);
    605608    else if (equalLettersIgnoringASCIICase(name, sandbox))
    606609        applySandboxPolicy(name, value);
    … …  
    609612#if ENABLE(CSP_NEXT)
    610613    else if (m_policy.experimentalFeaturesEnabled()) {
    611         if (equalLettersIgnoringASCIICase(name, pluginTypes))
    612             setCSPDirective<ContentSecurityPolicyMediaListDirective>(name, value, m_pluginTypes);
    613         else if (equalLettersIgnoringASCIICase(name, reflectedXSS))
     614        if (equalLettersIgnoringASCIICase(name, reflectedXSS))
    614615            parseReflectedXSS(name, value);
    615616        else
Note: See TracChangeset for help on using the changeset viewer.