Changeset 276666 in webkit
- Timestamp:
- Apr 27, 2021, 2:07:24 PM (5 years ago)
- Location:
- branches/safari-611-branch
- Files:
-
- 3 added
- 4 edited
-
LayoutTests/ChangeLog (modified) (1 diff)
-
LayoutTests/http/tests/security/resources/sandbox-iframe-and-blob-frame.html (added)
-
LayoutTests/http/tests/security/sandbox-iframe-and-blob.https-expected.txt (added)
-
LayoutTests/http/tests/security/sandbox-iframe-and-blob.https.html (added)
-
LayoutTests/platform/win/TestExpectations (modified) (1 diff)
-
Source/WebCore/ChangeLog (modified) (1 diff)
-
Source/WebCore/loader/PolicyChecker.cpp (modified) (2 diffs)
Legend:
- Unmodified
- Added
- Removed
-
branches/safari-611-branch/LayoutTests/ChangeLog
r276661 r276666 1 2021-04-27 Russell Epstein <repstein@apple.com> 2 3 Cherry-pick r276012. rdar://problem/77211405 4 5 REGRESSION(Safari 14): iframe with blob url does not work with sandboxing 6 https://bugs.webkit.org/show_bug.cgi?id=222312 7 <rdar://problem/74927624> 8 9 Reviewed by Chris Dumez. 10 11 Source/WebCore: 12 13 In https://trac.webkit.org/r275884, we correctly compute whether a blob is to be considered secure or not. 14 For that, we need to have the blob URL registered with its document origin. 15 Update PolicyChecker to properly register the temporoary blob URL with its document origin. 16 17 Test: http/tests/security/sandbox-iframe-and-blob.https.html 18 19 * loader/PolicyChecker.cpp: 20 (WebCore::FrameLoader::PolicyChecker::extendBlobURLLifetimeIfNecessary const): 21 22 LayoutTests: 23 24 * http/tests/security/resources/sandbox-iframe-and-blob-frame.html: Added. 25 * http/tests/security/sandbox-iframe-and-blob.https-expected.txt: Added. 26 * http/tests/security/sandbox-iframe-and-blob.https.html: Added. 27 * platform/win/TestExpectations: 28 29 30 git-svn-id: https://svn.webkit.org/repository/webkit/trunk@276012 268f45cc-cd09-0410-ab3c-d52691b4dbfc 31 32 2021-04-15 Youenn Fablet <youenn@apple.com> 33 34 REGRESSION(Safari 14): iframe with blob url does not work with sandboxing 35 https://bugs.webkit.org/show_bug.cgi?id=222312 36 <rdar://problem/74927624> 37 38 Reviewed by Chris Dumez. 39 40 * http/tests/security/resources/sandbox-iframe-and-blob-frame.html: Added. 41 * http/tests/security/sandbox-iframe-and-blob.https-expected.txt: Added. 42 * http/tests/security/sandbox-iframe-and-blob.https.html: Added. 43 * platform/win/TestExpectations: 44 1 45 2021-04-27 Russell Epstein <repstein@apple.com> 2 46 -
branches/safari-611-branch/LayoutTests/platform/win/TestExpectations
r275724 r276666 2331 2331 http/tests/security/contentSecurityPolicy/report-document-uri-blob.html [ Skip ] 2332 2332 fast/frames/restoring-page-cache-should-not-run-scripts-via-style-update.html [ Skip ] 2333 http/tests/security/sandbox-iframe-and-blob.https.html [ Skip ] 2333 2334 2334 2335 # Clear Key not implemented -
branches/safari-611-branch/Source/WebCore/ChangeLog
r276663 r276666 1 2021-04-27 Russell Epstein <repstein@apple.com> 2 3 Cherry-pick r276012. rdar://problem/77211405 4 5 REGRESSION(Safari 14): iframe with blob url does not work with sandboxing 6 https://bugs.webkit.org/show_bug.cgi?id=222312 7 <rdar://problem/74927624> 8 9 Reviewed by Chris Dumez. 10 11 Source/WebCore: 12 13 In https://trac.webkit.org/r275884, we correctly compute whether a blob is to be considered secure or not. 14 For that, we need to have the blob URL registered with its document origin. 15 Update PolicyChecker to properly register the temporoary blob URL with its document origin. 16 17 Test: http/tests/security/sandbox-iframe-and-blob.https.html 18 19 * loader/PolicyChecker.cpp: 20 (WebCore::FrameLoader::PolicyChecker::extendBlobURLLifetimeIfNecessary const): 21 22 LayoutTests: 23 24 * http/tests/security/resources/sandbox-iframe-and-blob-frame.html: Added. 25 * http/tests/security/sandbox-iframe-and-blob.https-expected.txt: Added. 26 * http/tests/security/sandbox-iframe-and-blob.https.html: Added. 27 * platform/win/TestExpectations: 28 29 30 git-svn-id: https://svn.webkit.org/repository/webkit/trunk@276012 268f45cc-cd09-0410-ab3c-d52691b4dbfc 31 32 2021-04-15 Youenn Fablet <youenn@apple.com> 33 34 REGRESSION(Safari 14): iframe with blob url does not work with sandboxing 35 https://bugs.webkit.org/show_bug.cgi?id=222312 36 <rdar://problem/74927624> 37 38 Reviewed by Chris Dumez. 39 40 In https://trac.webkit.org/r275884, we correctly compute whether a blob is to be considered secure or not. 41 For that, we need to have the blob URL registered with its document origin. 42 Update PolicyChecker to properly register the temporoary blob URL with its document origin. 43 44 Test: http/tests/security/sandbox-iframe-and-blob.https.html 45 46 * loader/PolicyChecker.cpp: 47 (WebCore::FrameLoader::PolicyChecker::extendBlobURLLifetimeIfNecessary const): 48 1 49 2021-04-27 Russell Epstein <repstein@apple.com> 2 50 -
branches/safari-611-branch/Source/WebCore/loader/PolicyChecker.cpp
r262085 r276666 48 48 #include "HTMLPlugInElement.h" 49 49 #include "Logging.h" 50 #include "ThreadableBlobRegistry.h" 50 51 #include <wtf/CompletionHandler.h> 51 52 … … 112 113 // Create a new temporary blobURL in case this one gets revoked during the asynchronous navigation policy decision. 113 114 URL temporaryBlobURL = BlobURL::createPublicURL(&m_frame.document()->securityOrigin()); 114 blobRegistry().registerBlobURL(temporaryBlobURL, request.url());115 ThreadableBlobRegistry::registerBlobURL(&m_frame.document()->securityOrigin(), temporaryBlobURL, request.url()); 115 116 request.setURL(temporaryBlobURL); 116 117 if (loader) 117 118 loader->request().setURL(temporaryBlobURL); 118 119 return CompletionHandler<void()>([temporaryBlobURL = WTFMove(temporaryBlobURL)] { 119 blobRegistry().unregisterBlobURL(temporaryBlobURL);120 ThreadableBlobRegistry::unregisterBlobURL(temporaryBlobURL); 120 121 }); 121 122 }
Note:
See TracChangeset
for help on using the changeset viewer.