Changeset 197084 in webkit
- Timestamp:
- Feb 25, 2016, 2:26:22 AM (11 years ago)
- Location:
- releases/WebKitGTK/webkit-2.12
- Files:
-
- 6 edited
-
LayoutTests/ChangeLog (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-blocked-file-uri-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-uri-from-inline-javascript-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/report-uri-from-javascript-expected.txt (modified) (1 diff)
-
Source/WebCore/ChangeLog (modified) (1 diff)
-
Source/WebCore/page/csp/ContentSecurityPolicy.cpp (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
releases/WebKitGTK/webkit-2.12/LayoutTests/ChangeLog
r197083 r197084 1 2016-02-21 Daniel Bates <dabates@apple.com> 2 3 CSP: Violation report should include column number 4 https://bugs.webkit.org/show_bug.cgi?id=154418 5 <rdar://problem/24729525> 6 7 Reviewed by Brent Fulgham. 8 9 Update expected results to include source file column information where the violation occurred. 10 11 * http/tests/security/contentSecurityPolicy/report-blocked-file-uri-expected.txt: 12 * http/tests/security/contentSecurityPolicy/report-uri-from-inline-javascript-expected.txt: 13 * http/tests/security/contentSecurityPolicy/report-uri-from-javascript-expected.txt: 14 1 15 2016-02-21 Daniel Bates <dabates@apple.com> 2 16 -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-blocked-file-uri-expected.txt
r197083 r197084 6 6 REQUEST_METHOD: POST 7 7 === POST DATA === 8 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-blocked-file-uri.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri resources/save-report.php","blocked-uri":"file","status-code":200,"source-file":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-blocked-file-uri.php","line-number":9 }}8 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-blocked-file-uri.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri resources/save-report.php","blocked-uri":"file","status-code":200,"source-file":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-blocked-file-uri.php","line-number":9,"column-number":26}} -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-uri-from-inline-javascript-expected.txt
r197083 r197084 6 6 REQUEST_METHOD: POST 7 7 === POST DATA === 8 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-uri-from-inline-javascript.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri resources/save-report.php","blocked-uri":"http://127.0.0.1:8000/security/resources/abe.png","status-code":200,"source-file":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-uri-from-inline-javascript.php","line-number":7 }}8 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-uri-from-inline-javascript.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri resources/save-report.php","blocked-uri":"http://127.0.0.1:8000/security/resources/abe.png","status-code":200,"source-file":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-uri-from-inline-javascript.php","line-number":7,"column-number":10}} -
releases/WebKitGTK/webkit-2.12/LayoutTests/http/tests/security/contentSecurityPolicy/report-uri-from-javascript-expected.txt
r197083 r197084 6 6 REQUEST_METHOD: POST 7 7 === POST DATA === 8 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-uri-from-javascript.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri resources/save-report.php","blocked-uri":"http://127.0.0.1:8000/security/resources/abe.png","status-code":200,"source-file":"http://127.0.0.1:8000/security/contentSecurityPolicy/resources/inject-image.js","line-number":3 }}8 {"csp-report":{"document-uri":"http://127.0.0.1:8000/security/contentSecurityPolicy/report-uri-from-javascript.php","referrer":"","violated-directive":"img-src 'none'","effective-directive":"img-src","original-policy":"img-src 'none'; report-uri resources/save-report.php","blocked-uri":"http://127.0.0.1:8000/security/resources/abe.png","status-code":200,"source-file":"http://127.0.0.1:8000/security/contentSecurityPolicy/resources/inject-image.js","line-number":3,"column-number":2}} -
releases/WebKitGTK/webkit-2.12/Source/WebCore/ChangeLog
r197083 r197084 1 2016-02-21 Daniel Bates <dabates@apple.com> 2 3 CSP: Violation report should include column number 4 https://bugs.webkit.org/show_bug.cgi?id=154418 5 <rdar://problem/24729525> 6 7 Reviewed by Brent Fulgham. 8 9 Include column-number in the Content Security Policy violation report for the column number 10 in the source script where the violation occurred (for a script violation) as per section 11 Reporting of the Content Security Policy 2.0 spec., <https://www.w3.org/TR/2015/CR-CSP2-20150721/>. 12 13 When a CSP report is created for a script violation the source file and line number of the 14 source code line where the violation occurred are included in the report. We now include 15 the column number in the source file where the violation occurred so as to help narrow 16 down the operation that triggered the violation in a complicated source code line. 17 18 * page/csp/ContentSecurityPolicy.cpp: 19 (WebCore::ContentSecurityPolicy::reportViolation): 20 1 21 2016-02-21 Daniel Bates <dabates@apple.com> 2 22 -
releases/WebKitGTK/webkit-2.12/Source/WebCore/page/csp/ContentSecurityPolicy.cpp
r197083 r197084 396 396 cspReport->setString(ASCIILiteral("source-file"), stripURLForUseInReport(document, source)); 397 397 cspReport->setInteger(ASCIILiteral("line-number"), callFrame->lineNumber()); 398 cspReport->setInteger(ASCIILiteral("column-number"), callFrame->columnNumber()); 398 399 } 399 400
Note:
See TracChangeset
for help on using the changeset viewer.