Changeset 291741 in webkit
- Timestamp:
- Mar 23, 2022, 2:04:48 AM (5 years ago)
- Location:
- trunk
- Files:
-
- 5 added
- 6 edited
-
LayoutTests/ChangeLog (modified) (1 diff)
-
LayoutTests/http/tests/cookies/resources/testharness-helpers.js (modified) (1 diff)
-
LayoutTests/http/tests/cookies/same-site/popup-from-iframe-same-site-with-post-form-expected.txt (added)
-
LayoutTests/http/tests/cookies/same-site/popup-from-iframe-same-site-with-post-form.html (added)
-
LayoutTests/http/tests/cookies/same-site/popup-same-site-with-post-form-expected.txt (added)
-
LayoutTests/http/tests/cookies/same-site/popup-same-site-with-post-form.html (added)
-
LayoutTests/http/tests/cookies/same-site/resources/popup-iframe.html (added)
-
Source/WebCore/ChangeLog (modified) (1 diff)
-
Source/WebCore/dom/Document.cpp (modified) (1 diff)
-
Source/WebCore/dom/Document.h (modified) (1 diff)
-
Source/WebCore/loader/FrameLoader.cpp (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
trunk/LayoutTests/ChangeLog
r291740 r291741 1 2022-03-23 Youenn Fablet <youenn@apple.com> 2 3 Computation of Document siteForCookies is buggy in case document is created by window.open 4 https://bugs.webkit.org/show_bug.cgi?id=238202 5 <rdar://88979099> 6 7 Reviewed by John Wilander. 8 9 * http/tests/cookies/resources/testharness-helpers.js: 10 * http/tests/cookies/same-site/popup-from-iframe-same-site-with-post-form-expected.txt: Added. 11 * http/tests/cookies/same-site/popup-from-iframe-same-site-with-post-form.html: Added. 12 * http/tests/cookies/same-site/popup-same-site-with-post-form-expected.txt: Added. 13 * http/tests/cookies/same-site/popup-same-site-with-post-form.html: Added. 14 * http/tests/cookies/same-site/resources/popup-iframe.html: Added. 15 1 16 2022-03-23 Razvan Caliman <rcaliman@apple.com> 2 17 -
trunk/LayoutTests/http/tests/cookies/resources/testharness-helpers.js
r230944 r291741 21 21 } 22 22 23 function with_iframe(url) { 24 return new Promise(function(resolve) { 25 var frame = document.createElement('iframe'); 26 frame.src = url; 27 frame.onload = function() { setTimeout(() => resolve(frame), 0); }; 28 document.body.appendChild(frame); 29 }); 30 } 31 32 function loadPopupThenTriggerPost() 33 { 34 let finish; 35 let promise = new Promise(resolve => finish = resolve); 36 37 clearKnownCookies(); 38 document.cookie = LAX_DOM + "=1; SameSite=Lax; Max-Age=100; path=/"; 39 document.cookie = NORMAL_DOM + "=1; Max-Age=100; path=/"; 40 document.cookie = STRICT_DOM + "=1; SameSite=Strict; Max-Age=100; path=/"; 41 42 const opener = window.open("http://127.0.0.1:8000/cookies/resources/post-cookies-to-opener.py") 43 window.onmessage = e => { 44 window.onmessage = e => { 45 opener.close(); 46 finish(e.data); 47 }; 48 49 const newDoc = opener.document; 50 var form = newDoc.createElement('form'); 51 form.method = 'POST'; 52 form.action = 'http://127.0.0.1:8000/cookies/resources/post-cookies-to-opener.py'; 53 var input = newDoc.createElement('input'); 54 input.name = 'name'; 55 input.value = 'value'; 56 form.appendChild(input); 57 newDoc.body.appendChild(form); 58 form.submit(); 59 }; 60 return promise; 61 } 62 63 function openPopupAndTriggerPost(popupURL, callback) 64 { 65 let finish; 66 let promise = new Promise(resolve => finish = resolve); 67 68 clearKnownCookies(); 69 document.cookie = LAX_DOM + "=1; SameSite=Lax; Max-Age=100; path=/"; 70 document.cookie = NORMAL_DOM + "=1; Max-Age=100; path=/"; 71 document.cookie = STRICT_DOM + "=1; SameSite=Strict; Max-Age=100; path=/"; 72 73 window.addEventListener("message", e => { 74 opener.close(); 75 finish(e.data); 76 }); 77 78 const opener = window.open(popupURL) 79 const newDoc = opener.document; 80 var form = newDoc.createElement('form'); 81 form.method = 'POST'; 82 form.action = 'http://127.0.0.1:8000/cookies/resources/post-cookies-to-opener.py'; 83 var input = newDoc.createElement('input'); 84 input.name = 'name'; 85 input.value = 'value'; 86 form.appendChild(input); 87 newDoc.body.appendChild(form); 88 form.submit(); 89 90 return promise; 91 } -
trunk/Source/WebCore/ChangeLog
r291737 r291741 1 2022-03-23 Youenn Fablet <youenn@apple.com> 2 3 Computation of Document siteForCookies is buggy in case document is created by window.open 4 https://bugs.webkit.org/show_bug.cgi?id=238202 5 <rdar://88979099> 6 7 Reviewed by John Wilander. 8 9 For top level navigations, we need to use the security origin to compute siteForCookies as the document 10 may have the opener security origin. 11 Add a Document routine to handle this case. 12 13 Tests: http/tests/cookies/same-site/popup-from-iframe-same-site-with-post-form.html 14 http/tests/cookies/same-site/popup-same-site-with-post-form.html 15 16 * dom/Document.cpp: 17 * dom/Document.h: 18 * loader/FrameLoader.cpp: 19 1 20 2022-03-22 Ben Nham <nham@apple.com> 2 21 -
trunk/Source/WebCore/dom/Document.cpp
r291320 r291741 9138 9138 } 9139 9139 9140 bool Document::isSameSiteForCookies(const URL& url) const 9141 { 9142 auto domain = isTopDocument() ? RegistrableDomain(securityOrigin().data()) : RegistrableDomain(siteForCookies()); 9143 return domain.matches(url); 9144 } 9145 9140 9146 } // namespace WebCore 9141 9147 -
trunk/Source/WebCore/dom/Document.h
r291734 r291741 1018 1018 const URL& siteForCookies() const { return m_siteForCookies; } 1019 1019 void setSiteForCookies(const URL& url) { m_siteForCookies = url; } 1020 1020 bool isSameSiteForCookies(const URL&) const; 1021 1021 1022 // The following implements the rule from HTML 4 for what valid names are. 1022 1023 // To get this right for all the XML cases, we probably have to improve this or move it -
trunk/Source/WebCore/loader/FrameLoader.cpp
r291320 r291741 3039 3039 return; 3040 3040 } 3041 request.setIsSameSite(areRegistrableDomainsEqual(initiator->siteForCookies(), request.url())); 3041 3042 request.setIsSameSite(initiator->isSameSiteForCookies(request.url())); 3042 3043 } 3043 3044
Note:
See TracChangeset
for help on using the changeset viewer.