Changeset 197263 in webkit
- Timestamp:
- Feb 27, 2016, 4:50:28 PM (11 years ago)
- Location:
- trunk
- Files:
-
- 10 edited
-
LayoutTests/ChangeLog (modified) (1 diff)
-
LayoutTests/http/tests/security/cross-frame-access-getOwnPropertyDescriptor-expected.txt (modified) (2 diffs)
-
LayoutTests/http/tests/security/cross-frame-access-getOwnPropertyDescriptor.html (modified) (1 diff)
-
LayoutTests/http/tests/security/cross-frame-access-location-get-expected.txt (modified) (2 diffs)
-
LayoutTests/http/tests/security/cross-frame-access-location-get-override-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/cross-frame-access-location-get-override.html (modified) (1 diff)
-
LayoutTests/http/tests/security/cross-frame-access-location-get.html (modified) (1 diff)
-
LayoutTests/http/tests/security/xss-DENIED-defineProperty-expected.txt (modified) (1 diff)
-
Source/WebCore/ChangeLog (modified) (1 diff)
-
Source/WebCore/bindings/js/JSLocationCustom.cpp (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
trunk/LayoutTests/ChangeLog
r197261 r197263 1 2016-02-27 Chris Dumez <cdumez@apple.com> 2 3 Prevent cross-origin access to Location.assign() / Location.reload() 4 https://bugs.webkit.org/show_bug.cgi?id=154779 5 6 Reviewed by Darin Adler. 7 8 Update existing layout tests now that we prevent cross-origin access to 9 Location.assign() / Location.reload(). 10 11 * http/tests/security/cross-frame-access-getOwnPropertyDescriptor-expected.txt: 12 * http/tests/security/cross-frame-access-getOwnPropertyDescriptor.html: 13 * http/tests/security/cross-frame-access-location-get-expected.txt: 14 * http/tests/security/cross-frame-access-location-get-override-expected.txt: 15 * http/tests/security/cross-frame-access-location-get-override.html: 16 * http/tests/security/cross-frame-access-location-get.html: 17 * http/tests/security/xss-DENIED-defineProperty-expected.txt: 18 1 19 2016-02-27 Andy VanWagoner <thetalecrafter@gmail.com> 2 20 -
trunk/LayoutTests/http/tests/security/cross-frame-access-getOwnPropertyDescriptor-expected.txt
r196227 r197263 1 CONSOLE MESSAGE: line 64: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match. 2 CONSOLE MESSAGE: line 64: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match. 1 3 CONSOLE MESSAGE: line 64: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match. 2 4 CONSOLE MESSAGE: line 64: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match. … … 409 411 PASS: canGetDescriptor(targetLocation, 'valueOf') should be 'false' and is. 410 412 PASS: canGetDescriptor(targetLocation, 'customProperty') should be 'false' and is. 411 PASS: canGetDescriptor(targetLocation, 'assign') should be 'true' and is. 413 PASS: canGetDescriptor(targetLocation, 'assign') should be 'false' and is. 414 PASS: canGetDescriptor(targetLocation, 'reload') should be 'false' and is. 412 415 PASS: canGetDescriptor(targetLocation, 'replace') should be 'true' and is. 413 PASS: canGetDescriptor(targetLocation, 'reload') should be 'true' and is.414 416 ----- tests access to cross domain history object ----- 415 417 PASS: canGetDescriptor(targetHistory, 'length') should be 'false' and is. -
trunk/LayoutTests/http/tests/security/cross-frame-access-getOwnPropertyDescriptor.html
r196227 r197263 254 254 window.targetLocation = targetWindow.location; 255 255 var locationPropertiesNotAllowed = [ 256 "protocol", "host", "hostname", "port", "pathname", "search", "hash", "toString", "valueOf", "customProperty" 256 "protocol", "host", "hostname", "port", "pathname", "search", "hash", "toString", "valueOf", "customProperty", "assign", "reload" 257 257 ]; 258 258 var locationPropertiesAllowed = [ 259 " assign", "replace", "reload"259 "replace" 260 260 ]; 261 261 for (var i = 0; i < locationPropertiesNotAllowed.length; i++) -
trunk/LayoutTests/http/tests/security/cross-frame-access-location-get-expected.txt
r178527 r197263 1 1 CONSOLE MESSAGE: line 107: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match. 2 2 CONSOLE MESSAGE: line 107: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match. 3 CONSOLE MESSAGE: line 55: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match. 4 CONSOLE MESSAGE: line 55: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match. 3 5 CONSOLE MESSAGE: line 55: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match. 4 6 CONSOLE MESSAGE: line 55: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match. … … 27 29 PASS: canGet('targetWindow.location.protocol') should be 'false' and is. 28 30 PASS: canGet('targetWindow.location.search') should be 'false' and is. 29 PASS: canGet('targetWindow.location.assign') should be ' true' and is.30 PASS: canGet('targetWindow.location.reload') should be ' true' and is.31 PASS: canGet('targetWindow.location.assign') should be 'false' and is. 32 PASS: canGet('targetWindow.location.reload') should be 'false' and is. 31 33 PASS: canGet('targetWindow.location.replace') should be 'true' and is. 32 34 PASS: canGet('targetWindow.location.existingCustomProperty') should be 'false' and is. -
trunk/LayoutTests/http/tests/security/cross-frame-access-location-get-override-expected.txt
r30157 r197263 1 CONSOLE MESSAGE: line 55: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match. 2 CONSOLE MESSAGE: line 55: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match. 1 3 2 4 ----- tests for getting a targetWindow's location object's functions which have custom overrides. The desired behavior is for the targetWindow to return the builtin function, not the override ----- 3 5 4 PASS: canGet('targetWindow.location.assign') should be 'true' and is. 5 PASS: toString('targetWindow.location.assign') should be 'function assign() { [native code]}' and is. 6 PASS: canGet('targetWindow.location.reload') should be 'true' and is. 7 PASS: toString('targetWindow.location.reload') should be 'function reload() { [native code]}' and is. 6 PASS: canGet('targetWindow.location.assign') should be 'false' and is. 7 PASS: canGet('targetWindow.location.reload') should be 'false' and is. 8 8 PASS: canGet('targetWindow.location.replace') should be 'true' and is. 9 9 PASS: toString('targetWindow.location.replace') should be 'function replace() { [native code]}' and is. -
trunk/LayoutTests/http/tests/security/cross-frame-access-location-get-override.html
r120174 r197263 41 41 42 42 // Overriden using window.location.assign = function() { return "new assign" } 43 shouldBeTrue("canGet('targetWindow.location.assign')"); 44 shouldBe("toString('targetWindow.location.assign')", "toString('window.location.assign')"); 43 shouldBeFalse("canGet('targetWindow.location.assign')"); 45 44 46 45 // Overriden using window.location.reload = "new reload" 47 shouldBeTrue("canGet('targetWindow.location.reload')"); 48 shouldBe("toString('targetWindow.location.reload')", "toString('window.location.reload')"); 46 shouldBeFalse("canGet('targetWindow.location.reload')"); 49 47 50 48 // Overriden using window.location.reload = "new replace" -
trunk/LayoutTests/http/tests/security/cross-frame-access-location-get.html
r143104 r197263 51 51 shouldBeFalse("canGet('targetWindow.location.protocol')"); 52 52 shouldBeFalse("canGet('targetWindow.location.search')"); 53 shouldBeFalse("canGet('targetWindow.location.assign')"); 54 shouldBeFalse("canGet('targetWindow.location.reload')"); 53 55 54 shouldBeTrue("canGet('targetWindow.location.assign')");55 shouldBeTrue("canGet('targetWindow.location.reload')");56 56 shouldBeTrue("canGet('targetWindow.location.replace')"); 57 57 -
trunk/LayoutTests/http/tests/security/xss-DENIED-defineProperty-expected.txt
r178527 r197263 53 53 CONSOLE MESSAGE: line 36: Blocked a frame with origin "http://localhost:8000" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and ports must match. 54 54 CONSOLE MESSAGE: line 36: Blocked a frame with origin "http://localhost:8000" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and ports must match. 55 CONSOLE MESSAGE: line 38: Blocked a frame with origin "http://localhost:8000" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and ports must match. 56 CONSOLE MESSAGE: line 38: Blocked a frame with origin "http://localhost:8000" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and ports must match. 57 CONSOLE MESSAGE: line 38: Blocked a frame with origin "http://localhost:8000" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and ports must match. 58 CONSOLE MESSAGE: line 38: Blocked a frame with origin "http://localhost:8000" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and ports must match. 59 CONSOLE MESSAGE: line 38: Blocked a frame with origin "http://localhost:8000" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and ports must match. 60 CONSOLE MESSAGE: line 38: Blocked a frame with origin "http://localhost:8000" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and ports must match. 55 61 CONSOLE MESSAGE: line 40: Blocked a frame with origin "http://localhost:8000" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and ports must match. 56 62 CONSOLE MESSAGE: line 40: Blocked a frame with origin "http://localhost:8000" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and ports must match. -
trunk/Source/WebCore/ChangeLog
r197261 r197263 1 2016-02-27 Chris Dumez <cdumez@apple.com> 2 3 Prevent cross-origin access to Location.assign() / Location.reload() 4 https://bugs.webkit.org/show_bug.cgi?id=154779 5 6 Reviewed by Darin Adler. 7 8 Prevent cross-origin access to Location.assign() / Location.reload() 9 to match the latest specification: 10 - https://html.spec.whatwg.org/multipage/browsers.html#crossoriginproperties-(-o-) 11 12 Firefox and Chrome already prevent this but WebKit allowed it. 13 14 No new tests, already covered by existing tests. 15 16 * bindings/js/JSLocationCustom.cpp: 17 (WebCore::JSLocation::getOwnPropertySlotDelegate): 18 (WebCore::JSLocation::putDelegate): Deleted. 19 1 20 2016-02-27 Andy VanWagoner <thetalecrafter@gmail.com> 2 21 -
trunk/Source/WebCore/bindings/js/JSLocationCustom.cpp
r196648 r197263 48 48 return false; 49 49 50 // Check for the few functions that we allow, even when called cross-domain.51 // Make theseread-only / non-configurable to prevent writes via defineProperty.50 // We only allow access to Location.replace() cross origin. 51 // Make it read-only / non-configurable to prevent writes via defineProperty. 52 52 if (propertyName == exec->propertyNames().replace) { 53 53 slot.setCustom(this, ReadOnly | DontDelete | DontEnum, nonCachingStaticFunctionGetter<jsLocationInstanceFunctionReplace, 1>); 54 54 return true; 55 55 } 56 if (propertyName == exec->propertyNames().reload) {57 slot.setCustom(this, ReadOnly | DontDelete | DontEnum, nonCachingStaticFunctionGetter<jsLocationInstanceFunctionReload, 0>);58 return true;59 }60 if (propertyName == exec->propertyNames().assign) {61 slot.setCustom(this, ReadOnly | DontDelete | DontEnum, nonCachingStaticFunctionGetter<jsLocationInstanceFunctionAssign, 1>);62 return true;63 }64 65 // FIXME: Other implementers of the Window cross-domain scheme (Window, History) allow toString,66 // but for now we have decided not to, partly because it seems silly to return "[Object Location]" in67 // such cases when normally the string form of Location would be the URL.68 56 69 57 printErrorMessageForFrame(frame, message);
Note:
See TracChangeset
for help on using the changeset viewer.