⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 287627 in webkit


Ignore:
Timestamp:
Jan 5, 2022, 10:21:03 AM (5 years ago)
Author:
Russell Epstein
Message:

Cherry-pick r286940. rdar://problem/85388372

Implement step 17 of main fetch algorithm
​https://bugs.webkit.org/show_bug.cgi?id=234140

Reviewed by Brent Fulgham.

LayoutTests/imported/w3c:

  • web-platform-tests/service-workers/service-worker/fetch-csp.https.html:
  • web-platform-tests/service-workers/service-worker/resources/fetch-csp-iframe.html.sub.headers:

Source/WebCore:

The step was implemented for non DocumentThreadableLoader resources, we need to also do the same step within DocumentThreadableLoader.

Covered by existing updated tests.

  • loader/DocumentThreadableLoader.cpp:
  • loader/DocumentThreadableLoader.h:

git-svn-id: ​https://svn.webkit.org/repository/webkit/trunk@286940 268f45cc-cd09-0410-ab3c-d52691b4dbfc

Location:
branches/safari-612-branch
Files:
6 edited

Legend:

Unmodified
Added
Removed
  • branches/safari-612-branch/LayoutTests/imported/w3c/ChangeLog

    r285321 r287627  
     12022-01-05  Russell Epstein  <repstein@apple.com>
     2
     3        Cherry-pick r286940. rdar://problem/85388372
     4
     5    Implement step 17 of main fetch algorithm
     6    https://bugs.webkit.org/show_bug.cgi?id=234140
     7   
     8    Reviewed by Brent Fulgham.
     9   
     10    LayoutTests/imported/w3c:
     11   
     12    * web-platform-tests/service-workers/service-worker/fetch-csp.https.html:
     13    * web-platform-tests/service-workers/service-worker/resources/fetch-csp-iframe.html.sub.headers:
     14   
     15    Source/WebCore:
     16   
     17    The step was implemented for non DocumentThreadableLoader resources, we need to also do the same step within DocumentThreadableLoader.
     18   
     19    Covered by existing updated tests.
     20   
     21    * loader/DocumentThreadableLoader.cpp:
     22    * loader/DocumentThreadableLoader.h:
     23   
     24   
     25    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@286940 268f45cc-cd09-0410-ab3c-d52691b4dbfc
     26
     27    2021-12-13  Youenn Fablet  <youenn@apple.com>
     28
     29            Implement step 17 of main fetch algorithm
     30            https://bugs.webkit.org/show_bug.cgi?id=234140
     31
     32            Reviewed by Brent Fulgham.
     33
     34            * web-platform-tests/service-workers/service-worker/fetch-csp.https.html:
     35            * web-platform-tests/service-workers/service-worker/resources/fetch-csp-iframe.html.sub.headers:
     36
    1372021-11-04  Russell Epstein  <repstein@apple.com>
    238
  • branches/safari-612-branch/LayoutTests/imported/w3c/web-platform-tests/service-workers/service-worker/fetch-csp.https.html

    r279389 r287627  
    109109        })
    110110      .then(function() {
     111          return assert_resolves(
     112              frame.contentWindow.fetch(IMAGE_URL + "&fetch1", { mode: 'no-cors'}),
     113              'Allowed scope fetch resource should be loaded.');
     114        })
     115      .then(function() {
     116          return assert_resolves(
     117              frame.contentWindow.fetch(
     118                  // The request for IMAGE_URL will be fetched in SW.
     119                  './sample?url=' + encodeURIComponent(IMAGE_URL + '&fetch2'), { mode: 'no-cors'}),
     120              'Allowed scope fetch resource which was fetched via SW should be loaded.');
     121        })
     122      .then(function() {
     123          return assert_rejects(
     124              frame.contentWindow.fetch(REMOTE_IMAGE_URL + "&fetch3", { mode: 'no-cors'}),
     125              'Disallowed scope fetch resource should not be loaded.');
     126        })
     127      .then(function() {
     128          return assert_rejects(
     129              frame.contentWindow.fetch(
     130                  // The request for REMOTE_IMAGE_URL will be fetched in SW.
     131                  './sample?url=' + encodeURIComponent(REMOTE_IMAGE_URL + '&fetch4'), { mode: 'no-cors'}),
     132              'Disallowed scope fetch resource which was fetched via SW should not be loaded.');
     133        })
     134      .then(function() {
    111135          frame.remove();
    112136        });
  • branches/safari-612-branch/LayoutTests/imported/w3c/web-platform-tests/service-workers/service-worker/resources/fetch-csp-iframe.html.sub.headers

    r220223 r287627  
    1 Content-Security-Policy: img-src https://{{host}}:{{ports[https][0]}}
     1Content-Security-Policy: img-src https://{{host}}:{{ports[https][0]}}; connect-src 'unsafe-inline' 'self'
  • branches/safari-612-branch/Source/WebCore/ChangeLog

    r287620 r287627  
     12022-01-05  Russell Epstein  <repstein@apple.com>
     2
     3        Cherry-pick r286940. rdar://problem/85388372
     4
     5    Implement step 17 of main fetch algorithm
     6    https://bugs.webkit.org/show_bug.cgi?id=234140
     7   
     8    Reviewed by Brent Fulgham.
     9   
     10    LayoutTests/imported/w3c:
     11   
     12    * web-platform-tests/service-workers/service-worker/fetch-csp.https.html:
     13    * web-platform-tests/service-workers/service-worker/resources/fetch-csp-iframe.html.sub.headers:
     14   
     15    Source/WebCore:
     16   
     17    The step was implemented for non DocumentThreadableLoader resources, we need to also do the same step within DocumentThreadableLoader.
     18   
     19    Covered by existing updated tests.
     20   
     21    * loader/DocumentThreadableLoader.cpp:
     22    * loader/DocumentThreadableLoader.h:
     23   
     24   
     25    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@286940 268f45cc-cd09-0410-ab3c-d52691b4dbfc
     26
     27    2021-12-13  Youenn Fablet  <youenn@apple.com>
     28
     29            Implement step 17 of main fetch algorithm
     30            https://bugs.webkit.org/show_bug.cgi?id=234140
     31
     32            Reviewed by Brent Fulgham.
     33
     34            The step was implemented for non DocumentThreadableLoader resources, we need to also do the same step within DocumentThreadableLoader.
     35
     36            Covered by existing updated tests.
     37
     38            * loader/DocumentThreadableLoader.cpp:
     39            * loader/DocumentThreadableLoader.h:
     40
    1412022-01-05  Russell Epstein  <repstein@apple.com>
    242
  • branches/safari-612-branch/Source/WebCore/loader/DocumentThreadableLoader.cpp

    r282928 r287627  
    405405    ASSERT(response.type() != ResourceResponse::Type::Error);
    406406
     407#if ENABLE(SERVICE_WORKER)
     408    // https://fetch.spec.whatwg.org/commit-snapshots/6257e220d70f560a037e46f1b4206325400db8dc/#main-fetch step 17.
     409    if (response.source() == ResourceResponse::Source::ServiceWorker && response.url() != m_resource->url()) {
     410        if (!isResponseAllowedByContentSecurityPolicy(response)) {
     411            reportContentSecurityPolicyError(response.url());
     412            return;
     413        }
     414    }
     415#endif
     416
    407417    InspectorInstrumentation::didReceiveThreadableLoaderResponse(*this, identifier);
    408418
    … …  
    692702}
    693703
     704bool DocumentThreadableLoader::isResponseAllowedByContentSecurityPolicy(const ResourceResponse& response)
     705{
     706    return isAllowedByContentSecurityPolicy(response.url(), ContentSecurityPolicy::RedirectResponseReceived::Yes, { });
     707}
     708
    694709bool DocumentThreadableLoader::isAllowedRedirect(const URL& url)
    695710{
  • branches/safari-612-branch/Source/WebCore/loader/DocumentThreadableLoader.h

    r282928 r287627  
    105105        bool isAllowedRedirect(const URL&);
    106106        bool isAllowedByContentSecurityPolicy(const URL&, ContentSecurityPolicy::RedirectResponseReceived, const URL& preRedirectURL = URL());
     107        bool isResponseAllowedByContentSecurityPolicy(const ResourceResponse&);
    107108
    108109        SecurityOrigin& securityOrigin() const;
Note: See TracChangeset for help on using the changeset viewer.