⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 286940 in webkit


Ignore:
Timestamp:
Dec 13, 2021, 1:18:27 AM (5 years ago)
Author:
youenn@apple.com
Message:

Implement step 17 of main fetch algorithm
​https://bugs.webkit.org/show_bug.cgi?id=234140

Reviewed by Brent Fulgham.

LayoutTests/imported/w3c:

  • web-platform-tests/service-workers/service-worker/fetch-csp.https.html:
  • web-platform-tests/service-workers/service-worker/resources/fetch-csp-iframe.html.sub.headers:

Source/WebCore:

The step was implemented for non DocumentThreadableLoader resources, we need to also do the same step within DocumentThreadableLoader.

Covered by existing updated tests.

  • loader/DocumentThreadableLoader.cpp:
  • loader/DocumentThreadableLoader.h:
Location:
trunk
Files:
6 edited

Legend:

Unmodified
Added
Removed
  • trunk/LayoutTests/imported/w3c/ChangeLog

    r286915 r286940  
     12021-12-13  Youenn Fablet  <youenn@apple.com>
     2
     3        Implement step 17 of main fetch algorithm
     4        https://bugs.webkit.org/show_bug.cgi?id=234140
     5
     6        Reviewed by Brent Fulgham.
     7
     8        * web-platform-tests/service-workers/service-worker/fetch-csp.https.html:
     9        * web-platform-tests/service-workers/service-worker/resources/fetch-csp-iframe.html.sub.headers:
     10
    1112021-12-11  Antoine Quint  <graouts@webkit.org>
    212
  • trunk/LayoutTests/imported/w3c/web-platform-tests/service-workers/service-worker/fetch-csp.https.html

    r279389 r286940  
    109109        })
    110110      .then(function() {
     111          return assert_resolves(
     112              frame.contentWindow.fetch(IMAGE_URL + "&fetch1", { mode: 'no-cors'}),
     113              'Allowed scope fetch resource should be loaded.');
     114        })
     115      .then(function() {
     116          return assert_resolves(
     117              frame.contentWindow.fetch(
     118                  // The request for IMAGE_URL will be fetched in SW.
     119                  './sample?url=' + encodeURIComponent(IMAGE_URL + '&fetch2'), { mode: 'no-cors'}),
     120              'Allowed scope fetch resource which was fetched via SW should be loaded.');
     121        })
     122      .then(function() {
     123          return assert_rejects(
     124              frame.contentWindow.fetch(REMOTE_IMAGE_URL + "&fetch3", { mode: 'no-cors'}),
     125              'Disallowed scope fetch resource should not be loaded.');
     126        })
     127      .then(function() {
     128          return assert_rejects(
     129              frame.contentWindow.fetch(
     130                  // The request for REMOTE_IMAGE_URL will be fetched in SW.
     131                  './sample?url=' + encodeURIComponent(REMOTE_IMAGE_URL + '&fetch4'), { mode: 'no-cors'}),
     132              'Disallowed scope fetch resource which was fetched via SW should not be loaded.');
     133        })
     134      .then(function() {
    111135          frame.remove();
    112136        });
  • trunk/LayoutTests/imported/w3c/web-platform-tests/service-workers/service-worker/resources/fetch-csp-iframe.html.sub.headers

    r220223 r286940  
    1 Content-Security-Policy: img-src https://{{host}}:{{ports[https][0]}}
     1Content-Security-Policy: img-src https://{{host}}:{{ports[https][0]}}; connect-src 'unsafe-inline' 'self'
  • trunk/Source/WebCore/ChangeLog

    r286939 r286940  
     12021-12-13  Youenn Fablet  <youenn@apple.com>
     2
     3        Implement step 17 of main fetch algorithm
     4        https://bugs.webkit.org/show_bug.cgi?id=234140
     5
     6        Reviewed by Brent Fulgham.
     7
     8        The step was implemented for non DocumentThreadableLoader resources, we need to also do the same step within DocumentThreadableLoader.
     9
     10        Covered by existing updated tests.
     11
     12        * loader/DocumentThreadableLoader.cpp:
     13        * loader/DocumentThreadableLoader.h:
     14
    1152021-12-13  Youenn Fablet  <youenn@apple.com>
    216
  • trunk/Source/WebCore/loader/DocumentThreadableLoader.cpp

    r286937 r286940  
    405405    ASSERT(response.type() != ResourceResponse::Type::Error);
    406406
     407#if ENABLE(SERVICE_WORKER)
     408    // https://fetch.spec.whatwg.org/commit-snapshots/6257e220d70f560a037e46f1b4206325400db8dc/#main-fetch step 17.
     409    if (response.source() == ResourceResponse::Source::ServiceWorker && response.url() != m_resource->url()) {
     410        if (!isResponseAllowedByContentSecurityPolicy(response)) {
     411            reportContentSecurityPolicyError(response.url());
     412            return;
     413        }
     414    }
     415#endif
     416
    407417    InspectorInstrumentation::didReceiveThreadableLoaderResponse(*this, identifier);
    408418
    … …  
    692702}
    693703
     704bool DocumentThreadableLoader::isResponseAllowedByContentSecurityPolicy(const ResourceResponse& response)
     705{
     706    return isAllowedByContentSecurityPolicy(response.url(), ContentSecurityPolicy::RedirectResponseReceived::Yes, { });
     707}
     708
    694709bool DocumentThreadableLoader::isAllowedRedirect(const URL& url)
    695710{
  • trunk/Source/WebCore/loader/DocumentThreadableLoader.h

    r282712 r286940  
    106106        bool isAllowedRedirect(const URL&);
    107107        bool isAllowedByContentSecurityPolicy(const URL&, ContentSecurityPolicy::RedirectResponseReceived, const URL& preRedirectURL = URL());
     108        bool isResponseAllowedByContentSecurityPolicy(const ResourceResponse&);
    108109
    109110        SecurityOrigin& securityOrigin() const;
Note: See TracChangeset for help on using the changeset viewer.