Changeset 197118 in webkit
- Timestamp:
- Feb 25, 2016, 8:21:40 AM (11 years ago)
- Location:
- trunk
- Files:
-
- 1 added
- 22 edited
- 1 copied
-
LayoutTests/ChangeLog (modified) (1 diff)
-
LayoutTests/TestExpectations (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-basics-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-cross-origin-image-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-cross-origin-image-from-script-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-cross-origin-image-from-script.html (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-cross-origin-image.html (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image-from-script-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image-from-script.html (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image-https-expected.txt (copied) (copied from trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image-expected.txt ) (2 diffs)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image-https.html (added)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image.html (modified) (1 diff)
-
LayoutTests/js/dom/global-constructors-attributes-expected.txt (modified) (1 diff)
-
LayoutTests/platform/efl/js/dom/global-constructors-attributes-expected.txt (modified) (1 diff)
-
LayoutTests/platform/mac-mavericks/js/dom/global-constructors-attributes-expected.txt (modified) (1 diff)
-
LayoutTests/platform/mac-yosemite/js/dom/global-constructors-attributes-expected.txt (modified) (1 diff)
-
LayoutTests/platform/mac/js/dom/global-constructors-attributes-expected.txt (modified) (1 diff)
-
Source/WebCore/ChangeLog (modified) (1 diff)
-
Source/WebCore/WebCore.xcodeproj/project.pbxproj (modified) (5 diffs)
-
Source/WebCore/dom/EventNames.in (modified) (1 diff)
-
Source/WebCore/dom/SecurityPolicyViolationEvent.h (modified) (8 diffs)
-
Source/WebCore/dom/SecurityPolicyViolationEvent.idl (modified) (3 diffs)
-
Source/WebCore/page/csp/ContentSecurityPolicy.cpp (modified) (3 diffs)
Legend:
- Unmodified
- Added
- Removed
-
trunk/LayoutTests/ChangeLog
r197114 r197118 1 2016-02-25 Daniel Bates <dabates@apple.com> 2 3 CSP: Make SecurityPolicyViolationEvent more closely conform to CSP spec and enable it by default 4 https://bugs.webkit.org/show_bug.cgi?id=154522 5 <rdar://problem/24762078> 6 7 Reviewed by Brent Fulgham. 8 9 Add new test http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image-https.html 10 to ensure that SecurityPolicyViolationEvent.statusCode is 0 when dispatched for a violation on an HTTPS-served 11 document per section Reporting of the Content Security Policy 2.0 spec, <https://www.w3.org/TR/2015/CR-CSP2-20150721/>. 12 Update existing test results and mark more tests as PASS in file LayoutTests/TestExpectations. 13 14 * TestExpectations: Mark tests http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation*.html as PASS 15 so that we run them. 16 * http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-basics-expected.txt: Update expected result to 17 reflect failing sub-test. We do not support the experimental JavaScript event listener onsecuritypolicyviolation when 18 building with ENABLE(CSP_NEXT) disabled. 19 * http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-cross-origin-image-expected.txt: Update line and column numbers. 20 * http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-cross-origin-image-from-script-expected.txt: Ditto. 21 * http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-cross-origin-image-from-script.html: Ditto. 22 * http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-cross-origin-image.html: Ditto. 23 * http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image-expected.txt: Ditto. 24 * http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image-from-script-expected.txt: Ditto. 25 * http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image-from-script.html: Ditto. 26 * http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image-https-expected.txt: Added. 27 * http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image-https.html: Added. 28 * http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image.html: Update line and column numbers. 29 * js/dom/global-constructors-attributes-expected.txt: Update expected results now that we expose SecurityPolicyViolationEvent. 30 * platform/efl/js/dom/global-constructors-attributes-expected.txt: Ditto. 31 * platform/mac-mavericks/js/dom/global-constructors-attributes-expected.txt: Ditto. 32 * platform/mac-yosemite/js/dom/global-constructors-attributes-expected.txt: Ditto. 33 * platform/mac/js/dom/global-constructors-attributes-expected.txt: Ditto. 34 1 35 2016-02-25 Eric Carlson <eric.carlson@apple.com> 2 36 -
trunk/LayoutTests/TestExpectations
r197038 r197118 815 815 http/tests/security/contentSecurityPolicy/1.1/base-uri-deny.html [ Pass ] 816 816 http/tests/security/contentSecurityPolicy/1.1/report-uri-effective-directive.php [ Pass ] 817 http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-basics.html [ Pass ] 818 http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-cross-origin-image-from-script.html [ Pass ] 819 http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-cross-origin-image.html [ Pass ] 820 http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image-from-script.html [ Pass ] 821 http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image-https.html [ Pass ] 822 http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image.html [ Pass ] 817 823 webkit.org/b/154203 http/tests/security/contentSecurityPolicy/1.1/frame-ancestors/frame-ancestors-overrides-xfo.html 818 824 webkit.org/b/154203 http/tests/security/contentSecurityPolicy/1.1/scripthash-default-src.html -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-basics-expected.txt
r195367 r197118 4 4 5 5 6 PASS typeof document.onsecuritypolicyviolation is "object" 6 FAIL typeof document.onsecuritypolicyviolation should be object. Was undefined. 7 7 PASS typeof SecurityPolicyViolationEvent is "function" 8 8 PASS typeof window.e is "object" -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-cross-origin-image-expected.txt
r195367 r197118 14 14 PASS window.e.originalPolicy is "img-src 'none'" 15 15 PASS window.e.sourceFile is "http://127.0.0.1:8000/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-cross-origin-image.html" 16 PASS window.e.lineNumber is 2 317 PASS window.e.columnNumber is 2116 PASS window.e.lineNumber is 25 17 PASS window.e.columnNumber is 16 18 18 PASS window.e.statusCode is 200 19 19 PASS successfullyParsed is true -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-cross-origin-image-from-script-expected.txt
r195367 r197118 15 15 PASS window.e.sourceFile is "http://localhost:8000" 16 16 PASS window.e.lineNumber is 3 17 PASS window.e.columnNumber is 717 PASS window.e.columnNumber is 2 18 18 PASS window.e.statusCode is 200 19 19 PASS successfullyParsed is true -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-cross-origin-image-from-script.html
r195367 r197118 17 17 'sourceFile': 'http://localhost:8000', 18 18 'lineNumber': 3, 19 'columnNumber': 7,19 'columnNumber': 2, 20 20 'statusCode': 200, 21 21 }; -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-cross-origin-image.html
r195367 r197118 16 16 'originalPolicy': 'img-src \'none\'', 17 17 'sourceFile': document.location.toString(), 18 'lineNumber': 2 3,19 'columnNumber': 21,18 'lineNumber': 25, 19 'columnNumber': 16, 20 20 'statusCode': 200, 21 21 }; -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image-expected.txt
r195367 r197118 14 14 PASS window.e.originalPolicy is "img-src 'none'" 15 15 PASS window.e.sourceFile is "http://127.0.0.1:8000/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image.html" 16 PASS window.e.lineNumber is 2 317 PASS window.e.columnNumber is 2116 PASS window.e.lineNumber is 25 17 PASS window.e.columnNumber is 16 18 18 PASS window.e.statusCode is 200 19 19 PASS successfullyParsed is true -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image-from-script-expected.txt
r195367 r197118 15 15 PASS window.e.sourceFile is "http://127.0.0.1:8000/security/contentSecurityPolicy/resources/inject-image.js" 16 16 PASS window.e.lineNumber is 3 17 PASS window.e.columnNumber is 717 PASS window.e.columnNumber is 2 18 18 PASS window.e.statusCode is 200 19 19 PASS successfullyParsed is true -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image-from-script.html
r195367 r197118 17 17 'sourceFile': 'http://127.0.0.1:8000/security/contentSecurityPolicy/resources/inject-image.js', 18 18 'lineNumber': 3, 19 'columnNumber': 7,19 'columnNumber': 2, 20 20 'statusCode': 200, 21 21 }; -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image-https-expected.txt
r197114 r197118 1 1 CONSOLE MESSAGE: Refused to load the image 'http://127.0.0.1:8000/security/resources/abe.png' because it violates the following Content Security Policy directive: "img-src 'none'". 2 2 3 4 5 -------- 6 Frame: '<!--framePath //<!--frame0-->-->' 7 -------- 3 8 Check that a SecurityPolicyViolationEvent is fired upon blocking an image. 4 9 … … 7 12 8 13 Kicking off the tests: 9 PASS window.e.documentURI is "http ://127.0.0.1:8000/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image.html"10 PASS window.e.referrer is " "11 PASS window.e.blockedURI is "http://127.0.0.1:8000/security/resources/abe.png" 14 PASS window.e.documentURI is "https://127.0.0.1:8443/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image.html" 15 PASS window.e.referrer is "http://127.0.0.1:8000/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image-https.html" 16 FAIL window.e.blockedURI should be http://127.0.0.1:8000/security/resources/abe.png. Was http://127.0.0.1:8000. 12 17 PASS window.e.violatedDirective is "img-src 'none'" 13 18 PASS window.e.effectiveDirective is "img-src" 14 19 PASS window.e.originalPolicy is "img-src 'none'" 15 PASS window.e.sourceFile is "http ://127.0.0.1:8000/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image.html"16 PASS window.e.lineNumber is 2 317 PASS window.e.columnNumber is 2118 PASS window.e.statusCode is 20020 PASS window.e.sourceFile is "https://127.0.0.1:8443/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image.html" 21 PASS window.e.lineNumber is 25 22 PASS window.e.columnNumber is 16 23 PASS window.e.statusCode is 0 19 24 PASS successfullyParsed is true 20 25 -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image.html
r195367 r197118 16 16 'originalPolicy': 'img-src \'none\'', 17 17 'sourceFile': document.location.toString(), 18 'lineNumber': 2 3,19 'columnNumber': 21,20 'statusCode': 200,18 'lineNumber': 25, 19 'columnNumber': 16, 20 'statusCode': document.location.protocol === 'http:' ? 200 : 0, 21 21 }; 22 22 23 23 function run() { 24 24 var img = document.createElement('img'); 25 img.src = ' /security/resources/abe.png';25 img.src = 'http://127.0.0.1:8000/security/resources/abe.png'; 26 26 document.body.appendChild(img); 27 27 } -
trunk/LayoutTests/js/dom/global-constructors-attributes-expected.txt
r197049 r197118 1719 1719 PASS Object.getOwnPropertyDescriptor(global, 'ScriptProcessorNode').enumerable is false 1720 1720 PASS Object.getOwnPropertyDescriptor(global, 'ScriptProcessorNode').configurable is true 1721 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').value is SecurityPolicyViolationEvent 1722 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').hasOwnProperty('get') is false 1723 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').hasOwnProperty('set') is false 1724 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').enumerable is false 1725 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').configurable is true 1721 1726 PASS Object.getOwnPropertyDescriptor(global, 'Selection').value is Selection 1722 1727 PASS Object.getOwnPropertyDescriptor(global, 'Selection').hasOwnProperty('get') is false -
trunk/LayoutTests/platform/efl/js/dom/global-constructors-attributes-expected.txt
r197049 r197118 1789 1789 PASS Object.getOwnPropertyDescriptor(global, 'ScriptProcessorNode').enumerable is false 1790 1790 PASS Object.getOwnPropertyDescriptor(global, 'ScriptProcessorNode').configurable is true 1791 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').value is SecurityPolicyViolationEvent 1792 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').hasOwnProperty('get') is false 1793 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').hasOwnProperty('set') is false 1794 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').enumerable is false 1795 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').configurable is true 1791 1796 PASS Object.getOwnPropertyDescriptor(global, 'Selection').value is Selection 1792 1797 PASS Object.getOwnPropertyDescriptor(global, 'Selection').hasOwnProperty('get') is false -
trunk/LayoutTests/platform/mac-mavericks/js/dom/global-constructors-attributes-expected.txt
r197049 r197118 1799 1799 PASS Object.getOwnPropertyDescriptor(global, 'ScriptProcessorNode').enumerable is false 1800 1800 PASS Object.getOwnPropertyDescriptor(global, 'ScriptProcessorNode').configurable is true 1801 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').value is SecurityPolicyViolationEvent 1802 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').hasOwnProperty('get') is false 1803 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').hasOwnProperty('set') is false 1804 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').enumerable is false 1805 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').configurable is true 1801 1806 PASS Object.getOwnPropertyDescriptor(global, 'Selection').value is Selection 1802 1807 PASS Object.getOwnPropertyDescriptor(global, 'Selection').hasOwnProperty('get') is false -
trunk/LayoutTests/platform/mac-yosemite/js/dom/global-constructors-attributes-expected.txt
r197049 r197118 1924 1924 PASS Object.getOwnPropertyDescriptor(global, 'ScriptProcessorNode').enumerable is false 1925 1925 PASS Object.getOwnPropertyDescriptor(global, 'ScriptProcessorNode').configurable is true 1926 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').value is SecurityPolicyViolationEvent 1927 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').hasOwnProperty('get') is false 1928 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').hasOwnProperty('set') is false 1929 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').enumerable is false 1930 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').configurable is true 1926 1931 PASS Object.getOwnPropertyDescriptor(global, 'Selection').value is Selection 1927 1932 PASS Object.getOwnPropertyDescriptor(global, 'Selection').hasOwnProperty('get') is false -
trunk/LayoutTests/platform/mac/js/dom/global-constructors-attributes-expected.txt
r197049 r197118 1924 1924 PASS Object.getOwnPropertyDescriptor(global, 'ScriptProcessorNode').enumerable is false 1925 1925 PASS Object.getOwnPropertyDescriptor(global, 'ScriptProcessorNode').configurable is true 1926 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').value is SecurityPolicyViolationEvent 1927 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').hasOwnProperty('get') is false 1928 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').hasOwnProperty('set') is false 1929 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').enumerable is false 1930 PASS Object.getOwnPropertyDescriptor(global, 'SecurityPolicyViolationEvent').configurable is true 1926 1931 PASS Object.getOwnPropertyDescriptor(global, 'Selection').value is Selection 1927 1932 PASS Object.getOwnPropertyDescriptor(global, 'Selection').hasOwnProperty('get') is false -
trunk/Source/WebCore/ChangeLog
r197114 r197118 1 2016-02-25 Daniel Bates <dabates@apple.com> 2 3 CSP: Make SecurityPolicyViolationEvent more closely conform to CSP spec and enable it by default 4 https://bugs.webkit.org/show_bug.cgi?id=154522 5 <rdar://problem/24762078> 6 7 Reviewed by Brent Fulgham. 8 9 Include attributes statusCode and columnNumber in a dispatched SecurityPolicyViolationEvent and 10 as part of the SecurityPolicyViolationEventInit dictionary as per section Violation DOM Events 11 of the Content Security Policy Level 3 spec., <https://w3c.github.io/webappsec-csp/> (24 February 2016). 12 Additionally, enable dispatching of this event when a Content Security Policy violation occurs regardless 13 of whether ENABLE(CSP_NEXT) is enabled. 14 15 Test: http/tests/security/contentSecurityPolicy/1.1/securitypolicyviolation-block-image-https.html 16 17 * WebCore.xcodeproj/project.pbxproj: Add files JSSecurityPolicyViolationEvent.{cpp, h}. 18 * dom/EventNames.in: Enable support for SecurityPolicyViolationEvent unconditionally. 19 * dom/SecurityPolicyViolationEvent.h: Remove ENABLE(CSP_NEXT)-guard so that we compile this 20 code unconditionally. Modified SecurityPolicyViolationEventInit and SecurityPolicyViolationEvent 21 to support attributes statusCode and columnNumebr. 22 * dom/SecurityPolicyViolationEvent.idl: Add attributes statusCode and columnNumber. 23 * page/csp/ContentSecurityPolicy.cpp: 24 (WebCore::ContentSecurityPolicy::reportViolation): Modified to both dispatch a SecurityPolicyViolationEvent 25 and send a violation report (if applicable). 26 1 27 2016-02-25 Eric Carlson <eric.carlson@apple.com> 2 28 -
trunk/Source/WebCore/WebCore.xcodeproj/project.pbxproj
r197058 r197118 6256 6256 CECADFCE1537791D00E37068 /* TextInsertionBaseCommand.h in Headers */ = {isa = PBXBuildFile; fileRef = CECADFCC1537791D00E37068 /* TextInsertionBaseCommand.h */; }; 6257 6257 CECCFC3B141973D5002A0AC1 /* DecodeEscapeSequences.h in Headers */ = {isa = PBXBuildFile; fileRef = CECCFC3A141973D5002A0AC1 /* DecodeEscapeSequences.h */; }; 6258 CED06AD01C77754800FDFAF1 /* JSSecurityPolicyViolationEvent.cpp in Sources */ = {isa = PBXBuildFile; fileRef = CED06ACE1C77754800FDFAF1 /* JSSecurityPolicyViolationEvent.cpp */; }; 6259 CED06AD11C77754800FDFAF1 /* JSSecurityPolicyViolationEvent.h in Headers */ = {isa = PBXBuildFile; fileRef = CED06ACF1C77754800FDFAF1 /* JSSecurityPolicyViolationEvent.h */; }; 6258 6260 CEDA12D7152CA1CB00D9E08D /* AlternativeTextClient.h in Headers */ = {isa = PBXBuildFile; fileRef = CEDA12D6152CA1CB00D9E08D /* AlternativeTextClient.h */; settings = {ATTRIBUTES = (Private, ); }; }; 6259 6261 CEE27ACB1BBB53A20072400A /* pthreadSPI.h in Headers */ = {isa = PBXBuildFile; fileRef = CEE27ACA1BBB53A20072400A /* pthreadSPI.h */; settings = {ATTRIBUTES = (Private, ); }; }; … … 14279 14281 CECADFCC1537791D00E37068 /* TextInsertionBaseCommand.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = TextInsertionBaseCommand.h; sourceTree = "<group>"; }; 14280 14282 CECCFC3A141973D5002A0AC1 /* DecodeEscapeSequences.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = DecodeEscapeSequences.h; sourceTree = "<group>"; }; 14283 CED06ACE1C77754800FDFAF1 /* JSSecurityPolicyViolationEvent.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; path = JSSecurityPolicyViolationEvent.cpp; sourceTree = "<group>"; }; 14284 CED06ACF1C77754800FDFAF1 /* JSSecurityPolicyViolationEvent.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = JSSecurityPolicyViolationEvent.h; sourceTree = "<group>"; }; 14281 14285 CEDA12D6152CA1CB00D9E08D /* AlternativeTextClient.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = AlternativeTextClient.h; sourceTree = "<group>"; }; 14282 14286 CEE27ACA1BBB53A20072400A /* pthreadSPI.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = pthreadSPI.h; sourceTree = "<group>"; }; … … 20987 20991 5189F01B10B37BD900F3C739 /* JSPopStateEvent.cpp */, 20988 20992 5189F01C10B37BD900F3C739 /* JSPopStateEvent.h */, 20993 CED06ACE1C77754800FDFAF1 /* JSSecurityPolicyViolationEvent.cpp */, 20994 CED06ACF1C77754800FDFAF1 /* JSSecurityPolicyViolationEvent.h */, 20989 20995 933A14B60B7D1D5200A53FFD /* JSTextEvent.cpp */, 20990 20996 933A14B70B7D1D5200A53FFD /* JSTextEvent.h */, … … 26818 26824 9FA37EFB1172FDA600C4CD55 /* JSScriptProfile.h in Headers */, 26819 26825 9FA37EFD1172FDA600C4CD55 /* JSScriptProfileNode.h in Headers */, 26826 CED06AD11C77754800FDFAF1 /* JSSecurityPolicyViolationEvent.h in Headers */, 26820 26827 9BDA64D81B975CF2009C4387 /* JSShadowRoot.h in Headers */, 26821 26828 CD9DE17B17AAC75B00EA386D /* JSSourceBuffer.h in Headers */, … … 30573 30580 9FA37EFA1172FDA600C4CD55 /* JSScriptProfile.cpp in Sources */, 30574 30581 9FA37EFC1172FDA600C4CD55 /* JSScriptProfileNode.cpp in Sources */, 30582 CED06AD01C77754800FDFAF1 /* JSSecurityPolicyViolationEvent.cpp in Sources */, 30575 30583 9BDA64D71B975CE5009C4387 /* JSShadowRoot.cpp in Sources */, 30576 30584 CD9DE17A17AAC75B00EA386D /* JSSourceBuffer.cpp in Sources */, -
trunk/Source/WebCore/dom/EventNames.in
r192464 r197118 58 58 AutocompleteErrorEvent conditional=REQUEST_AUTOCOMPLETE 59 59 CSSFontFaceLoadEvent conditional=FONT_LOAD_EVENTS 60 SecurityPolicyViolationEvent conditional=CSP_NEXT60 SecurityPolicyViolationEvent 61 61 UIRequestEvent conditional=INDIE_UI 62 62 GestureEvent conditional=IOS_GESTURE_EVENTS|MAC_GESTURE_EVENTS -
trunk/Source/WebCore/dom/SecurityPolicyViolationEvent.h
r196400 r197118 1 1 /* 2 2 * Copyright (C) 2013 Google Inc. All rights reserved. 3 * Copyright (C) 2016 Apple Inc. All rights reserved. 3 4 * 4 5 * Redistribution and use in source and binary forms, with or without … … 26 27 #define SecurityPolicyViolationEvent_h 27 28 28 #if ENABLE(CSP_NEXT)29 30 29 #include "Event.h" 31 30 … … 40 39 String originalPolicy; 41 40 String sourceFile; 41 unsigned short statusCode { 0 }; 42 42 int lineNumber { 0 }; 43 int columnNumber { 0 }; 43 44 }; 44 45 45 46 class SecurityPolicyViolationEvent final : public Event { 46 47 public: 47 static Ref<SecurityPolicyViolationEvent> create(const AtomicString& type, bool canBubble, bool cancelable, const String& documentURI, const String& referrer, const String& blockedURI, const String& violatedDirective, const String& effectiveDirective, const String& originalPolicy, const String& sourceFile, int lineNumber)48 static Ref<SecurityPolicyViolationEvent> create(const AtomicString& type, bool canBubble, bool cancelable, const String& documentURI, const String& referrer, const String& blockedURI, const String& violatedDirective, const String& effectiveDirective, const String& originalPolicy, const String& sourceFile, unsigned short statusCode, int lineNumber, int columnNumber) 48 49 { 49 return adoptRef(*new SecurityPolicyViolationEvent(type, canBubble, cancelable, documentURI, referrer, blockedURI, violatedDirective, effectiveDirective, originalPolicy, sourceFile, lineNumber));50 return adoptRef(*new SecurityPolicyViolationEvent(type, canBubble, cancelable, documentURI, referrer, blockedURI, violatedDirective, effectiveDirective, originalPolicy, sourceFile, statusCode, lineNumber, columnNumber)); 50 51 } 51 52 … … 67 68 const String& originalPolicy() const { return m_originalPolicy; } 68 69 const String& sourceFile() const { return m_sourceFile; } 70 unsigned short statusCode() const { return m_statusCode; } 69 71 int lineNumber() const { return m_lineNumber; } 72 int columnNumber() const { return m_columnNumber; } 70 73 71 74 virtual EventInterface eventInterface() const { return SecurityPolicyViolationEventInterfaceType; } … … 76 79 } 77 80 78 SecurityPolicyViolationEvent(const AtomicString& type, bool canBubble, bool cancelable, const String& documentURI, const String& referrer, const String& blockedURI, const String& violatedDirective, const String& effectiveDirective, const String& originalPolicy, const String& sourceFile, int lineNumber)81 SecurityPolicyViolationEvent(const AtomicString& type, bool canBubble, bool cancelable, const String& documentURI, const String& referrer, const String& blockedURI, const String& violatedDirective, const String& effectiveDirective, const String& originalPolicy, const String& sourceFile, unsigned short statusCode, int lineNumber, int columnNumber) 79 82 : Event(type, canBubble, cancelable) 80 83 , m_documentURI(documentURI) … … 85 88 , m_originalPolicy(originalPolicy) 86 89 , m_sourceFile(sourceFile) 90 , m_statusCode(statusCode) 87 91 , m_lineNumber(lineNumber) 92 , m_columnNumber(columnNumber) 88 93 { 89 94 } … … 98 103 , m_originalPolicy(initializer.originalPolicy) 99 104 , m_sourceFile(initializer.sourceFile) 105 , m_statusCode(initializer.statusCode) 100 106 , m_lineNumber(initializer.lineNumber) 107 , m_columnNumber(initializer.columnNumber) 101 108 { 102 109 } … … 109 116 String m_originalPolicy; 110 117 String m_sourceFile; 118 unsigned short m_statusCode; 111 119 int m_lineNumber; 120 int m_columnNumber; 112 121 }; 113 122 114 123 } // namespace WebCore 115 124 116 #endif // ENABLE(CSP_NEXT)117 118 125 #endif // SecurityPolicyViolationEvent_h -
trunk/Source/WebCore/dom/SecurityPolicyViolationEvent.idl
r146763 r197118 1 1 /* 2 2 * Copyright (C) 2013 Google Inc. All rights reserved. 3 * Copyright (C) 2016 Apple Inc. All rights reserved. 3 4 * 4 5 * Redistribution and use in source and binary forms, with or without … … 24 25 25 26 [ 26 Conditional=CSP_NEXT,27 27 ConstructorTemplate=Event, 28 28 ] interface SecurityPolicyViolationEvent : Event { … … 34 34 [InitializedByEventConstructor] readonly attribute DOMString originalPolicy; 35 35 [InitializedByEventConstructor] readonly attribute DOMString sourceFile; 36 [InitializedByEventConstructor] readonly attribute long lineNumber; 36 [InitializedByEventConstructor] readonly attribute unsigned short statusCode; 37 [InitializedByEventConstructor] readonly attribute long lineNumber; 38 [InitializedByEventConstructor] readonly attribute long columnNumber; 37 39 }; -
trunk/Source/WebCore/page/csp/ContentSecurityPolicy.cpp
r196877 r197118 343 343 return; 344 344 345 #if ENABLE(CSP_NEXT) 346 if (experimentalFeaturesEnabled()) { 347 // FIXME: This code means that we're gathering information like line numbers twice. Once we can bring this out from behind the flag, we should reuse the data gathered here when generating the JSON report below. 348 String documentURI = document.url().string(); 349 String referrer = document.referrer(); 350 String blockedURI = stripURLForUseInReport(document, blockedURL); 351 String violatedDirective = directiveText; 352 String originalPolicy = header; 353 String sourceFile = String(); 354 int lineNumber = 0; 355 356 Ref<ScriptCallStack> stack = createScriptCallStack(JSMainThreadExecState::currentState(), 2); 357 const ScriptCallFrame* callFrame = stack->firstNonNativeCallFrame(); 358 if (callFrame && callFrame->lineNumber()) { 359 URL source = URL(URL(), callFrame->sourceURL()); 360 sourceFile = stripURLForUseInReport(document, source); 361 lineNumber = callFrame->lineNumber(); 362 } 363 364 document.enqueueDocumentEvent(SecurityPolicyViolationEvent::create(eventNames().securitypolicyviolationEvent, false, false, documentURI, referrer, blockedURI, violatedDirective, effectiveDirective, originalPolicy, sourceFile, lineNumber)); 365 } 366 #endif 367 345 String documentURI = document.url().strippedForUseAsReferrer(); 346 String referrer = document.referrer(); 347 String blockedURI = stripURLForUseInReport(document, blockedURL); 348 String violatedDirective = directiveText; 349 String originalPolicy = header; 350 ASSERT(document.loader()); 351 unsigned short statusCode = document.url().protocolIs("http") && document.loader() ? document.loader()->response().httpStatusCode() : 0; 352 353 String sourceFile; 354 int lineNumber = 0; 355 int columnNumber = 0; 356 RefPtr<ScriptCallStack> stack = createScriptCallStack(JSMainThreadExecState::currentState(), 2); 357 const ScriptCallFrame* callFrame = stack->firstNonNativeCallFrame(); 358 if (callFrame && callFrame->lineNumber()) { 359 sourceFile = stripURLForUseInReport(document, URL(URL(), callFrame->sourceURL())); 360 lineNumber = callFrame->lineNumber(); 361 columnNumber = callFrame->columnNumber(); 362 } 363 364 // 1. Dispatch violation event. 365 bool canBubble = false; 366 bool cancelable = false; 367 document.enqueueDocumentEvent(SecurityPolicyViolationEvent::create(eventNames().securitypolicyviolationEvent, canBubble, cancelable, documentURI, referrer, blockedURI, violatedDirective, effectiveDirective, originalPolicy, sourceFile, statusCode, lineNumber, columnNumber)); 368 369 // 2. Send violation report (if applicable). 368 370 if (reportURIs.isEmpty()) 369 371 return; … … 380 382 381 383 RefPtr<InspectorObject> cspReport = InspectorObject::create(); 382 cspReport->setString(ASCIILiteral("document-uri"), document .url().strippedForUseAsReferrer());383 cspReport->setString(ASCIILiteral("referrer"), document.referrer());384 cspReport->setString(ASCIILiteral("document-uri"), documentURI); 385 cspReport->setString(ASCIILiteral("referrer"), referrer); 384 386 cspReport->setString(ASCIILiteral("violated-directive"), directiveText); 385 387 cspReport->setString(ASCIILiteral("effective-directive"), effectiveDirective); 386 cspReport->setString(ASCIILiteral("original-policy"), header); 387 cspReport->setString(ASCIILiteral("blocked-uri"), stripURLForUseInReport(document, blockedURL)); 388 389 ASSERT(document.loader()); 390 cspReport->setInteger(ASCIILiteral("status-code"), document.url().protocolIs("http") && document.loader() ? document.loader()->response().httpStatusCode() : 0); 391 392 RefPtr<ScriptCallStack> stack = createScriptCallStack(JSMainThreadExecState::currentState(), 2); 393 const ScriptCallFrame* callFrame = stack->firstNonNativeCallFrame(); 394 if (callFrame && callFrame->lineNumber()) { 395 URL source = URL(URL(), callFrame->sourceURL()); 396 cspReport->setString(ASCIILiteral("source-file"), stripURLForUseInReport(document, source)); 397 cspReport->setInteger(ASCIILiteral("line-number"), callFrame->lineNumber()); 398 cspReport->setInteger(ASCIILiteral("column-number"), callFrame->columnNumber()); 388 cspReport->setString(ASCIILiteral("original-policy"), originalPolicy); 389 cspReport->setString(ASCIILiteral("blocked-uri"), blockedURI); 390 cspReport->setInteger(ASCIILiteral("status-code"), statusCode); 391 if (!sourceFile.isNull()) { 392 cspReport->setString(ASCIILiteral("source-file"), sourceFile); 393 cspReport->setInteger(ASCIILiteral("line-number"), lineNumber); 394 cspReport->setInteger(ASCIILiteral("column-number"), columnNumber); 399 395 } 400 396 … … 403 399 404 400 RefPtr<FormData> report = FormData::create(reportObject->toJSONString().utf8()); 405 406 401 for (const auto& url : reportURIs) 407 402 PingLoader::sendViolationReport(*frame, document.completeURL(url), report.copyRef(), ViolationReportType::ContentSecurityPolicy);
Note:
See TracChangeset
for help on using the changeset viewer.