⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 276012 in webkit


Ignore:
Timestamp:
Apr 15, 2021, 2:07:44 AM (5 years ago)
Author:
youenn@apple.com
Message:

REGRESSION(Safari 14): iframe with blob url does not work with sandboxing
​https://bugs.webkit.org/show_bug.cgi?id=222312
<rdar://problem/74927624>

Reviewed by Chris Dumez.

Source/WebCore:

In ​https://trac.webkit.org/r275884, we correctly compute whether a blob is to be considered secure or not.
For that, we need to have the blob URL registered with its document origin.
Update PolicyChecker to properly register the temporoary blob URL with its document origin.

Test: http/tests/security/sandbox-iframe-and-blob.https.html

  • loader/PolicyChecker.cpp:

(WebCore::FrameLoader::PolicyChecker::extendBlobURLLifetimeIfNecessary const):

LayoutTests:

  • http/tests/security/resources/sandbox-iframe-and-blob-frame.html: Added.
  • http/tests/security/sandbox-iframe-and-blob.https-expected.txt: Added.
  • http/tests/security/sandbox-iframe-and-blob.https.html: Added.
  • platform/win/TestExpectations:
Location:
trunk
Files:
3 added
4 edited

Legend:

Unmodified
Added
Removed
  • trunk/LayoutTests/ChangeLog

    r276011 r276012  
     12021-04-15  Youenn Fablet  <youenn@apple.com>
     2
     3        REGRESSION(Safari 14): iframe with blob url does not work with sandboxing
     4        https://bugs.webkit.org/show_bug.cgi?id=222312
     5        <rdar://problem/74927624>
     6
     7        Reviewed by Chris Dumez.
     8
     9        * http/tests/security/resources/sandbox-iframe-and-blob-frame.html: Added.
     10        * http/tests/security/sandbox-iframe-and-blob.https-expected.txt: Added.
     11        * http/tests/security/sandbox-iframe-and-blob.https.html: Added.
     12        * platform/win/TestExpectations:
     13
    1142021-04-15  Diego Pino Garcia  <dpino@igalia.com>
    215
  • trunk/LayoutTests/platform/win/TestExpectations

    r275917 r276012  
    22632263http/tests/security/contentSecurityPolicy/report-document-uri-blob.html [ Skip ]
    22642264fast/frames/restoring-page-cache-should-not-run-scripts-via-style-update.html [ Skip ]
     2265http/tests/security/sandbox-iframe-and-blob.https.html [ Skip ]
    22652266
    22662267# Clear Key not implemented
  • trunk/Source/WebCore/ChangeLog

    r276010 r276012  
     12021-04-15  Youenn Fablet  <youenn@apple.com>
     2
     3        REGRESSION(Safari 14): iframe with blob url does not work with sandboxing
     4        https://bugs.webkit.org/show_bug.cgi?id=222312
     5        <rdar://problem/74927624>
     6
     7        Reviewed by Chris Dumez.
     8
     9        In https://trac.webkit.org/r275884, we correctly compute whether a blob is to be considered secure or not.
     10        For that, we need to have the blob URL registered with its document origin.
     11        Update PolicyChecker to properly register the temporoary blob URL with its document origin.
     12
     13        Test: http/tests/security/sandbox-iframe-and-blob.https.html
     14
     15        * loader/PolicyChecker.cpp:
     16        (WebCore::FrameLoader::PolicyChecker::extendBlobURLLifetimeIfNecessary const):
     17
    1182021-04-15  Carlos Garcia Campos  <cgarcia@igalia.com>
    219
  • trunk/Source/WebCore/loader/PolicyChecker.cpp

    r272122 r276012  
    4848#include "HTMLPlugInElement.h"
    4949#include "Logging.h"
     50#include "ThreadableBlobRegistry.h"
    5051#include <wtf/CompletionHandler.h>
    5152
    … …  
    112113    // Create a new temporary blobURL in case this one gets revoked during the asynchronous navigation policy decision.
    113114    URL temporaryBlobURL = BlobURL::createPublicURL(&m_frame.document()->securityOrigin());
    114     blobRegistry().registerBlobURL(temporaryBlobURL, request.url());
     115    ThreadableBlobRegistry::registerBlobURL(&m_frame.document()->securityOrigin(), temporaryBlobURL, request.url());
    115116    request.setURL(temporaryBlobURL);
    116117    if (loader)
    117118        loader->request().setURL(temporaryBlobURL);
    118119    return CompletionHandler<void()>([temporaryBlobURL = WTFMove(temporaryBlobURL)] {
    119         blobRegistry().unregisterBlobURL(temporaryBlobURL);
     120        ThreadableBlobRegistry::unregisterBlobURL(temporaryBlobURL);
    120121    });
    121122}
Note: See TracChangeset for help on using the changeset viewer.