Changeset 286094 in webkit
- Timestamp:
- Nov 20, 2021, 12:15:52 AM (5 years ago)
- Location:
- trunk
- Files:
-
- 26 edited
-
LayoutTests/ChangeLog (modified) (1 diff)
-
LayoutTests/TestExpectations (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/1.1/child-src/worker-redirect-blocked-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/audio-redirect-blocked-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/font-redirect-blocked-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/image-redirect-blocked-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/script-redirect-blocked-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/stylesheet-redirect-blocked-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/svg-font-redirect-blocked-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/svg-image-redirect-blocked-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/track-redirect-blocked-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/video-redirect-blocked-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/worker-blob-inherits-csp-importScripts-redirect-cross-origin-blocked-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/worker-csp-importScripts-redirect-cross-origin-blocked-expected.txt (modified) (1 diff)
-
LayoutTests/http/tests/security/contentSecurityPolicy/xsl-redirect-blocked-expected.txt (modified) (1 diff)
-
LayoutTests/imported/w3c/ChangeLog (modified) (1 diff)
-
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/img-src-redirect.sub-expected.txt (modified) (1 diff)
-
Source/WebCore/ChangeLog (modified) (1 diff)
-
Source/WebCore/loader/DocumentThreadableLoader.cpp (modified) (1 diff)
-
Source/WebCore/loader/SubresourceLoader.cpp (modified) (1 diff)
-
Source/WebCore/loader/cache/CachedResourceLoader.cpp (modified) (9 diffs)
-
Source/WebCore/loader/cache/CachedResourceLoader.h (modified) (2 diffs)
-
Source/WebCore/page/csp/ContentSecurityPolicy.cpp (modified) (1 diff)
-
Source/WebCore/page/csp/ContentSecurityPolicy.h (modified) (1 diff)
-
Source/WebKit/ChangeLog (modified) (1 diff)
-
Source/WebKit/NetworkProcess/NetworkLoadChecker.cpp (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
trunk/LayoutTests/ChangeLog
r286089 r286094 1 2021-11-20 Carlos Garcia Campos <cgarcia@igalia.com> 2 3 Report the initiating url instead of the redirected one 4 https://bugs.webkit.org/show_bug.cgi?id=233037 5 6 Reviewed by Brent Fulgham. 7 8 * TestExpectations: Unskip imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/img-src-redirect.sub.html 9 * http/tests/security/contentSecurityPolicy/1.1/child-src/worker-redirect-blocked-expected.txt: 10 * http/tests/security/contentSecurityPolicy/audio-redirect-blocked-expected.txt: 11 * http/tests/security/contentSecurityPolicy/font-redirect-blocked-expected.txt: 12 * http/tests/security/contentSecurityPolicy/image-redirect-blocked-expected.txt: 13 * http/tests/security/contentSecurityPolicy/script-redirect-blocked-expected.txt: 14 * http/tests/security/contentSecurityPolicy/stylesheet-redirect-blocked-expected.txt: 15 * http/tests/security/contentSecurityPolicy/svg-font-redirect-blocked-expected.txt: 16 * http/tests/security/contentSecurityPolicy/svg-image-redirect-blocked-expected.txt: 17 * http/tests/security/contentSecurityPolicy/track-redirect-blocked-expected.txt: 18 * http/tests/security/contentSecurityPolicy/video-redirect-blocked-expected.txt: 19 * http/tests/security/contentSecurityPolicy/worker-blob-inherits-csp-importScripts-redirect-cross-origin-blocked-expected.txt: 20 * http/tests/security/contentSecurityPolicy/worker-csp-importScripts-redirect-cross-origin-blocked-expected.txt: 21 * http/tests/security/contentSecurityPolicy/xsl-redirect-blocked-expected.txt: 22 1 23 2021-11-19 Arcady Goldmints-Orlov <agoldmints@igalia.com> 2 24 -
trunk/LayoutTests/TestExpectations
r286085 r286094 526 526 imported/w3c/web-platform-tests/content-security-policy/prefetch-src/prefetch-header-blocked-by-default.html [ Skip ] 527 527 imported/w3c/web-platform-tests/content-security-policy/reporting-api/report-to-directive-allowed-in-meta.https.sub.html [ Skip ] 528 imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/img-src-redirect.sub.html [ Skip ]529 528 imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/source-file-blob-scheme.html [ Skip ] 530 529 imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/source-file-data-scheme.html [ Skip ] -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/1.1/child-src/worker-redirect-blocked-expected.txt
r274244 r286094 1 CONSOLE MESSAGE: Refused to load http:// localhost:8000/security/contentSecurityPolicy/resources/alert-fail.js because it does not appear in the child-src directive of the Content Security Policy.1 CONSOLE MESSAGE: Refused to load http://127.0.0.1:8000/security/contentSecurityPolicy/resources/redir.py?url=http://localhost:8000/security/contentSecurityPolicy/resources/alert-fail.js because it does not appear in the child-src directive of the Content Security Policy. 2 2 CONSOLE MESSAGE: Blocked by Content Security Policy. 3 3 CONSOLE MESSAGE: Cannot load http://localhost:8000/security/contentSecurityPolicy/resources/alert-fail.js due to access control checks. -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/audio-redirect-blocked-expected.txt
r198643 r286094 1 CONSOLE MESSAGE: Refused to load http:// localhost:8000/resources/balls-of-the-orient.aif because it does not appear in the media-src directive of the Content Security Policy.1 CONSOLE MESSAGE: Refused to load http://127.0.0.1:8000/resources/redirect.py?code=307&url=http%3A%2F%2Flocalhost%3A8000/resources/balls-of-the-orient.aif because it does not appear in the media-src directive of the Content Security Policy. 2 2 ALERT: PASS 3 3 -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/font-redirect-blocked-expected.txt
r198591 r286094 1 CONSOLE MESSAGE: Refused to load http:// localhost:8000/resources/Ahem.woff because it does not appear in the font-src directive of the Content Security Policy.1 CONSOLE MESSAGE: Refused to load http://127.0.0.1:8000/resources/redirect.py?code=307&url=http%3A%2F%2Flocalhost%3A8000/resources/Ahem.woff because it does not appear in the font-src directive of the Content Security Policy. 2 2 Tests that a cross-origin CSS font loaded via a redirect is blocked by the Content Security Policy. This test PASSED if there is a console warning message. 3 3 -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/image-redirect-blocked-expected.txt
r198591 r286094 1 CONSOLE MESSAGE: Refused to load http:// localhost:8000/security/resources/abe.png because it does not appear in the img-src directive of the Content Security Policy.1 CONSOLE MESSAGE: Refused to load http://127.0.0.1:8000/resources/redirect.py?code=307&url=http%3A%2F%2Flocalhost%3A8000/security/resources/abe.png because it does not appear in the img-src directive of the Content Security Policy. 2 2 Tests that a cross-origin image loaded via a redirect is blocked by the Content Security Policy. This test PASSED if there is a console warning message. 3 3 -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/script-redirect-blocked-expected.txt
r198591 r286094 1 CONSOLE MESSAGE: Refused to load http:// localhost:8000/security/contentSecurityPolicy/resources/alert-fail.js because it does not appear in the script-src directive of the Content Security Policy.1 CONSOLE MESSAGE: Refused to load http://127.0.0.1:8000/resources/redirect.py?code=307&url=http%3A%2F%2Flocalhost%3A8000/security/contentSecurityPolicy/resources/alert-fail.js because it does not appear in the script-src directive of the Content Security Policy. 2 2 ALERT: PASS 3 3 -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/stylesheet-redirect-blocked-expected.txt
r198591 r286094 1 CONSOLE MESSAGE: Refused to load http:// localhost:8000/security/contentSecurityPolicy/resources/blue.css because it does not appear in the style-src directive of the Content Security Policy.1 CONSOLE MESSAGE: Refused to load http://127.0.0.1:8000/resources/redirect.py?code=307&url=http%3A%2F%2Flocalhost%3A8000/security/contentSecurityPolicy/resources/blue.css because it does not appear in the style-src directive of the Content Security Policy. 2 2 ALERT: PASS 3 3 -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/svg-font-redirect-blocked-expected.txt
r198591 r286094 1 CONSOLE MESSAGE: Refused to load http:// localhost:8000/security/contentSecurityPolicy/resources/ABCFont.svg because it does not appear in the font-src directive of the Content Security Policy.1 CONSOLE MESSAGE: Refused to load http://127.0.0.1:8000/resources/redirect.py?code=307&url=http%3A%2F%2Flocalhost%3A8000/security/contentSecurityPolicy/resources/ABCFont.svg because it does not appear in the font-src directive of the Content Security Policy. 2 2 Tests that a SVG font-face element is blocked from loading a cross-origin external SVG font via a redirect by the Content Security Policy. This test PASSED if there is a console warning message. 3 3 -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/svg-image-redirect-blocked-expected.txt
r198591 r286094 1 CONSOLE MESSAGE: Refused to load http:// localhost:8000/security/contentSecurityPolicy/resources/red-square.svg because it does not appear in the img-src directive of the Content Security Policy.1 CONSOLE MESSAGE: Refused to load http://127.0.0.1:8000/resources/redirect.py?code=307&url=http%3A%2F%2Flocalhost%3A8000/security/contentSecurityPolicy/resources/red-square.svg because it does not appear in the img-src directive of the Content Security Policy. 2 2 Tests that a cross-origin SVG image loaded via a redirect is blocked by the Content Security Policy. This test PASSED if there is a console warning message. 3 3 -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/track-redirect-blocked-expected.txt
r198591 r286094 1 CONSOLE MESSAGE: Refused to load http:// localhost:8000/security/contentSecurityPolicy/resources/track.vtt because it does not appear in the media-src directive of the Content Security Policy.1 CONSOLE MESSAGE: Refused to load http://127.0.0.1:8000/resources/redirect.py?code=307&url=http%3A%2F%2Flocalhost%3A8000/security/contentSecurityPolicy/resources/track.vtt because it does not appear in the media-src directive of the Content Security Policy. 2 2 ALERT: PASS 3 3 -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/video-redirect-blocked-expected.txt
r198643 r286094 1 CONSOLE MESSAGE: Refused to load http:// localhost:8000/resources/test.mp4 because it does not appear in the media-src directive of the Content Security Policy.1 CONSOLE MESSAGE: Refused to load http://127.0.0.1:8000/resources/redirect.py?code=307&url=http%3A%2F%2Flocalhost%3A8000/resources/test.mp4 because it does not appear in the media-src directive of the Content Security Policy. 2 2 ALERT: PASS 3 3 -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/worker-blob-inherits-csp-importScripts-redirect-cross-origin-blocked-expected.txt
r281012 r286094 1 CONSOLE MESSAGE: Refused to load http:// localhost:8000/security/contentSecurityPolicy/resources/script-set-value.js because it does not appear in the script-src directive of the Content Security Policy.1 CONSOLE MESSAGE: Refused to load http://127.0.0.1:8000/security/contentSecurityPolicy/resources/redir.py?url=http://localhost:8000/security/contentSecurityPolicy/resources/script-set-value.js because it does not appear in the script-src directive of the Content Security Policy. 2 2 CONSOLE MESSAGE: Blocked by Content Security Policy. 3 3 This tests that the Content Security Policy of the parent origin (this page) blocks a Web Worker from importing a script from a different origin, not listed in script-src, through a redirect. -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/worker-csp-importScripts-redirect-cross-origin-blocked-expected.txt
r281012 r286094 1 CONSOLE MESSAGE: Refused to load http:// localhost:8000/security/contentSecurityPolicy/resources/script-set-value.js because it does not appear in the script-src directive of the Content Security Policy.1 CONSOLE MESSAGE: Refused to load http://127.0.0.1:8000/security/contentSecurityPolicy/resources/redir.py?url=http://localhost:8000/security/contentSecurityPolicy/resources/script-set-value.js because it does not appear in the script-src directive of the Content Security Policy. 2 2 CONSOLE MESSAGE: Blocked by Content Security Policy. 3 3 This tests a Web Worker with Content Security Policy "script-src 'self'" blocks the import of a script from a different origin through a redirect. -
trunk/LayoutTests/http/tests/security/contentSecurityPolicy/xsl-redirect-blocked-expected.txt
r198591 r286094 1 CONSOLE MESSAGE: Refused to load http:// localhost:8000/security/contentSecurityPolicy/resources/alert-fail.xsl because it does not appear in the script-src directive of the Content Security Policy.1 CONSOLE MESSAGE: Refused to load http://127.0.0.1:8000/resources/redirect.py?code=307&url=http%3A%2F%2Flocalhost%3A8000/security/contentSecurityPolicy/resources/alert-fail.xsl because it does not appear in the script-src directive of the Content Security Policy. 2 2 -
trunk/LayoutTests/imported/w3c/ChangeLog
r286089 r286094 1 2021-11-20 Carlos Garcia Campos <cgarcia@igalia.com> 2 3 Report the initiating url instead of the redirected one 4 https://bugs.webkit.org/show_bug.cgi?id=233037 5 6 Reviewed by Brent Fulgham. 7 8 * web-platform-tests/content-security-policy/securitypolicyviolation/img-src-redirect.sub-expected.txt: 9 1 10 2021-11-19 Arcady Goldmints-Orlov <agoldmints@igalia.com> 2 11 -
trunk/LayoutTests/imported/w3c/web-platform-tests/content-security-policy/securitypolicyviolation/img-src-redirect.sub-expected.txt
r283111 r286094 1 2 1 3 FAIL The blocked URI in the security policy violation event should be the original URI before redirects. assert_equals: expected "http://localhost:8800/common/redirect.py?location=http%3A%2F%2F127.0.0.1%3A8800%2Fcontent-security-policy%2Fsupport%2Ffail.png" but got "http://127.0.0.1:8800"4 2 3 PASS The blocked URI in the security policy violation event should be the original URI before redirects. 4 -
trunk/Source/WebCore/ChangeLog
r286093 r286094 1 2021-11-20 Carlos Garcia Campos <cgarcia@igalia.com> 2 3 Report the initiating url instead of the redirected one 4 https://bugs.webkit.org/show_bug.cgi?id=233037 5 6 Reviewed by Brent Fulgham. 7 8 As per the spec, blockedURI should use the requested URL of original request instead of redirected location. 9 10 * loader/DocumentThreadableLoader.cpp: 11 (WebCore::DocumentThreadableLoader::isAllowedByContentSecurityPolicy): 12 * loader/SubresourceLoader.cpp: 13 (WebCore::SubresourceLoader::willSendRequestInternal): 14 * loader/cache/CachedResourceLoader.cpp: 15 (WebCore::CachedResourceLoader::allowedByContentSecurityPolicy const): 16 (WebCore::CachedResourceLoader::canRequestAfterRedirection const): 17 (WebCore::CachedResourceLoader::updateRequestAfterRedirection): 18 * loader/cache/CachedResourceLoader.h: 19 * page/csp/ContentSecurityPolicy.cpp: 20 (WebCore::ContentSecurityPolicy::allowChildContextFromSource const): 21 (WebCore::ContentSecurityPolicy::allowScriptFromSource const): 22 (WebCore::ContentSecurityPolicy::allowImageFromSource const): 23 (WebCore::ContentSecurityPolicy::allowStyleFromSource const): 24 (WebCore::ContentSecurityPolicy::allowFontFromSource const): 25 (WebCore::ContentSecurityPolicy::allowManifestFromSource const): 26 (WebCore::ContentSecurityPolicy::allowMediaFromSource const): 27 * page/csp/ContentSecurityPolicy.h: 28 1 29 2021-11-19 Carlos Garcia Campos <cgarcia@igalia.com> 2 30 -
trunk/Source/WebCore/loader/DocumentThreadableLoader.cpp
r284009 r286094 682 682 return true; 683 683 case ContentSecurityPolicyEnforcement::EnforceChildSrcDirective: 684 return contentSecurityPolicy().allowChildContextFromSource(url, redirectResponseReceived );684 return contentSecurityPolicy().allowChildContextFromSource(url, redirectResponseReceived, preRedirectURL); 685 685 case ContentSecurityPolicyEnforcement::EnforceConnectSrcDirective: 686 686 return contentSecurityPolicy().allowConnectToSource(url, redirectResponseReceived, preRedirectURL); 687 687 case ContentSecurityPolicyEnforcement::EnforceScriptSrcDirective: 688 return contentSecurityPolicy().allowScriptFromSource(url, redirectResponseReceived );688 return contentSecurityPolicy().allowScriptFromSource(url, redirectResponseReceived, preRedirectURL); 689 689 } 690 690 ASSERT_NOT_REACHED(); -
trunk/Source/WebCore/loader/SubresourceLoader.cpp
r282853 r286094 278 278 } 279 279 280 if (!m_documentLoader->cachedResourceLoader().updateRequestAfterRedirection(m_resource->type(), newRequest, options() )) {280 if (!m_documentLoader->cachedResourceLoader().updateRequestAfterRedirection(m_resource->type(), newRequest, options(), redirectResponse.url())) { 281 281 SUBRESOURCELOADER_RELEASE_LOG("willSendRequestInternal: resource load canceled because CachedResourceLoader::updateRequestAfterRedirection (really CachedResourceLoader::canRequestAfterRedirection) said no"); 282 282 cancel(); -
trunk/Source/WebCore/loader/cache/CachedResourceLoader.cpp
r285823 r286094 489 489 } 490 490 491 bool CachedResourceLoader::allowedByContentSecurityPolicy(CachedResource::Type type, const URL& url, const ResourceLoaderOptions& options, ContentSecurityPolicy::RedirectResponseReceived redirectResponseReceived ) const491 bool CachedResourceLoader::allowedByContentSecurityPolicy(CachedResource::Type type, const URL& url, const ResourceLoaderOptions& options, ContentSecurityPolicy::RedirectResponseReceived redirectResponseReceived, const URL& preRedirectURL) const 492 492 { 493 493 if (options.contentSecurityPolicyImposition == ContentSecurityPolicyImposition::SkipPolicyCheck) … … 502 502 #endif 503 503 case CachedResource::Type::Script: 504 if (!m_document->contentSecurityPolicy()->allowScriptFromSource(url, redirectResponseReceived ))504 if (!m_document->contentSecurityPolicy()->allowScriptFromSource(url, redirectResponseReceived, preRedirectURL)) 505 505 return false; 506 506 break; 507 507 case CachedResource::Type::CSSStyleSheet: 508 if (!m_document->contentSecurityPolicy()->allowStyleFromSource(url, redirectResponseReceived ))508 if (!m_document->contentSecurityPolicy()->allowStyleFromSource(url, redirectResponseReceived, preRedirectURL)) 509 509 return false; 510 510 break; … … 512 512 case CachedResource::Type::Icon: 513 513 case CachedResource::Type::ImageResource: 514 if (!m_document->contentSecurityPolicy()->allowImageFromSource(url, redirectResponseReceived ))514 if (!m_document->contentSecurityPolicy()->allowImageFromSource(url, redirectResponseReceived, preRedirectURL)) 515 515 return false; 516 516 break; 517 517 case CachedResource::Type::SVGFontResource: 518 518 case CachedResource::Type::FontResource: 519 if (!m_document->contentSecurityPolicy()->allowFontFromSource(url, redirectResponseReceived ))519 if (!m_document->contentSecurityPolicy()->allowFontFromSource(url, redirectResponseReceived, preRedirectURL)) 520 520 return false; 521 521 break; … … 524 524 case CachedResource::Type::TextTrackResource: 525 525 #endif 526 if (!m_document->contentSecurityPolicy()->allowMediaFromSource(url, redirectResponseReceived ))526 if (!m_document->contentSecurityPolicy()->allowMediaFromSource(url, redirectResponseReceived, preRedirectURL)) 527 527 return false; 528 528 break; … … 536 536 #if ENABLE(APPLICATION_MANIFEST) 537 537 case CachedResource::Type::ApplicationManifest: 538 if (!m_document->contentSecurityPolicy()->allowManifestFromSource(url, redirectResponseReceived ))538 if (!m_document->contentSecurityPolicy()->allowManifestFromSource(url, redirectResponseReceived, preRedirectURL)) 539 539 return false; 540 540 break; … … 594 594 595 595 // FIXME: Should we find a way to know whether the redirection is for a preload request like we do for CachedResourceLoader::canRequest? 596 bool CachedResourceLoader::canRequestAfterRedirection(CachedResource::Type type, const URL& url, const ResourceLoaderOptions& options ) const596 bool CachedResourceLoader::canRequestAfterRedirection(CachedResource::Type type, const URL& url, const ResourceLoaderOptions& options, const URL& preRedirectURL) const 597 597 { 598 598 if (document() && !document()->securityOrigin().canDisplay(url)) { … … 612 612 } 613 613 614 if (!allowedByContentSecurityPolicy(type, url, options, ContentSecurityPolicy::RedirectResponseReceived::Yes )) {614 if (!allowedByContentSecurityPolicy(type, url, options, ContentSecurityPolicy::RedirectResponseReceived::Yes, preRedirectURL)) { 615 615 CACHEDRESOURCELOADER_RELEASE_LOG("canRequestAfterRedirection: URL was not allowed by content policy"); 616 616 return false; … … 627 627 } 628 628 629 bool CachedResourceLoader::updateRequestAfterRedirection(CachedResource::Type type, ResourceRequest& request, const ResourceLoaderOptions& options )629 bool CachedResourceLoader::updateRequestAfterRedirection(CachedResource::Type type, ResourceRequest& request, const ResourceLoaderOptions& options, const URL& preRedirectURL) 630 630 { 631 631 ASSERT(m_documentLoader); … … 635 635 // FIXME: We might want to align the checks done here with the ones done in CachedResourceLoader::requestResource, content extensions blocking in particular. 636 636 637 return canRequestAfterRedirection(type, request.url(), options );637 return canRequestAfterRedirection(type, request.url(), options, preRedirectURL); 638 638 } 639 639 -
trunk/Source/WebCore/loader/cache/CachedResourceLoader.h
r284093 r286094 157 157 void stopUnusedPreloadsTimer(); 158 158 159 bool updateRequestAfterRedirection(CachedResource::Type, ResourceRequest&, const ResourceLoaderOptions& );160 bool allowedByContentSecurityPolicy(CachedResource::Type, const URL&, const ResourceLoaderOptions&, ContentSecurityPolicy::RedirectResponseReceived ) const;159 bool updateRequestAfterRedirection(CachedResource::Type, ResourceRequest&, const ResourceLoaderOptions&, const URL& preRedirectURL); 160 bool allowedByContentSecurityPolicy(CachedResource::Type, const URL&, const ResourceLoaderOptions&, ContentSecurityPolicy::RedirectResponseReceived, const URL& preRedirectURL = URL()) const; 161 161 162 162 static const ResourceLoaderOptions& defaultCachedResourceOptions(); … … 198 198 void reloadImagesIfNotDeferred(); 199 199 200 bool canRequestAfterRedirection(CachedResource::Type, const URL&, const ResourceLoaderOptions& ) const;200 bool canRequestAfterRedirection(CachedResource::Type, const URL&, const ResourceLoaderOptions&, const URL& preRedirectURL) const; 201 201 bool canRequestInContentDispositionAttachmentSandbox(CachedResource::Type, const URL&) const; 202 202 -
trunk/Source/WebCore/page/csp/ContentSecurityPolicy.cpp
r285800 r286094 636 636 } 637 637 638 bool ContentSecurityPolicy::allowChildContextFromSource(const URL& url, RedirectResponseReceived redirectResponseReceived ) const639 { 640 return allowResourceFromSource(url, redirectResponseReceived, ContentSecurityPolicyDirectiveNames::childSrc, &ContentSecurityPolicyDirectiveList::violatedDirectiveForChildContext );641 } 642 643 bool ContentSecurityPolicy::allowScriptFromSource(const URL& url, RedirectResponseReceived redirectResponseReceived ) const638 bool ContentSecurityPolicy::allowChildContextFromSource(const URL& url, RedirectResponseReceived redirectResponseReceived, const URL& preRedirectURL) const 639 { 640 return allowResourceFromSource(url, redirectResponseReceived, ContentSecurityPolicyDirectiveNames::childSrc, &ContentSecurityPolicyDirectiveList::violatedDirectiveForChildContext, preRedirectURL); 641 } 642 643 bool ContentSecurityPolicy::allowScriptFromSource(const URL& url, RedirectResponseReceived redirectResponseReceived, const URL& preRedirectURL) const 644 644 { 645 645 if (shouldPerformEarlyCSPCheck()) 646 646 return true; 647 647 648 return allowResourceFromSource(url, redirectResponseReceived, ContentSecurityPolicyDirectiveNames::scriptSrc, &ContentSecurityPolicyDirectiveList::violatedDirectiveForScript );649 } 650 651 bool ContentSecurityPolicy::allowImageFromSource(const URL& url, RedirectResponseReceived redirectResponseReceived ) const652 { 653 return allowResourceFromSource(url, redirectResponseReceived, ContentSecurityPolicyDirectiveNames::imgSrc, &ContentSecurityPolicyDirectiveList::violatedDirectiveForImage );654 } 655 656 bool ContentSecurityPolicy::allowStyleFromSource(const URL& url, RedirectResponseReceived redirectResponseReceived ) const657 { 658 return allowResourceFromSource(url, redirectResponseReceived, ContentSecurityPolicyDirectiveNames::styleSrc, &ContentSecurityPolicyDirectiveList::violatedDirectiveForStyle );659 } 660 661 bool ContentSecurityPolicy::allowFontFromSource(const URL& url, RedirectResponseReceived redirectResponseReceived ) const662 { 663 return allowResourceFromSource(url, redirectResponseReceived, ContentSecurityPolicyDirectiveNames::fontSrc, &ContentSecurityPolicyDirectiveList::violatedDirectiveForFont );648 return allowResourceFromSource(url, redirectResponseReceived, ContentSecurityPolicyDirectiveNames::scriptSrc, &ContentSecurityPolicyDirectiveList::violatedDirectiveForScript, preRedirectURL); 649 } 650 651 bool ContentSecurityPolicy::allowImageFromSource(const URL& url, RedirectResponseReceived redirectResponseReceived, const URL& preRedirectURL) const 652 { 653 return allowResourceFromSource(url, redirectResponseReceived, ContentSecurityPolicyDirectiveNames::imgSrc, &ContentSecurityPolicyDirectiveList::violatedDirectiveForImage, preRedirectURL); 654 } 655 656 bool ContentSecurityPolicy::allowStyleFromSource(const URL& url, RedirectResponseReceived redirectResponseReceived, const URL& preRedirectURL) const 657 { 658 return allowResourceFromSource(url, redirectResponseReceived, ContentSecurityPolicyDirectiveNames::styleSrc, &ContentSecurityPolicyDirectiveList::violatedDirectiveForStyle, preRedirectURL); 659 } 660 661 bool ContentSecurityPolicy::allowFontFromSource(const URL& url, RedirectResponseReceived redirectResponseReceived, const URL& preRedirectURL) const 662 { 663 return allowResourceFromSource(url, redirectResponseReceived, ContentSecurityPolicyDirectiveNames::fontSrc, &ContentSecurityPolicyDirectiveList::violatedDirectiveForFont, preRedirectURL); 664 664 } 665 665 666 666 #if ENABLE(APPLICATION_MANIFEST) 667 bool ContentSecurityPolicy::allowManifestFromSource(const URL& url, RedirectResponseReceived redirectResponseReceived ) const668 { 669 return allowResourceFromSource(url, redirectResponseReceived, ContentSecurityPolicyDirectiveNames::manifestSrc, &ContentSecurityPolicyDirectiveList::violatedDirectiveForManifest );667 bool ContentSecurityPolicy::allowManifestFromSource(const URL& url, RedirectResponseReceived redirectResponseReceived, const URL& preRedirectURL) const 668 { 669 return allowResourceFromSource(url, redirectResponseReceived, ContentSecurityPolicyDirectiveNames::manifestSrc, &ContentSecurityPolicyDirectiveList::violatedDirectiveForManifest, preRedirectURL); 670 670 } 671 671 #endif // ENABLE(APPLICATION_MANIFEST) 672 672 673 bool ContentSecurityPolicy::allowMediaFromSource(const URL& url, RedirectResponseReceived redirectResponseReceived ) const674 { 675 return allowResourceFromSource(url, redirectResponseReceived, ContentSecurityPolicyDirectiveNames::mediaSrc, &ContentSecurityPolicyDirectiveList::violatedDirectiveForMedia );673 bool ContentSecurityPolicy::allowMediaFromSource(const URL& url, RedirectResponseReceived redirectResponseReceived, const URL& preRedirectURL) const 674 { 675 return allowResourceFromSource(url, redirectResponseReceived, ContentSecurityPolicyDirectiveNames::mediaSrc, &ContentSecurityPolicyDirectiveList::violatedDirectiveForMedia, preRedirectURL); 676 676 } 677 677 -
trunk/Source/WebCore/page/csp/ContentSecurityPolicy.h
r285478 r286094 110 110 111 111 enum class RedirectResponseReceived { No, Yes }; 112 WEBCORE_EXPORT bool allowScriptFromSource(const URL&, RedirectResponseReceived = RedirectResponseReceived::No ) const;113 bool allowImageFromSource(const URL&, RedirectResponseReceived = RedirectResponseReceived::No ) const;114 bool allowStyleFromSource(const URL&, RedirectResponseReceived = RedirectResponseReceived::No ) const;115 bool allowFontFromSource(const URL&, RedirectResponseReceived = RedirectResponseReceived::No ) const;112 WEBCORE_EXPORT bool allowScriptFromSource(const URL&, RedirectResponseReceived = RedirectResponseReceived::No, const URL& preRedirectURL = URL()) const; 113 bool allowImageFromSource(const URL&, RedirectResponseReceived = RedirectResponseReceived::No, const URL& preRedirectURL = URL()) const; 114 bool allowStyleFromSource(const URL&, RedirectResponseReceived = RedirectResponseReceived::No, const URL& preRedirectURL = URL()) const; 115 bool allowFontFromSource(const URL&, RedirectResponseReceived = RedirectResponseReceived::No, const URL& preRedirectURL = URL()) const; 116 116 #if ENABLE(APPLICATION_MANIFEST) 117 bool allowManifestFromSource(const URL&, RedirectResponseReceived = RedirectResponseReceived::No ) const;117 bool allowManifestFromSource(const URL&, RedirectResponseReceived = RedirectResponseReceived::No, const URL& preRedirectURL = URL()) const; 118 118 #endif 119 bool allowMediaFromSource(const URL&, RedirectResponseReceived = RedirectResponseReceived::No ) const;119 bool allowMediaFromSource(const URL&, RedirectResponseReceived = RedirectResponseReceived::No, const URL& preRedirectURL = URL()) const; 120 120 121 121 bool allowChildFrameFromSource(const URL&, RedirectResponseReceived = RedirectResponseReceived::No) const; 122 WEBCORE_EXPORT bool allowChildContextFromSource(const URL&, RedirectResponseReceived = RedirectResponseReceived::No ) const;122 WEBCORE_EXPORT bool allowChildContextFromSource(const URL&, RedirectResponseReceived = RedirectResponseReceived::No, const URL& requestedURL = URL()) const; 123 123 WEBCORE_EXPORT bool allowConnectToSource(const URL&, RedirectResponseReceived = RedirectResponseReceived::No, const URL& requestedURL = URL()) const; 124 124 bool allowFormAction(const URL&, RedirectResponseReceived = RedirectResponseReceived::No, const URL& preRedirectURL = URL()) const; -
trunk/Source/WebKit/ChangeLog
r286087 r286094 1 2021-11-20 Carlos Garcia Campos <cgarcia@igalia.com> 2 3 Report the initiating url instead of the redirected one 4 https://bugs.webkit.org/show_bug.cgi?id=233037 5 6 Reviewed by Brent Fulgham. 7 8 Pass pre-redirect URL to allowChildContextFromSource() and allowScriptFromSource(). 9 10 * NetworkProcess/NetworkLoadChecker.cpp: 11 (WebKit::NetworkLoadChecker::isAllowedByContentSecurityPolicy): 12 1 13 2021-11-19 Myles C. Maxfield <mmaxfield@apple.com> 2 14 -
trunk/Source/WebKit/NetworkProcess/NetworkLoadChecker.cpp
r284142 r286094 291 291 case FetchOptions::Destination::Serviceworker: 292 292 case FetchOptions::Destination::Sharedworker: 293 return contentSecurityPolicy->allowChildContextFromSource(request.url(), redirectResponseReceived );293 return contentSecurityPolicy->allowChildContextFromSource(request.url(), redirectResponseReceived, preRedirectURL); 294 294 case FetchOptions::Destination::Script: 295 if (request.requester() == ResourceRequest::Requester::ImportScripts && !contentSecurityPolicy->allowScriptFromSource(request.url(), redirectResponseReceived ))295 if (request.requester() == ResourceRequest::Requester::ImportScripts && !contentSecurityPolicy->allowScriptFromSource(request.url(), redirectResponseReceived, preRedirectURL)) 296 296 return false; 297 297 // FIXME: Check CSP for non-importScripts() initiated loads.
Note:
See TracChangeset
for help on using the changeset viewer.