⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 283732 in webkit


Ignore:
Timestamp:
Oct 7, 2021, 12:12:57 PM (5 years ago)
Author:
Chris Dumez
Message:

Add feature flag for COOP / COEP violation reporting and turn off by default
​https://bugs.webkit.org/show_bug.cgi?id=231371

Reviewed by Youenn Fablet.

Add feature flag for COOP / COEP violation reporting and turn off by default since our
implementation doesn't match the latest specification.

Source/WebCore:

  • loader/CrossOriginEmbedderPolicy.cpp:

(WebCore::sendCOEPPolicyInheritenceViolation):
(WebCore::sendCOEPCORPViolation):

  • loader/CrossOriginOpenerPolicy.cpp:

(WebCore::sendViolationReportWhenNavigatingToCOOPResponse):
(WebCore::sendViolationReportWhenNavigatingAwayFromCOOPResponse):

Source/WTF:

  • Scripts/Preferences/WebPreferencesExperimental.yaml:
Location:
trunk/Source
Files:
5 edited

Legend:

Unmodified
Added
Removed
  • trunk/Source/WTF/ChangeLog

    r283676 r283732  
     12021-10-07  Chris Dumez  <cdumez@apple.com>
     2
     3        Add feature flag for COOP / COEP violation reporting and turn off by default
     4        https://bugs.webkit.org/show_bug.cgi?id=231371
     5
     6        Reviewed by Youenn Fablet.
     7
     8        Add feature flag for COOP / COEP violation reporting and turn off by default since our
     9        implementation doesn't match the latest specification.
     10
     11        * Scripts/Preferences/WebPreferencesExperimental.yaml:
     12
    1132021-10-06  Sihui Liu  <sihui_liu@apple.com>
    214
  • trunk/Source/WTF/Scripts/Preferences/WebPreferencesExperimental.yaml

    r283676 r283732  
    332332      default: false
    333333
     334CoopCoepViolationReportingEnabled:
     335  type: bool
     336  humanReadableName: "COOP and COEP violations reporting"
     337  humanReadableDescription: "Cross-Origin-Opener-Policy and Cross-Origin-Embedder-Policy reporting"
     338  defaultValue:
     339    WebKitLegacy:
     340      default: false
     341    WebKit:
     342      default: false
     343    WebCore:
     344      default: false
     345
    334346CoreImageAcceleratedFilterRenderEnabled:
    335347  type: bool
  • trunk/Source/WebCore/ChangeLog

    r283726 r283732  
     12021-10-07  Chris Dumez  <cdumez@apple.com>
     2
     3        Add feature flag for COOP / COEP violation reporting and turn off by default
     4        https://bugs.webkit.org/show_bug.cgi?id=231371
     5
     6        Reviewed by Youenn Fablet.
     7
     8        Add feature flag for COOP / COEP violation reporting and turn off by default since our
     9        implementation doesn't match the latest specification.
     10
     11        * loader/CrossOriginEmbedderPolicy.cpp:
     12        (WebCore::sendCOEPPolicyInheritenceViolation):
     13        (WebCore::sendCOEPCORPViolation):
     14        * loader/CrossOriginOpenerPolicy.cpp:
     15        (WebCore::sendViolationReportWhenNavigatingToCOOPResponse):
     16        (WebCore::sendViolationReportWhenNavigatingAwayFromCOOPResponse):
     17
    1182021-10-07  Antti Koivisto  <antti@apple.com>
    219
  • trunk/Source/WebCore/loader/CrossOriginEmbedderPolicy.cpp

    r283069 r283732  
    114114void sendCOEPPolicyInheritenceViolation(Frame& frame, const WebCore::SecurityOriginData& embedderOrigin, const String& endpoint, COEPDisposition disposition, const String& type, const URL& blockedURL)
    115115{
     116    if (!frame.settings().coopCoepViolationReportingEnabled())
     117        return;
     118
    116119    ASSERT(!endpoint.isEmpty());
    117120    PingLoader::sendReportToEndpoint(frame, embedderOrigin, endpoint, "coep"_s, contextURLForReport(frame), frame.loader().userAgent(blockedURL), [&](auto& body) {
    … …  
    126129{
    127130    ASSERT(!endpoint.isEmpty());
     131    if (!frame.settings().coopCoepViolationReportingEnabled())
     132        return;
     133
    128134    PingLoader::sendReportToEndpoint(frame, embedderOrigin, endpoint, "coep"_s, contextURLForReport(frame), frame.loader().userAgent(blockedURL), [&](auto& body) {
    129135        body.setString("disposition"_s, disposition == COEPDisposition::Reporting ? "reporting"_s : "enforce"_s);
  • trunk/Source/WebCore/loader/CrossOriginOpenerPolicy.cpp

    r283482 r283732  
    210210void sendViolationReportWhenNavigatingToCOOPResponse(Frame& frame, CrossOriginOpenerPolicy coop, COOPDisposition disposition, const URL& coopURL, const URL& previousResponseURL, const SecurityOrigin& coopOrigin, const SecurityOrigin& previousResponseOrigin, const String& referrer, const String& userAgent)
    211211{
     212    if (!frame.settings().coopCoepViolationReportingEnabled())
     213        return;
     214
    212215    auto& endpoint = coop.reportingEndpointForDisposition(disposition);
    213216    if (endpoint.isEmpty())
    … …  
    226229void sendViolationReportWhenNavigatingAwayFromCOOPResponse(Frame& frame, CrossOriginOpenerPolicy coop, COOPDisposition disposition, const URL& coopURL, const URL& nextResponseURL, const SecurityOrigin& coopOrigin, const SecurityOrigin& nextResponseOrigin, bool isCOOPResponseNavigationSource, const String& userAgent)
    227230{
     231    if (!frame.settings().coopCoepViolationReportingEnabled())
     232        return;
     233
    228234    auto& endpoint = coop.reportingEndpointForDisposition(disposition);
    229235    if (endpoint.isEmpty())
Note: See TracChangeset for help on using the changeset viewer.