Changeset 197150 in webkit
- Timestamp:
- Feb 25, 2016, 5:22:33 PM (11 years ago)
- Location:
- trunk
- Files:
-
- 2 added
- 6 edited
-
Source/WebKit/mac/ChangeLog (modified) (1 diff)
-
Source/WebKit/mac/WebCoreSupport/WebFrameLoaderClient.mm (modified) (2 diffs)
-
Source/WebKit2/ChangeLog (modified) (1 diff)
-
Source/WebKit2/WebProcess/InjectedBundle/InjectedBundleNavigationAction.cpp (modified) (2 diffs)
-
Tools/ChangeLog (modified) (1 diff)
-
Tools/TestWebKitAPI/TestWebKitAPI.xcodeproj/project.pbxproj (modified) (9 diffs)
-
Tools/TestWebKitAPI/Tests/mac/IsNavigationActionTrusted.html (added)
-
Tools/TestWebKitAPI/Tests/mac/IsNavigationActionTrusted.mm (added)
Legend:
- Unmodified
- Added
- Removed
-
trunk/Source/WebKit/mac/ChangeLog
r197114 r197150 1 2016-02-25 Jiewen Tan <jiewen_tan@apple.com> 2 3 Restrict information passed with navigation action which is triggered by untrusted event 4 https://bugs.webkit.org/show_bug.cgi?id=154571 5 <rdar://problem/15967937> 6 7 Reviewed by Andy Estes. 8 9 * WebCoreSupport/WebFrameLoaderClient.mm: 10 (WebFrameLoaderClient::actionDictionary): 11 1 12 2016-02-25 Eric Carlson <eric.carlson@apple.com> 2 13 -
trunk/Source/WebKit/mac/WebCoreSupport/WebFrameLoaderClient.mm
r195743 r197150 1562 1562 const Event* event = action.event(); 1563 1563 #if !PLATFORM(IOS) 1564 if (const UIEventWithKeyState* keyStateEvent = findEventWithKeyState(const_cast<Event*>(event))) { 1564 const UIEventWithKeyState* keyStateEvent = findEventWithKeyState(const_cast<Event*>(event)); 1565 if (keyStateEvent && keyStateEvent->isTrusted()) { 1565 1566 if (keyStateEvent->ctrlKey()) 1566 1567 modifierFlags |= NSControlKeyMask; … … 1591 1592 [element release]; 1592 1593 1593 [result setObject:[NSNumber numberWithInt:mouseEvent->button()] forKey:WebActionButtonKey]; 1594 if (mouseEvent->isTrusted()) 1595 [result setObject:[NSNumber numberWithInt:mouseEvent->button()] forKey:WebActionButtonKey]; 1596 else 1597 [result setObject:[NSNumber numberWithInt:WebCore::NoButton] forKey:WebActionButtonKey]; 1594 1598 } 1595 1599 -
trunk/Source/WebKit2/ChangeLog
r197133 r197150 1 2016-02-25 Jiewen Tan <jiewen_tan@apple.com> 2 3 Restrict information passed with navigation action which is triggered by untrusted event 4 https://bugs.webkit.org/show_bug.cgi?id=154571 5 <rdar://problem/15967937> 6 7 Reviewed by Andy Estes. 8 9 When navigation action is triggered by an untrusted event, we should be more restricted of 10 what information should be passed to the clients to lower the risk that clients could 11 be fooled by the untrusted event. 12 13 In this patch, we drop the modifiers for key state events and set the mouse button to NoButton 14 for mouse events. 15 16 * WebProcess/InjectedBundle/InjectedBundleNavigationAction.cpp: 17 (WebKit::InjectedBundleNavigationAction::modifiersForNavigationAction): 18 1 19 2016-02-25 Ada Chan <adachan@apple.com> 2 20 -
trunk/Source/WebKit2/WebProcess/InjectedBundle/InjectedBundleNavigationAction.cpp
r186664 r197150 53 53 return WebMouseEvent::NoButton; 54 54 55 if (!mouseEvent->buttonDown() )55 if (!mouseEvent->buttonDown() || !mouseEvent->isTrusted()) 56 56 return WebMouseEvent::NoButton; 57 57 … … 62 62 { 63 63 uint32_t modifiers = 0; 64 if (const UIEventWithKeyState* keyStateEvent = findEventWithKeyState(const_cast<Event*>(navigationAction.event()))) { 64 const UIEventWithKeyState* keyStateEvent = findEventWithKeyState(const_cast<Event*>(navigationAction.event())); 65 if (keyStateEvent && keyStateEvent->isTrusted()) { 65 66 if (keyStateEvent->shiftKey()) 66 67 modifiers |= WebEvent::ShiftKey; -
trunk/Tools/ChangeLog
r197132 r197150 1 2016-02-25 Jiewen Tan <jiewen_tan@apple.com> 2 3 Restrict information passed with navigation action which is triggered by untrusted event 4 https://bugs.webkit.org/show_bug.cgi?id=154571 5 <rdar://problem/15967937> 6 7 Reviewed by Andy Estes. 8 9 * TestWebKitAPI/TestWebKitAPI.xcodeproj/project.pbxproj: 10 * TestWebKitAPI/Tests/mac/IsNavigationActionTrusted.mm: Added. 11 (-[WKNavigationActionDelegate webView:decidePolicyForNavigationAction:decisionHandler:]): 12 (TestWebKitAPI::TEST): 13 (-[NavigationActionDelegate webView:decidePolicyForNavigationAction:request:frame:decisionListener:]): 14 * TestWebKitAPI/Tests/mac/IsNavigationActionTrusted.html: Added. 15 1 16 2016-02-25 Gavin Barraclough <barraclough@apple.com> 2 17 -
trunk/Tools/TestWebKitAPI/TestWebKitAPI.xcodeproj/project.pbxproj
r196987 r197150 76 76 52D673EE1AFB127300FA19FE /* WKPageCopySessionStateWithFiltering.cpp in Sources */ = {isa = PBXBuildFile; fileRef = 52D673EC1AFB126800FA19FE /* WKPageCopySessionStateWithFiltering.cpp */; }; 77 77 52E5CE4914D21EAB003B2BD8 /* ParentFrame_Bundle.cpp in Sources */ = {isa = PBXBuildFile; fileRef = 52E5CE4814D21EAB003B2BD8 /* ParentFrame_Bundle.cpp */; }; 78 57F10D931C7E7B3800ECDF30 /* IsNavigationActionTrusted.mm in Sources */ = {isa = PBXBuildFile; fileRef = 57F10D921C7E7B3800ECDF30 /* IsNavigationActionTrusted.mm */; }; 79 57F56A5C1C7F8CC100F31D7E /* IsNavigationActionTrusted.html in Copy Resources */ = {isa = PBXBuildFile; fileRef = 57F56A5B1C7F8A4000F31D7E /* IsNavigationActionTrusted.html */; }; 78 80 764322D71B61CCC30024F801 /* WordBoundaryTypingAttributes.mm in Sources */ = {isa = PBXBuildFile; fileRef = 764322D51B61CCA40024F801 /* WordBoundaryTypingAttributes.mm */; }; 79 81 7673499D1930C5BB00E44DF9 /* StopLoadingDuringDidFailProvisionalLoad_bundle.cpp in Sources */ = {isa = PBXBuildFile; fileRef = 7673499A1930182E00E44DF9 /* StopLoadingDuringDidFailProvisionalLoad_bundle.cpp */; }; … … 387 389 dstSubfolderSpec = 7; 388 390 files = ( 391 57F56A5C1C7F8CC100F31D7E /* IsNavigationActionTrusted.html in Copy Resources */, 389 392 A16F66BA1C40EB4F00BD4D24 /* ContentFiltering.html in Copy Resources */, 390 393 CDC8E4941BC6F10800594FEC /* video-with-audio.html in Copy Resources */, … … 605 608 52E5CE4514D21E9D003B2BD8 /* ParentFrame.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; path = ParentFrame.cpp; sourceTree = "<group>"; }; 606 609 52E5CE4814D21EAB003B2BD8 /* ParentFrame_Bundle.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; path = ParentFrame_Bundle.cpp; sourceTree = "<group>"; }; 610 57F10D921C7E7B3800ECDF30 /* IsNavigationActionTrusted.mm */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.objcpp; path = IsNavigationActionTrusted.mm; sourceTree = "<group>"; }; 611 57F56A5B1C7F8A4000F31D7E /* IsNavigationActionTrusted.html */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = text.html; path = IsNavigationActionTrusted.html; sourceTree = "<group>"; }; 607 612 7560917719259C59009EF06E /* MemoryCacheAddImageToCacheIOS.mm */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.objcpp; path = MemoryCacheAddImageToCacheIOS.mm; sourceTree = "<group>"; }; 608 613 75F3133F18C171B70041CAEC /* EphemeralSessionPushStateNoHistoryCallback.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; path = EphemeralSessionPushStateNoHistoryCallback.cpp; sourceTree = "<group>"; }; … … 1273 1278 isa = PBXGroup; 1274 1279 children = ( 1275 7AE9E5081AE5AE8B00CF874B /* test.pdf */,1276 7A1458FB1AD5C03500E06772 /* mouse-button-listener.html */,1277 1280 C045F9461385C2F800C0F3CD /* 18-characters.html */, 1278 1281 93D3D19B17B1A7B000C7C415 /* all-content-in-one-iframe.html */, … … 1301 1304 930AD401150698B30067970F /* lots-of-text.html */, 1302 1305 51CD1C711B38D48400142CA5 /* modal-alerts-in-new-about-blank-window.html */, 1306 7A1458FB1AD5C03500E06772 /* mouse-button-listener.html */, 1303 1307 33E79E05137B5FCE00E32D99 /* mouse-move-listener.html */, 1304 1308 CEA6CF2719CCF69D0064F5A7 /* open-and-close-window.html */, … … 1313 1317 CEBABD481B71687C0051210A /* should-open-external-schemes.html */, 1314 1318 C02B7882126615410026BF0F /* spacebar-scrolling.html */, 1319 7AE9E5081AE5AE8B00CF874B /* test.pdf */, 1315 1320 CD59F53319E910BC00CF1835 /* test-mse.mp4 */, 1316 1321 524BBCA019E30C63002F1AF1 /* test.mp4 */, … … 1378 1383 9B26FC6B159D061000CC3765 /* HTMLFormCollectionNamedItem.mm */, 1379 1384 C507E8A614C6545B005D6B3B /* InspectorBar.mm */, 1385 57F10D921C7E7B3800ECDF30 /* IsNavigationActionTrusted.mm */, 1380 1386 4BB4160116815B2600824238 /* JSWrapperForNodeInWebFrame.mm */, 1381 1387 E1220D9F155B25480013E2FC /* MemoryCacheDisableWithinResourceLoadDelegate.mm */, … … 1425 1431 9B4F8FA6159D52CA002D9F94 /* HTMLCollectionNamedItem.html */, 1426 1432 9B26FCB4159D15E700CC3765 /* HTMLFormCollectionNamedItem.html */, 1433 57F56A5B1C7F8A4000F31D7E /* IsNavigationActionTrusted.html */, 1427 1434 C2CF975816CEC69E0054E99D /* JSContextBackForwardCache1.html */, 1428 1435 C2CF975916CEC69E0054E99D /* JSContextBackForwardCache2.html */, … … 1860 1867 CD225C081C45A69200140761 /* ParsedContentRange.cpp in Sources */, 1861 1868 41973B5D1AF22875006C7B36 /* SharedBuffer.cpp in Sources */, 1869 57F10D931C7E7B3800ECDF30 /* IsNavigationActionTrusted.mm in Sources */, 1862 1870 2DD355361BD08378005DF4A7 /* AutoLayoutIntegration.mm in Sources */, 1863 1871 7AA6A1521AAC0B31002B2ED3 /* WorkQueue.cpp in Sources */,
Note:
See TracChangeset
for help on using the changeset viewer.