Changeset 197083 in webkit
- Timestamp:
- Feb 25, 2016, 2:26:03 AM (11 years ago)
- Location:
- releases/WebKitGTK/webkit-2.12
- Files:
-
- 2 added
- 24 edited
- 1 moved
-
LayoutTests/ChangeLog (modified) (1 diff)
-
LayoutTests/TestExpectations (modified) (3 diffs)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/report-uri-effective-directive-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/report-uri-effective-directive.php (moved) (moved from releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/report-uri-effective-directive.html ) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-and-enforce-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-blocked-data-uri-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-blocked-file-uri-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-blocked-uri-cross-origin-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-blocked-uri-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-cross-origin-no-cookies-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-cross-origin-no-cookies-when-private-browsing-enabled-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-cross-origin-no-cookies-when-private-browsing-toggled-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-only-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-only-from-header-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-same-origin-no-cookies-when-private-browsing-toggled-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-same-origin-with-cookies-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-same-origin-with-cookies-when-private-browsing-enabled-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-status-code-zero-when-using-https-expected.txt (added)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-status-code-zero-when-using-https.html (added)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-uri-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-uri-from-child-frame-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-uri-from-child-frame.html (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-uri-from-inline-javascript-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-uri-from-javascript-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-uri-scheme-relative-expected.txt (modified) (1 diff)
-
Source/WebCore/ChangeLog (modified) (1 diff)
-
Source/WebCore/page/csp/ContentSecurityPolicy.cpp (modified) (2 diffs)
Legend:
- Unmodified
- Added
- Removed
-
releases/WebKitGTK/webkit-2.12/LayoutTests/ChangeLog
r197082 r197083 1 2016-02-21 Daniel Bates <dabates@apple.com> 2 3 CSP: Violation report should include HTTP status code and effective-directive of protected resource 4 https://bugs.webkit.org/show_bug.cgi?id=154288 5 <rdar://problem/24674982> 6 And 7 https://bugs.webkit.org/show_bug.cgi?id=115707 8 <rdar://problem/24383128> 9 10 Reviewed by Brent Fulgham. 11 12 Add new test http/tests/security/contentSecurityPolicy/report-status-code-zero-when-using-https.html to ensure 13 that the CSP report property status-code is 0 when the protected document is delivered over HTTPS. Fix a 14 correctness issue in the result for test http/tests/security/contentSecurityPolicy/report-blocked-file-uri.html 15 and update the expected results for the following tests now that the CSP violation report includes properties 16 status-code and effective-directive: 17 http/tests/security/contentSecurityPolicy/report-cross-origin-no-cookies-when-private-browsing-enabled.php 18 http/tests/security/contentSecurityPolicy/report-cross-origin-no-cookies-when-private-browsing-toggled.php 19 http/tests/security/contentSecurityPolicy/report-same-origin-no-cookies-when-private-browsing-toggled.php 20 http/tests/security/contentSecurityPolicy/report-same-origin-with-cookies-when-private-browsing-enabled.php 21 22 The rest of the changes to the expected results are cosmetic and reflect the difference in wording for inline 23 script violations between WebKit and Blink. We will consider adopting wording similar to Blink in 24 <https://bugs.webkit.org/show_bug.cgi?id=153242>. 25 26 * TestExpectations: Remove entries for tests that now pass. Add test http/tests/security/contentSecurityPolicy/1.1/report-uri-effective-directive.php. 27 * http/tests/security/contentSecurityPolicy/1.1/report-uri-effective-directive-expected.txt: 28 * http/tests/security/contentSecurityPolicy/1.1/report-uri-effective-directive.php: Renamed from LayoutTests/http/tests/security/contentSecurityPolicy/1.1/report-uri-effective-directive.html. The report-uri 29 directive is only honored when defined in a policy delivered via an HTTP header. We convert this 30 HTML file to a PHP script to be able to deliver a Content-Security-Policy HTTP header. 31 * http/tests/security/contentSecurityPolicy/report-and-enforce-expected.txt: 32 * http/tests/security/contentSecurityPolicy/report-blocked-data-uri-expected.txt: Cosmetic change. 33 * http/tests/security/contentSecurityPolicy/report-blocked-file-uri-expected.txt: Ditto. 34 * http/tests/security/contentSecurityPolicy/report-blocked-uri-cross-origin-expected.txt: Ditto. 35 * http/tests/security/contentSecurityPolicy/report-blocked-uri-expected.txt: Ditto. 36 * http/tests/security/contentSecurityPolicy/report-cross-origin-no-cookies-expected.txt: Ditto. 37 * http/tests/security/contentSecurityPolicy/report-cross-origin-no-cookies-when-private-browsing-enabled-expected.txt: Update expected result now 38 that the report includes properties status-code and effective-directive. 39 * http/tests/security/contentSecurityPolicy/report-cross-origin-no-cookies-when-private-browsing-toggled-expected.txt: Ditto. 40 * http/tests/security/contentSecurityPolicy/report-only-expected.txt: Cosmetic change. 41 * http/tests/security/contentSecurityPolicy/report-only-from-header-expected.txt: Ditto. 42 * http/tests/security/contentSecurityPolicy/report-same-origin-no-cookies-when-private-browsing-toggled-expected.txt: Update expected result now 43 that the report includes properties status-code and effective-directive. 44 * http/tests/security/contentSecurityPolicy/report-same-origin-with-cookies-expected.txt: Cosmetic change. 45 * http/tests/security/contentSecurityPolicy/report-same-origin-with-cookies-when-private-browsing-enabled-expected.txt: Update expected result now 46 that the report includes properties status-code and effective-directive. 47 * http/tests/security/contentSecurityPolicy/report-status-code-zero-when-using-https-expected.txt: Added. 48 * http/tests/security/contentSecurityPolicy/report-status-code-zero-when-using-https.html: Added. 49 * http/tests/security/contentSecurityPolicy/report-uri-expected.txt: Cosmetic change. 50 * http/tests/security/contentSecurityPolicy/report-uri-from-child-frame-expected.txt: Cosmetic change. 51 * http/tests/security/contentSecurityPolicy/report-uri-from-child-frame.html: Fix ill-formed markup; substitute </iframe> for </script>. 52 * http/tests/security/contentSecurityPolicy/report-uri-from-inline-javascript-expected.txt: Cosmetic change. 53 * http/tests/security/contentSecurityPolicy/report-uri-from-javascript-expected.txt: Ditto. 54 * http/tests/security/contentSecurityPolicy/report-uri-scheme-relative-expected.txt: Ditto. 55 1 56 2016-02-21 Daniel Bates <dabates@apple.com> 2 57 -
releases/WebKitGTK/webkit-2.12/LayoutTests/TestExpectations
r197082 r197083 804 804 webkit.org/b/85558 http/tests/security/contentSecurityPolicy/1.1 805 805 http/tests/security/contentSecurityPolicy/1.1/child-src [ Pass ] 806 http/tests/security/contentSecurityPolicy/1.1/report-uri-effective-directive.php [ Pass ] 806 807 webkit.org/b/154203 http/tests/security/contentSecurityPolicy/1.1/frame-ancestors/frame-ancestors-overrides-xfo.html 807 808 webkit.org/b/154203 http/tests/security/contentSecurityPolicy/1.1/scripthash-default-src.html … … 809 810 webkit.org/b/111869 http/tests/security/contentSecurityPolicy/eval-blocked-and-sends-report.html 810 811 webkit.org/b/115700 http/tests/security/contentSecurityPolicy/inline-event-handler-blocked-after-injecting-meta.html [ Failure ] 811 webkit.org/b/115702 webkit.org/b/154288 http/tests/security/contentSecurityPolicy/report-cross-origin-no-cookies.php [ Failure ]812 webkit.org/b/115702 webkit.org/b/154288 http/tests/security/contentSecurityPolicy/report-same-origin-with-cookies.php [ Failure ]813 webkit.org/b/115707 http/tests/security/contentSecurityPolicy/report-uri-scheme-relative.php [ Failure ]814 812 webkit.org/b/153148 http/tests/security/contentSecurityPolicy/eval-allowed-in-report-only-mode-and-sends-report.html 815 813 webkit.org/b/153150 http/tests/security/contentSecurityPolicy/frame-src-cross-origin-load.html … … 830 828 webkit.org/b/153160 http/tests/security/contentSecurityPolicy/plugin-in-iframe-with-csp.html [ Failure ] 831 829 webkit.org/b/153161 http/tests/security/contentSecurityPolicy/register-bypassing-scheme-partial.html [ Failure ] 832 webkit.org/b/153162 webkit.org/b/154288 http/tests/security/contentSecurityPolicy/report-multiple-violations-01.html [ Failure ] 833 webkit.org/b/153162 webkit.org/b/154288 http/tests/security/contentSecurityPolicy/report-multiple-violations-02.html [ Failure ] 834 webkit.org/b/153242 webkit.org/b/154288 http/tests/security/contentSecurityPolicy/report-blocked-file-uri.php [ Failure ] 835 webkit.org/b/153242 webkit.org/b/154288 http/tests/security/contentSecurityPolicy/report-blocked-uri-cross-origin.php [ Failure ] 836 webkit.org/b/153242 webkit.org/b/154288 http/tests/security/contentSecurityPolicy/report-blocked-uri.php [ Failure ] 837 webkit.org/b/153242 webkit.org/b/154288 http/tests/security/contentSecurityPolicy/report-only-from-header.php [ Failure ] 838 webkit.org/b/153242 webkit.org/b/154288 http/tests/security/contentSecurityPolicy/report-only.php [ Failure ] 839 webkit.org/b/153242 webkit.org/b/154288 http/tests/security/contentSecurityPolicy/report-uri-from-child-frame.html [ Failure ] 840 webkit.org/b/153242 webkit.org/b/154288 http/tests/security/contentSecurityPolicy/report-uri-from-inline-javascript.php [ Failure ] 841 webkit.org/b/153242 webkit.org/b/154288 http/tests/security/contentSecurityPolicy/report-uri-from-javascript.php [ Failure ] 842 webkit.org/b/153242 webkit.org/b/154288 http/tests/security/contentSecurityPolicy/report-uri.php [ Failure ] 843 webkit.org/b/153242 webkit.org/b/154288 http/tests/security/contentSecurityPolicy/report-and-enforce.php [ Failure ] 844 webkit.org/b/153242 webkit.org/b/154288 http/tests/security/contentSecurityPolicy/report-blocked-data-uri.php [ Failure ] 830 webkit.org/b/153162 http/tests/security/contentSecurityPolicy/report-multiple-violations-01.html [ Failure ] 831 webkit.org/b/153162 http/tests/security/contentSecurityPolicy/report-multiple-violations-02.html [ Failure ] 845 832 http/tests/security/contentSecurityPolicy/script-src-blocked-error-event.html [ Pass Failure ] 846 833 -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/report-uri-effective-directive-expected.txt
r195367 r197083 1 CONSOLE MESSAGE: line 7: Refused to execute inline script because it violates the following Content Security Policy directive: "default-src 'self'". Either the 'unsafe-inline' keyword, a hash ('sha256-L3uuqigJSGd8GNknRL52DwyzzMGSUwfFRHXvGFby0oM='), or a nonce ('nonce-...') is required to enable inline execution. Note alsothat 'script-src' was not explicitly set, so 'default-src' is used as a fallback.1 CONSOLE MESSAGE: line 4: Refused to execute inline script because it violates the following Content Security Policy directive: "default-src 'self'". Note that 'script-src' was not explicitly set, so 'default-src' is used as a fallback. 2 2 3 3 CSP report received: 4 4 CONTENT_TYPE: application/csp-report 5 HTTP_REFERER: http://127.0.0.1:8000/security/contentSecurityPolicy/1.1/report-uri-effective-directive. html5 HTTP_REFERER: http://127.0.0.1:8000/security/contentSecurityPolicy/1.1/report-uri-effective-directive.php 6 6 REQUEST_METHOD: POST 7 7 === POST DATA === 8 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/1.1/report-uri-effective-directive. html","referrer":"","violated-directive":"default-src 'self'","effective-directive":"script-src","original-policy":"default-src 'self'; report-uri ../resources/save-report.php","blocked-uri":"","status-code":200}}8 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/1.1/report-uri-effective-directive.php","referrer":"","violated-directive":"default-src 'self'","effective-directive":"script-src","original-policy":"default-src 'self'; report-uri ../resources/save-report.php","blocked-uri":"","status-code":200}} -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/report-uri-effective-directive.php
r197082 r197083 1 <?php 2 header("Content-Security-Policy: default-src 'self'; report-uri ../resources/save-report.php"); 3 ?> 1 4 <!DOCTYPE html> 2 5 <html> 3 <head>4 <meta http-equiv="Content-Security-Policy" content="default-src 'self'; report-uri ../resources/save-report.php">5 </head>6 6 <body> 7 7 <script> -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-and-enforce-expected.txt
r197082 r197083 1 CONSOLE MESSAGE: line 14:Refused to load the image 'http://127.0.0.1:8000/security/resources/abe.png' because it violates the following Content Security Policy directive: "img-src 'none'".1 CONSOLE MESSAGE: Refused to load the image 'http://127.0.0.1:8000/security/resources/abe.png' because it violates the following Content Security Policy directive: "img-src 'none'". 2 2 3 CONSOLE MESSAGE: line 11: [Report Only] Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self'". Either the 'unsafe-inline' keyword, a hash ('sha256-YQwmkO9U3gKLwAFFj9h7BeOrJNIo50emf5tmL1p32RY='), or a nonce ('nonce-...') is required to enable inline execution.3 CONSOLE MESSAGE: line 9: [Report Only] Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self'". 4 4 5 5 ALERT: PASS -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-blocked-data-uri-expected.txt
r197082 r197083 1 CONSOLE MESSAGE: line 8:Refused to load the image 'data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==' because it violates the following Content Security Policy directive: "img-src 'none'".1 CONSOLE MESSAGE: Refused to load the image 'data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==' because it violates the following Content Security Policy directive: "img-src 'none'". 2 2 3 3 CSP report received: -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-blocked-file-uri-expected.txt
r197082 r197083 6 6 REQUEST_METHOD: POST 7 7 === POST DATA === 8 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-blocked-file-uri.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri resources/save-report.php","blocked-uri":"file","status-code":200 }}8 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-blocked-file-uri.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri resources/save-report.php","blocked-uri":"file","status-code":200,"source-file":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-blocked-file-uri.php","line-number":9}} -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-blocked-uri-cross-origin-expected.txt
r197082 r197083 1 CONSOLE MESSAGE: line 4:[Report Only] Refused to load the image 'http://localhost:8080/security/resources/abe.png' because it violates the following Content Security Policy directive: "img-src 'none'".1 CONSOLE MESSAGE: [Report Only] Refused to load the image 'http://localhost:8080/security/resources/abe.png' because it violates the following Content Security Policy directive: "img-src 'none'". 2 2 3 3 CSP report received: -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-blocked-uri-expected.txt
r197082 r197083 1 CONSOLE MESSAGE: line 4:[Report Only] Refused to load the image 'http://127.0.0.1:8000/security/resources/abe.png' because it violates the following Content Security Policy directive: "img-src 'none'".1 CONSOLE MESSAGE: [Report Only] Refused to load the image 'http://127.0.0.1:8000/security/resources/abe.png' because it violates the following Content Security Policy directive: "img-src 'none'". 2 2 3 3 CSP report received: -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-cross-origin-no-cookies-expected.txt
r197082 r197083 1 CONSOLE MESSAGE: line 18:Refused to load the image 'http://127.0.0.1:8000/security/resources/abe.png' because it violates the following Content Security Policy directive: "img-src 'none'".1 CONSOLE MESSAGE: Refused to load the image 'http://127.0.0.1:8000/security/resources/abe.png' because it violates the following Content Security Policy directive: "img-src 'none'". 2 2 3 3 CSP report received: -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-cross-origin-no-cookies-when-private-browsing-enabled-expected.txt
r197082 r197083 4 4 REQUEST_METHOD: POST 5 5 === POST DATA === 6 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-cross-origin-no-cookies-when-private-browsing-enabled.php","referrer":"","violated-directive":"img-src 'none'"," original-policy":"img-src 'none'; report-uri http://localhost:8080/security/contentSecurityPolicy/resources/save-report.php","blocked-uri":"http://127.0.0.1:8000/security/resources/abe.png"}}6 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-cross-origin-no-cookies-when-private-browsing-enabled.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri http://localhost:8080/security/contentSecurityPolicy/resources/save-report.php","blocked-uri":"http://127.0.0.1:8000/security/resources/abe.png","status-code":200}} -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-cross-origin-no-cookies-when-private-browsing-toggled-expected.txt
r197082 r197083 4 4 REQUEST_METHOD: POST 5 5 === POST DATA === 6 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-cross-origin-no-cookies-when-private-browsing-toggled.php","referrer":"","violated-directive":"img-src 'none'"," original-policy":"img-src 'none'; report-uri http://localhost:8080/security/contentSecurityPolicy/resources/save-report.php","blocked-uri":"http://127.0.0.1:8000/security/resources/abe.png"}}6 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-cross-origin-no-cookies-when-private-browsing-toggled.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri http://localhost:8080/security/contentSecurityPolicy/resources/save-report.php","blocked-uri":"http://127.0.0.1:8000/security/resources/abe.png","status-code":200}} -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-only-expected.txt
r197082 r197083 1 CONSOLE MESSAGE: line 3: [Report Only] Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self'". Either the 'unsafe-inline' keyword, a hash ('sha256-MbVeEjw3Zzj1MNUWQYXDtxD7K2xZqa56QKGb3hkp9DY='), or a nonce ('nonce-...') is required to enable inline execution.1 CONSOLE MESSAGE: line 1: [Report Only] Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self'". 2 2 3 3 ALERT: PASS -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-only-from-header-expected.txt
r195367 r197083 1 CONSOLE MESSAGE: line 1: [Report Only] Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self'". Either the 'unsafe-inline' keyword, a hash ('sha256-MbVeEjw3Zzj1MNUWQYXDtxD7K2xZqa56QKGb3hkp9DY='), or a nonce ('nonce-...') is required to enable inline execution.1 CONSOLE MESSAGE: line 1: [Report Only] Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self'". 2 2 3 3 ALERT: PASS -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-same-origin-no-cookies-when-private-browsing-toggled-expected.txt
r197082 r197083 4 4 REQUEST_METHOD: POST 5 5 === POST DATA === 6 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-same-origin-no-cookies-when-private-browsing-toggled.php","referrer":"","violated-directive":"img-src 'none'"," original-policy":"img-src 'none'; report-uri /security/contentSecurityPolicy/resources/save-report.php","blocked-uri":"http://127.0.0.1:8000/security/resources/abe.png"}}6 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-same-origin-no-cookies-when-private-browsing-toggled.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri /security/contentSecurityPolicy/resources/save-report.php","blocked-uri":"http://127.0.0.1:8000/security/resources/abe.png","status-code":200}} -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-same-origin-with-cookies-expected.txt
r197082 r197083 1 CONSOLE MESSAGE: line 18:Refused to load the image 'http://127.0.0.1:8000/security/resources/abe.png' because it violates the following Content Security Policy directive: "img-src 'none'".1 CONSOLE MESSAGE: Refused to load the image 'http://127.0.0.1:8000/security/resources/abe.png' because it violates the following Content Security Policy directive: "img-src 'none'". 2 2 3 3 CSP report received: -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-same-origin-with-cookies-when-private-browsing-enabled-expected.txt
r197082 r197083 5 5 REQUEST_METHOD: POST 6 6 === POST DATA === 7 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-same-origin-with-cookies-when-private-browsing-enabled.php","referrer":"","violated-directive":"img-src 'none'"," original-policy":"img-src 'none'; report-uri /security/contentSecurityPolicy/resources/save-report.php","blocked-uri":"http://127.0.0.1:8000/security/resources/abe.png"}}7 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-same-origin-with-cookies-when-private-browsing-enabled.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri /security/contentSecurityPolicy/resources/save-report.php","blocked-uri":"http://127.0.0.1:8000/security/resources/abe.png","status-code":200}} -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-uri-expected.txt
r197082 r197083 1 CONSOLE MESSAGE: line 3: Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self'". Either the 'unsafe-inline' keyword, a hash ('sha256-2jEXxWe/uIoRJGbfoW7Bd11qhRclP9IuS5ZXCbhCUnM='), or a nonce ('nonce-...') is required to enable inline execution.1 CONSOLE MESSAGE: line 1: Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self'". 2 2 3 3 CSP report received: -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-uri-from-child-frame-expected.txt
r196664 r197083 1 CONSOLE MESSAGE: line 2: Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self'". Either the 'unsafe-inline' keyword, a hash ('sha256-2jEXxWe/uIoRJGbfoW7Bd11qhRclP9IuS5ZXCbhCUnM='), or a nonce ('nonce-...') is required to enable inline execution.1 CONSOLE MESSAGE: line 1: Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self'". 2 2 3 3 -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-uri-from-child-frame.html
r176413 r197083 3 3 testRunner.dumpChildFramesAsText(); 4 4 </script> 5 <iframe src="resources/generate-csp-report.php?test=/security/contentSecurityPolicy/report-uri-from-child-frame.html"></ script>5 <iframe src="resources/generate-csp-report.php?test=/security/contentSecurityPolicy/report-uri-from-child-frame.html"></iframe> -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-uri-from-inline-javascript-expected.txt
r197082 r197083 6 6 REQUEST_METHOD: POST 7 7 === POST DATA === 8 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-uri-from-inline-javascript.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri resources/save-report.php","blocked-uri":"http://127.0.0.1:8000/security/resources/abe.png","status-code":200 }}8 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-uri-from-inline-javascript.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri resources/save-report.php","blocked-uri":"http://127.0.0.1:8000/security/resources/abe.png","status-code":200,"source-file":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-uri-from-inline-javascript.php","line-number":7}} -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-uri-from-javascript-expected.txt
r197082 r197083 6 6 REQUEST_METHOD: POST 7 7 === POST DATA === 8 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-uri-from-javascript.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri resources/save-report.php","blocked-uri":"http://127.0.0.1:8000/security/resources/abe.png","status-code":200 }}8 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-uri-from-javascript.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri resources/save-report.php","blocked-uri":"http://127.0.0.1:8000/security/resources/abe.png","status-code":200,"source-file":"http://127.0.0.1:8000/security/contentSecurityPolicy/resources/inject-image.js","line-number":3}} -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-uri-scheme-relative-expected.txt
r197082 r197083 1 CONSOLE MESSAGE: line 3: Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self'". Either the 'unsafe-inline' keyword, a hash ('sha256-2jEXxWe/uIoRJGbfoW7Bd11qhRclP9IuS5ZXCbhCUnM='), or a nonce ('nonce-...') is required to enable inline execution.1 CONSOLE MESSAGE: line 1: Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self'". 2 2 3 3 CSP report received: -
releases/WebKitGTK/webkit-2.12/Source/WebCore/ChangeLog
r197082 r197083 1 2016-02-21 Daniel Bates <dabates@apple.com> 2 3 CSP: Violation report should include HTTP status code and effective-directive of protected resource 4 https://bugs.webkit.org/show_bug.cgi?id=154288 5 <rdar://problem/24674982> 6 And 7 https://bugs.webkit.org/show_bug.cgi?id=115707 8 <rdar://problem/24383128> 9 10 Reviewed by Brent Fulgham. 11 12 Include status-code and effective-directive in the Content Security Policy violation report for 13 the HTTP status code of the protected resource and name of the policy directive that was violated, 14 respectively, as per section Reporting of the Content Security Policy 2.0 spec., <https://www.w3.org/TR/2015/CR-CSP2-20150721/>. 15 16 Test: http/tests/security/contentSecurityPolicy/report-status-code-zero-when-using-https.html 17 18 * page/csp/ContentSecurityPolicy.cpp: 19 (WebCore::ContentSecurityPolicy::reportViolation): Add key status-code to the report with value 20 equal to the HTTP response code for the document or 0 depending on whether the document was 21 delivered over HTTP or not. Additionally, remove ENABLE(CSP_NEXT)-guard/experimentalFeaturesEnabled()-condition 22 around code to include the effective-directive property in the report. 23 1 24 2016-02-21 Daniel Bates <dabates@apple.com> 2 25 -
releases/WebKitGTK/webkit-2.12/Source/WebCore/page/csp/ContentSecurityPolicy.cpp
r197081 r197083 34 34 #include "DOMStringList.h" 35 35 #include "Document.h" 36 #include "DocumentLoader.h" 36 37 #include "FormData.h" 37 38 #include "FormDataList.h" … … 382 383 cspReport->setString(ASCIILiteral("referrer"), document.referrer()); 383 384 cspReport->setString(ASCIILiteral("violated-directive"), directiveText); 384 #if ENABLE(CSP_NEXT) 385 if (experimentalFeaturesEnabled()) 386 cspReport->setString(ASCIILiteral("effective-directive"), effectiveDirective); 387 #else 388 UNUSED_PARAM(effectiveDirective); 389 #endif 385 cspReport->setString(ASCIILiteral("effective-directive"), effectiveDirective); 390 386 cspReport->setString(ASCIILiteral("original-policy"), header); 391 387 cspReport->setString(ASCIILiteral("blocked-uri"), stripURLForUseInReport(document, blockedURL)); 388 389 ASSERT(document.loader()); 390 cspReport->setInteger(ASCIILiteral("status-code"), document.url().protocolIs("http") && document.loader() ? document.loader()->response().httpStatusCode() : 0); 392 391 393 392 RefPtr<ScriptCallStack> stack = createScriptCallStack(JSMainThreadExecState::currentState(), 2);
Note:
See TracChangeset
for help on using the changeset viewer.