⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 285174 in webkit


Ignore:
Timestamp:
Nov 2, 2021, 12:31:47 PM (5 years ago)
Author:
Russell Epstein
Message:

Cherry-pick r283732. rdar://problem/84349027

Add feature flag for COOP / COEP violation reporting and turn off by default
​https://bugs.webkit.org/show_bug.cgi?id=231371

Reviewed by Youenn Fablet.

Add feature flag for COOP / COEP violation reporting and turn off by default since our
implementation doesn't match the latest specification.

Source/WebCore:

  • loader/CrossOriginEmbedderPolicy.cpp: (WebCore::sendCOEPPolicyInheritenceViolation): (WebCore::sendCOEPCORPViolation):
  • loader/CrossOriginOpenerPolicy.cpp: (WebCore::sendViolationReportWhenNavigatingToCOOPResponse): (WebCore::sendViolationReportWhenNavigatingAwayFromCOOPResponse):

Source/WTF:

  • Scripts/Preferences/WebPreferencesExperimental.yaml:

git-svn-id: ​https://svn.webkit.org/repository/webkit/trunk@283732 268f45cc-cd09-0410-ab3c-d52691b4dbfc

Location:
branches/safari-612-branch/Source
Files:
5 edited

Legend:

Unmodified
Added
Removed
  • branches/safari-612-branch/Source/WTF/ChangeLog

    r284950 r285174  
     12021-11-02  Russell Epstein  <repstein@apple.com>
     2
     3        Cherry-pick r283732. rdar://problem/84349027
     4
     5    Add feature flag for COOP / COEP violation reporting and turn off by default
     6    https://bugs.webkit.org/show_bug.cgi?id=231371
     7   
     8    Reviewed by Youenn Fablet.
     9   
     10    Add feature flag for COOP / COEP violation reporting and turn off by default since our
     11    implementation doesn't match the latest specification.
     12   
     13    Source/WebCore:
     14   
     15    * loader/CrossOriginEmbedderPolicy.cpp:
     16    (WebCore::sendCOEPPolicyInheritenceViolation):
     17    (WebCore::sendCOEPCORPViolation):
     18    * loader/CrossOriginOpenerPolicy.cpp:
     19    (WebCore::sendViolationReportWhenNavigatingToCOOPResponse):
     20    (WebCore::sendViolationReportWhenNavigatingAwayFromCOOPResponse):
     21   
     22    Source/WTF:
     23   
     24    * Scripts/Preferences/WebPreferencesExperimental.yaml:
     25   
     26   
     27    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@283732 268f45cc-cd09-0410-ab3c-d52691b4dbfc
     28
     29    2021-10-07  Chris Dumez  <cdumez@apple.com>
     30
     31            Add feature flag for COOP / COEP violation reporting and turn off by default
     32            https://bugs.webkit.org/show_bug.cgi?id=231371
     33
     34            Reviewed by Youenn Fablet.
     35
     36            Add feature flag for COOP / COEP violation reporting and turn off by default since our
     37            implementation doesn't match the latest specification.
     38
     39            * Scripts/Preferences/WebPreferencesExperimental.yaml:
     40
    1412021-10-26  Alan Coon  <alancoon@apple.com>
    242
  • branches/safari-612-branch/Source/WTF/Scripts/Preferences/WebPreferencesExperimental.yaml

    r284431 r285174  
    310310      default: false
    311311
     312CoopCoepViolationReportingEnabled:
     313  type: bool
     314  humanReadableName: "COOP and COEP violations reporting"
     315  humanReadableDescription: "Cross-Origin-Opener-Policy and Cross-Origin-Embedder-Policy reporting"
     316  defaultValue:
     317    WebKitLegacy:
     318      default: false
     319    WebKit:
     320      default: false
     321    WebCore:
     322      default: false
     323
    312324CoreImageAcceleratedFilterRenderEnabled:
    313325  type: bool
  • branches/safari-612-branch/Source/WebCore/ChangeLog

    r284989 r285174  
     12021-11-02  Russell Epstein  <repstein@apple.com>
     2
     3        Cherry-pick r283732. rdar://problem/84349027
     4
     5    Add feature flag for COOP / COEP violation reporting and turn off by default
     6    https://bugs.webkit.org/show_bug.cgi?id=231371
     7   
     8    Reviewed by Youenn Fablet.
     9   
     10    Add feature flag for COOP / COEP violation reporting and turn off by default since our
     11    implementation doesn't match the latest specification.
     12   
     13    Source/WebCore:
     14   
     15    * loader/CrossOriginEmbedderPolicy.cpp:
     16    (WebCore::sendCOEPPolicyInheritenceViolation):
     17    (WebCore::sendCOEPCORPViolation):
     18    * loader/CrossOriginOpenerPolicy.cpp:
     19    (WebCore::sendViolationReportWhenNavigatingToCOOPResponse):
     20    (WebCore::sendViolationReportWhenNavigatingAwayFromCOOPResponse):
     21   
     22    Source/WTF:
     23   
     24    * Scripts/Preferences/WebPreferencesExperimental.yaml:
     25   
     26   
     27    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@283732 268f45cc-cd09-0410-ab3c-d52691b4dbfc
     28
     29    2021-10-07  Chris Dumez  <cdumez@apple.com>
     30
     31            Add feature flag for COOP / COEP violation reporting and turn off by default
     32            https://bugs.webkit.org/show_bug.cgi?id=231371
     33
     34            Reviewed by Youenn Fablet.
     35
     36            Add feature flag for COOP / COEP violation reporting and turn off by default since our
     37            implementation doesn't match the latest specification.
     38
     39            * loader/CrossOriginEmbedderPolicy.cpp:
     40            (WebCore::sendCOEPPolicyInheritenceViolation):
     41            (WebCore::sendCOEPCORPViolation):
     42            * loader/CrossOriginOpenerPolicy.cpp:
     43            (WebCore::sendViolationReportWhenNavigatingToCOOPResponse):
     44            (WebCore::sendViolationReportWhenNavigatingAwayFromCOOPResponse):
     45
    1462021-10-28  Alan Coon  <alancoon@apple.com>
    247
  • branches/safari-612-branch/Source/WebCore/loader/CrossOriginEmbedderPolicy.cpp

    r283922 r285174  
    102102void sendCOEPPolicyInheritenceViolation(Frame& frame, const WebCore::SecurityOriginData& embedderOrigin, const String& endpoint, COEPDisposition disposition, const String& type, const URL& blockedURL)
    103103{
     104    if (!frame.settings().coopCoepViolationReportingEnabled())
     105        return;
     106
    104107    ASSERT(!endpoint.isEmpty());
    105108    PingLoader::sendReportToEndpoint(frame, embedderOrigin, endpoint, "coep"_s, contextURLForReport(frame), frame.loader().userAgent(blockedURL), [&](auto& body) {
    … …  
    114117{
    115118    ASSERT(!endpoint.isEmpty());
     119    if (!frame.settings().coopCoepViolationReportingEnabled())
     120        return;
     121
    116122    PingLoader::sendReportToEndpoint(frame, embedderOrigin, endpoint, "coep"_s, contextURLForReport(frame), frame.loader().userAgent(blockedURL), [&](auto& body) {
    117123        body.setString("disposition"_s, disposition == COEPDisposition::Reporting ? "reporting"_s : "enforce"_s);
  • branches/safari-612-branch/Source/WebCore/loader/CrossOriginOpenerPolicy.cpp

    r283929 r285174  
    206206void sendViolationReportWhenNavigatingToCOOPResponse(Frame& frame, CrossOriginOpenerPolicy coop, COOPDisposition disposition, const URL& coopURL, const URL& previousResponseURL, const SecurityOrigin& coopOrigin, const SecurityOrigin& previousResponseOrigin, const String& referrer, const String& userAgent)
    207207{
     208    if (!frame.settings().coopCoepViolationReportingEnabled())
     209        return;
     210
    208211    auto& endpoint = coop.reportingEndpointForDisposition(disposition);
    209212    if (endpoint.isEmpty())
    … …  
    222225void sendViolationReportWhenNavigatingAwayFromCOOPResponse(Frame& frame, CrossOriginOpenerPolicy coop, COOPDisposition disposition, const URL& coopURL, const URL& nextResponseURL, const SecurityOrigin& coopOrigin, const SecurityOrigin& nextResponseOrigin, bool isCOOPResponseNavigationSource, const String& userAgent)
    223226{
     227    if (!frame.settings().coopCoepViolationReportingEnabled())
     228        return;
     229
    224230    auto& endpoint = coop.reportingEndpointForDisposition(disposition);
    225231    if (endpoint.isEmpty())
Note: See TracChangeset for help on using the changeset viewer.