Changeset 286940 in webkit
- Timestamp:
- Dec 13, 2021, 1:18:27 AM (5 years ago)
- Location:
- trunk
- Files:
-
- 6 edited
-
LayoutTests/imported/w3c/ChangeLog (modified) (1 diff)
-
LayoutTests/imported/w3c/web-platform-tests/service-workers/service-worker/fetch-csp.https.html (modified) (1 diff)
-
LayoutTests/imported/w3c/web-platform-tests/service-workers/service-worker/resources/fetch-csp-iframe.html.sub.headers (modified) (1 diff)
-
Source/WebCore/ChangeLog (modified) (1 diff)
-
Source/WebCore/loader/DocumentThreadableLoader.cpp (modified) (2 diffs)
-
Source/WebCore/loader/DocumentThreadableLoader.h (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
trunk/LayoutTests/imported/w3c/ChangeLog
r286915 r286940 1 2021-12-13 Youenn Fablet <youenn@apple.com> 2 3 Implement step 17 of main fetch algorithm 4 https://bugs.webkit.org/show_bug.cgi?id=234140 5 6 Reviewed by Brent Fulgham. 7 8 * web-platform-tests/service-workers/service-worker/fetch-csp.https.html: 9 * web-platform-tests/service-workers/service-worker/resources/fetch-csp-iframe.html.sub.headers: 10 1 11 2021-12-11 Antoine Quint <graouts@webkit.org> 2 12 -
trunk/LayoutTests/imported/w3c/web-platform-tests/service-workers/service-worker/fetch-csp.https.html
r279389 r286940 109 109 }) 110 110 .then(function() { 111 return assert_resolves( 112 frame.contentWindow.fetch(IMAGE_URL + "&fetch1", { mode: 'no-cors'}), 113 'Allowed scope fetch resource should be loaded.'); 114 }) 115 .then(function() { 116 return assert_resolves( 117 frame.contentWindow.fetch( 118 // The request for IMAGE_URL will be fetched in SW. 119 './sample?url=' + encodeURIComponent(IMAGE_URL + '&fetch2'), { mode: 'no-cors'}), 120 'Allowed scope fetch resource which was fetched via SW should be loaded.'); 121 }) 122 .then(function() { 123 return assert_rejects( 124 frame.contentWindow.fetch(REMOTE_IMAGE_URL + "&fetch3", { mode: 'no-cors'}), 125 'Disallowed scope fetch resource should not be loaded.'); 126 }) 127 .then(function() { 128 return assert_rejects( 129 frame.contentWindow.fetch( 130 // The request for REMOTE_IMAGE_URL will be fetched in SW. 131 './sample?url=' + encodeURIComponent(REMOTE_IMAGE_URL + '&fetch4'), { mode: 'no-cors'}), 132 'Disallowed scope fetch resource which was fetched via SW should not be loaded.'); 133 }) 134 .then(function() { 111 135 frame.remove(); 112 136 }); -
trunk/LayoutTests/imported/w3c/web-platform-tests/service-workers/service-worker/resources/fetch-csp-iframe.html.sub.headers
r220223 r286940 1 Content-Security-Policy: img-src https://{{host}}:{{ports[https][0]}} 1 Content-Security-Policy: img-src https://{{host}}:{{ports[https][0]}}; connect-src 'unsafe-inline' 'self' -
trunk/Source/WebCore/ChangeLog
r286939 r286940 1 2021-12-13 Youenn Fablet <youenn@apple.com> 2 3 Implement step 17 of main fetch algorithm 4 https://bugs.webkit.org/show_bug.cgi?id=234140 5 6 Reviewed by Brent Fulgham. 7 8 The step was implemented for non DocumentThreadableLoader resources, we need to also do the same step within DocumentThreadableLoader. 9 10 Covered by existing updated tests. 11 12 * loader/DocumentThreadableLoader.cpp: 13 * loader/DocumentThreadableLoader.h: 14 1 15 2021-12-13 Youenn Fablet <youenn@apple.com> 2 16 -
trunk/Source/WebCore/loader/DocumentThreadableLoader.cpp
r286937 r286940 405 405 ASSERT(response.type() != ResourceResponse::Type::Error); 406 406 407 #if ENABLE(SERVICE_WORKER) 408 // https://fetch.spec.whatwg.org/commit-snapshots/6257e220d70f560a037e46f1b4206325400db8dc/#main-fetch step 17. 409 if (response.source() == ResourceResponse::Source::ServiceWorker && response.url() != m_resource->url()) { 410 if (!isResponseAllowedByContentSecurityPolicy(response)) { 411 reportContentSecurityPolicyError(response.url()); 412 return; 413 } 414 } 415 #endif 416 407 417 InspectorInstrumentation::didReceiveThreadableLoaderResponse(*this, identifier); 408 418 … … 692 702 } 693 703 704 bool DocumentThreadableLoader::isResponseAllowedByContentSecurityPolicy(const ResourceResponse& response) 705 { 706 return isAllowedByContentSecurityPolicy(response.url(), ContentSecurityPolicy::RedirectResponseReceived::Yes, { }); 707 } 708 694 709 bool DocumentThreadableLoader::isAllowedRedirect(const URL& url) 695 710 { -
trunk/Source/WebCore/loader/DocumentThreadableLoader.h
r282712 r286940 106 106 bool isAllowedRedirect(const URL&); 107 107 bool isAllowedByContentSecurityPolicy(const URL&, ContentSecurityPolicy::RedirectResponseReceived, const URL& preRedirectURL = URL()); 108 bool isResponseAllowedByContentSecurityPolicy(const ResourceResponse&); 108 109 109 110 SecurityOrigin& securityOrigin() const;
Note:
See TracChangeset
for help on using the changeset viewer.