⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 197263 in webkit


Ignore:
Timestamp:
Feb 27, 2016, 4:50:28 PM (11 years ago)
Author:
Chris Dumez
Message:

Prevent cross-origin access to Location.assign() / Location.reload()
​https://bugs.webkit.org/show_bug.cgi?id=154779

Reviewed by Darin Adler.

Source/WebCore:

Prevent cross-origin access to Location.assign() / Location.reload()
to match the latest specification:

Firefox and Chrome already prevent this but WebKit allowed it.

No new tests, already covered by existing tests.

  • bindings/js/JSLocationCustom.cpp:

(WebCore::JSLocation::getOwnPropertySlotDelegate):
(WebCore::JSLocation::putDelegate): Deleted.

LayoutTests:

Update existing layout tests now that we prevent cross-origin access to
Location.assign() / Location.reload().

  • http/tests/security/cross-frame-access-getOwnPropertyDescriptor-expected.txt:
  • http/tests/security/cross-frame-access-getOwnPropertyDescriptor.html:
  • http/tests/security/cross-frame-access-location-get-expected.txt:
  • http/tests/security/cross-frame-access-location-get-override-expected.txt:
  • http/tests/security/cross-frame-access-location-get-override.html:
  • http/tests/security/cross-frame-access-location-get.html:
  • http/tests/security/xss-DENIED-defineProperty-expected.txt:
Location:
trunk
Files:
10 edited

Legend:

Unmodified
Added
Removed
  • trunk/LayoutTests/ChangeLog

    r197261 r197263  
     12016-02-27  Chris Dumez  <cdumez@apple.com>
     2
     3        Prevent cross-origin access to Location.assign() / Location.reload()
     4        https://bugs.webkit.org/show_bug.cgi?id=154779
     5
     6        Reviewed by Darin Adler.
     7
     8        Update existing layout tests now that we prevent cross-origin access to
     9        Location.assign() / Location.reload().
     10
     11        * http/tests/security/cross-frame-access-getOwnPropertyDescriptor-expected.txt:
     12        * http/tests/security/cross-frame-access-getOwnPropertyDescriptor.html:
     13        * http/tests/security/cross-frame-access-location-get-expected.txt:
     14        * http/tests/security/cross-frame-access-location-get-override-expected.txt:
     15        * http/tests/security/cross-frame-access-location-get-override.html:
     16        * http/tests/security/cross-frame-access-location-get.html:
     17        * http/tests/security/xss-DENIED-defineProperty-expected.txt:
     18
    1192016-02-27  Andy VanWagoner  <thetalecrafter@gmail.com>
    220
  • trunk/LayoutTests/http/tests/security/cross-frame-access-getOwnPropertyDescriptor-expected.txt

    r196227 r197263  
     1CONSOLE MESSAGE: line 64: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match.
     2CONSOLE MESSAGE: line 64: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match.
    13CONSOLE MESSAGE: line 64: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match.
    24CONSOLE MESSAGE: line 64: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match.
    … …  
    409411PASS: canGetDescriptor(targetLocation, 'valueOf') should be 'false' and is.
    410412PASS: canGetDescriptor(targetLocation, 'customProperty') should be 'false' and is.
    411 PASS: canGetDescriptor(targetLocation, 'assign') should be 'true' and is.
     413PASS: canGetDescriptor(targetLocation, 'assign') should be 'false' and is.
     414PASS: canGetDescriptor(targetLocation, 'reload') should be 'false' and is.
    412415PASS: canGetDescriptor(targetLocation, 'replace') should be 'true' and is.
    413 PASS: canGetDescriptor(targetLocation, 'reload') should be 'true' and is.
    414416----- tests access to cross domain history object -----
    415417PASS: canGetDescriptor(targetHistory, 'length') should be 'false' and is.
  • trunk/LayoutTests/http/tests/security/cross-frame-access-getOwnPropertyDescriptor.html

    r196227 r197263  
    254254            window.targetLocation = targetWindow.location;
    255255            var locationPropertiesNotAllowed = [
    256                 "protocol", "host", "hostname", "port", "pathname", "search", "hash", "toString", "valueOf", "customProperty"
     256                "protocol", "host", "hostname", "port", "pathname", "search", "hash", "toString", "valueOf", "customProperty", "assign", "reload"
    257257            ];
    258258            var locationPropertiesAllowed = [
    259                 "assign", "replace", "reload"
     259                "replace"
    260260            ];
    261261            for (var i = 0; i < locationPropertiesNotAllowed.length; i++)
  • trunk/LayoutTests/http/tests/security/cross-frame-access-location-get-expected.txt

    r178527 r197263  
    11CONSOLE MESSAGE: line 107: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match.
    22CONSOLE MESSAGE: line 107: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match.
     3CONSOLE MESSAGE: line 55: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match.
     4CONSOLE MESSAGE: line 55: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match.
    35CONSOLE MESSAGE: line 55: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match.
    46CONSOLE MESSAGE: line 55: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match.
    … …  
    2729PASS: canGet('targetWindow.location.protocol') should be 'false' and is.
    2830PASS: canGet('targetWindow.location.search') should be 'false' and is.
    29 PASS: canGet('targetWindow.location.assign') should be 'true' and is.
    30 PASS: canGet('targetWindow.location.reload') should be 'true' and is.
     31PASS: canGet('targetWindow.location.assign') should be 'false' and is.
     32PASS: canGet('targetWindow.location.reload') should be 'false' and is.
    3133PASS: canGet('targetWindow.location.replace') should be 'true' and is.
    3234PASS: canGet('targetWindow.location.existingCustomProperty') should be 'false' and is.
  • trunk/LayoutTests/http/tests/security/cross-frame-access-location-get-override-expected.txt

    r30157 r197263  
     1CONSOLE MESSAGE: line 55: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match.
     2CONSOLE MESSAGE: line 55: Blocked a frame with origin "http://127.0.0.1:8000" from accessing a frame with origin "http://localhost:8000". Protocols, domains, and ports must match.
    13
    24----- tests for getting a targetWindow's location object's functions which have custom overrides.  The desired behavior is for the targetWindow to return the builtin function, not the override -----
    35
    4 PASS: canGet('targetWindow.location.assign') should be 'true' and is.
    5 PASS: toString('targetWindow.location.assign') should be 'function assign() {    [native code]}' and is.
    6 PASS: canGet('targetWindow.location.reload') should be 'true' and is.
    7 PASS: toString('targetWindow.location.reload') should be 'function reload() {    [native code]}' and is.
     6PASS: canGet('targetWindow.location.assign') should be 'false' and is.
     7PASS: canGet('targetWindow.location.reload') should be 'false' and is.
    88PASS: canGet('targetWindow.location.replace') should be 'true' and is.
    99PASS: toString('targetWindow.location.replace') should be 'function replace() {    [native code]}' and is.
  • trunk/LayoutTests/http/tests/security/cross-frame-access-location-get-override.html

    r120174 r197263  
    4141
    4242            // Overriden using window.location.assign = function() { return "new assign" }
    43             shouldBeTrue("canGet('targetWindow.location.assign')");
    44             shouldBe("toString('targetWindow.location.assign')", "toString('window.location.assign')");
     43            shouldBeFalse("canGet('targetWindow.location.assign')");
    4544
    4645            // Overriden using window.location.reload = "new reload"
    47             shouldBeTrue("canGet('targetWindow.location.reload')");
    48             shouldBe("toString('targetWindow.location.reload')", "toString('window.location.reload')");
     46            shouldBeFalse("canGet('targetWindow.location.reload')");
    4947
    5048            // Overriden using window.location.reload = "new replace"
  • trunk/LayoutTests/http/tests/security/cross-frame-access-location-get.html

    r143104 r197263  
    5151            shouldBeFalse("canGet('targetWindow.location.protocol')");
    5252            shouldBeFalse("canGet('targetWindow.location.search')");
     53            shouldBeFalse("canGet('targetWindow.location.assign')");
     54            shouldBeFalse("canGet('targetWindow.location.reload')");
    5355
    54             shouldBeTrue("canGet('targetWindow.location.assign')");
    55             shouldBeTrue("canGet('targetWindow.location.reload')");
    5656            shouldBeTrue("canGet('targetWindow.location.replace')");
    5757
  • trunk/LayoutTests/http/tests/security/xss-DENIED-defineProperty-expected.txt

    r178527 r197263  
    5353CONSOLE MESSAGE: line 36: Blocked a frame with origin "http://localhost:8000" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and ports must match.
    5454CONSOLE MESSAGE: line 36: Blocked a frame with origin "http://localhost:8000" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and ports must match.
     55CONSOLE MESSAGE: line 38: Blocked a frame with origin "http://localhost:8000" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and ports must match.
     56CONSOLE MESSAGE: line 38: Blocked a frame with origin "http://localhost:8000" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and ports must match.
     57CONSOLE MESSAGE: line 38: Blocked a frame with origin "http://localhost:8000" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and ports must match.
     58CONSOLE MESSAGE: line 38: Blocked a frame with origin "http://localhost:8000" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and ports must match.
     59CONSOLE MESSAGE: line 38: Blocked a frame with origin "http://localhost:8000" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and ports must match.
     60CONSOLE MESSAGE: line 38: Blocked a frame with origin "http://localhost:8000" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and ports must match.
    5561CONSOLE MESSAGE: line 40: Blocked a frame with origin "http://localhost:8000" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and ports must match.
    5662CONSOLE MESSAGE: line 40: Blocked a frame with origin "http://localhost:8000" from accessing a frame with origin "http://127.0.0.1:8000". Protocols, domains, and ports must match.
  • trunk/Source/WebCore/ChangeLog

    r197261 r197263  
     12016-02-27  Chris Dumez  <cdumez@apple.com>
     2
     3        Prevent cross-origin access to Location.assign() / Location.reload()
     4        https://bugs.webkit.org/show_bug.cgi?id=154779
     5
     6        Reviewed by Darin Adler.
     7
     8        Prevent cross-origin access to Location.assign() / Location.reload()
     9        to match the latest specification:
     10        - https://html.spec.whatwg.org/multipage/browsers.html#crossoriginproperties-(-o-)
     11
     12        Firefox and Chrome already prevent this but WebKit allowed it.
     13
     14        No new tests, already covered by existing tests.
     15
     16        * bindings/js/JSLocationCustom.cpp:
     17        (WebCore::JSLocation::getOwnPropertySlotDelegate):
     18        (WebCore::JSLocation::putDelegate): Deleted.
     19
    1202016-02-27  Andy VanWagoner  <thetalecrafter@gmail.com>
    221
  • trunk/Source/WebCore/bindings/js/JSLocationCustom.cpp

    r196648 r197263  
    4848        return false;
    4949
    50     // Check for the few functions that we allow, even when called cross-domain.
    51     // Make these read-only / non-configurable to prevent writes via defineProperty.
     50    // We only allow access to Location.replace() cross origin.
     51    // Make it read-only / non-configurable to prevent writes via defineProperty.
    5252    if (propertyName == exec->propertyNames().replace) {
    5353        slot.setCustom(this, ReadOnly | DontDelete | DontEnum, nonCachingStaticFunctionGetter<jsLocationInstanceFunctionReplace, 1>);
    5454        return true;
    5555    }
    56     if (propertyName == exec->propertyNames().reload) {
    57         slot.setCustom(this, ReadOnly | DontDelete | DontEnum, nonCachingStaticFunctionGetter<jsLocationInstanceFunctionReload, 0>);
    58         return true;
    59     }
    60     if (propertyName == exec->propertyNames().assign) {
    61         slot.setCustom(this, ReadOnly | DontDelete | DontEnum, nonCachingStaticFunctionGetter<jsLocationInstanceFunctionAssign, 1>);
    62         return true;
    63     }
    64 
    65     // FIXME: Other implementers of the Window cross-domain scheme (Window, History) allow toString,
    66     // but for now we have decided not to, partly because it seems silly to return "[Object Location]" in
    67     // such cases when normally the string form of Location would be the URL.
    6856
    6957    printErrorMessageForFrame(frame, message);
Note: See TracChangeset for help on using the changeset viewer.