Title: [207840] trunk
Revision
207840
Author
[email protected]
Date
2016-10-25 13:17:36 -0700 (Tue, 25 Oct 2016)

Log Message

Implement rel=noopener
https://bugs.webkit.org/show_bug.cgi?id=155166
<rdar://problem/25193787>

Reviewed by Brent Fulgham.

Source/WebCore:

Added support for rel=noopener to a and area elements.

Tests: fast/dom/Window/a-rel-noopener.html
       fast/dom/Window/area-rel-noopener.html

* html/HTMLAnchorElement.cpp:
(WebCore::HTMLAnchorElement::HTMLAnchorElement): Stopped initializing m_linkRelations to 0.
(WebCore::HTMLAnchorElement::parseAttribute): Declared static AtomicStrings for "noreferrer"
and "noopener", and created a SpaceSplitString from the rel attribute value to test for these
two values.
(WebCore::HTMLAnchorElement::hasRel): Updated to use OptionSet::contains().
(WebCore::HTMLAnchorElement::relList): Added a check for "noopener".
(WebCore::HTMLAnchorElement::handleClick): Passed NewFrameOpenerPolicy::Suppress to
FrameLoader::urlSelected() if rel=noopener was specified.
* html/HTMLAnchorElement.h: Changed the Relation enum to an enum class, removed unused enum
values, and changed m_linkRelations from a 30-bit unsigned integer to an OptionSet<Relation>
(HTMLAnchorElement is still 128 bytes on 64-bit).
* loader/FrameLoader.cpp:
(WebCore::FrameLoader::urlSelected): Changed to only compute a NewFrameOpenerPolicy from the
referrer policy if an explicit NewFrameOpenerPolicy isn't specified. Removed the version of
urlSelected() that did not take a downloadAttribute parameter.
* loader/FrameLoader.h: Added an Optional<NewFrameOpenerPolicy> parameter to urlSelected(),
and set a default argument for downloadAttribute instead of having a second version of
urlSelected().

LayoutTests:

* fast/dom/DOMTokenList-supports-expected.txt:
* fast/dom/DOMTokenList-supports.html:
* fast/dom/Window/a-rel-noopener-expected.txt: Added.
* fast/dom/Window/a-rel-noopener.html: Added.
* fast/dom/Window/area-rel-noopener-expected.txt: Added.
* fast/dom/Window/area-rel-noopener.html: Added.
* fast/dom/Window/resources/rel-noopener.js: Added.

Modified Paths

Added Paths

Diff

Modified: trunk/LayoutTests/ChangeLog (207839 => 207840)


--- trunk/LayoutTests/ChangeLog	2016-10-25 20:07:25 UTC (rev 207839)
+++ trunk/LayoutTests/ChangeLog	2016-10-25 20:17:36 UTC (rev 207840)
@@ -1,3 +1,19 @@
+2016-10-25  Andy Estes  <[email protected]>
+
+        Implement rel=noopener
+        https://bugs.webkit.org/show_bug.cgi?id=155166
+        <rdar://problem/25193787>
+
+        Reviewed by Brent Fulgham.
+
+        * fast/dom/DOMTokenList-supports-expected.txt:
+        * fast/dom/DOMTokenList-supports.html:
+        * fast/dom/Window/a-rel-noopener-expected.txt: Added.
+        * fast/dom/Window/a-rel-noopener.html: Added.
+        * fast/dom/Window/area-rel-noopener-expected.txt: Added.
+        * fast/dom/Window/area-rel-noopener.html: Added.
+        * fast/dom/Window/resources/rel-noopener.js: Added.
+
 2016-10-25  Eric Carlson  <[email protected]>
 
         [MediaStream] Add "has capture device" bit to media state flags

Modified: trunk/LayoutTests/fast/dom/DOMTokenList-supports-expected.txt (207839 => 207840)


--- trunk/LayoutTests/fast/dom/DOMTokenList-supports-expected.txt	2016-10-25 20:07:25 UTC (rev 207839)
+++ trunk/LayoutTests/fast/dom/DOMTokenList-supports-expected.txt	2016-10-25 20:17:36 UTC (rev 207840)
@@ -21,6 +21,8 @@
 PASS anchor.relList.__proto__ is DOMTokenList.prototype
 PASS anchor.relList.supports(anchorRelSupportedValues[i]) is true
 PASS anchor.relList.supports(anchorRelSupportedValues[i].toUpperCase()) is true
+PASS anchor.relList.supports(anchorRelSupportedValues[i]) is true
+PASS anchor.relList.supports(anchorRelSupportedValues[i].toUpperCase()) is true
 PASS anchor.relList.supports('unsupported') is false
 
 * HTMLAreaElement.relList
@@ -27,6 +29,8 @@
 PASS area.relList.__proto__ is DOMTokenList.prototype
 PASS area.relList.supports(areaRelSupportedValues[i]) is true
 PASS area.relList.supports(areaRelSupportedValues[i].toUpperCase()) is true
+PASS area.relList.supports(areaRelSupportedValues[i]) is true
+PASS area.relList.supports(areaRelSupportedValues[i].toUpperCase()) is true
 PASS area.relList.supports('unsupported') is false
 
 * HTMLIFrameElement.sandbox

Modified: trunk/LayoutTests/fast/dom/DOMTokenList-supports.html (207839 => 207840)


--- trunk/LayoutTests/fast/dom/DOMTokenList-supports.html	2016-10-25 20:07:25 UTC (rev 207839)
+++ trunk/LayoutTests/fast/dom/DOMTokenList-supports.html	2016-10-25 20:17:36 UTC (rev 207840)
@@ -22,7 +22,7 @@
 debug("* HTMLAnchorElement.relList");
 var anchor = document.createElement("a");
 shouldBe("anchor.relList.__proto__", "DOMTokenList.prototype");
-var anchorRelSupportedValues = ["noreferrer"];
+var anchorRelSupportedValues = ["noreferrer", "noopener"];
 for (var i = 0; i < anchorRelSupportedValues.length; i++) {
     shouldBeTrue("anchor.relList.supports(anchorRelSupportedValues[i])");
     shouldBeTrue("anchor.relList.supports(anchorRelSupportedValues[i].toUpperCase())");
@@ -33,7 +33,7 @@
 debug("* HTMLAreaElement.relList");
 var area = document.createElement("area");
 shouldBe("area.relList.__proto__", "DOMTokenList.prototype");
-var areaRelSupportedValues = ["noreferrer"];
+var areaRelSupportedValues = ["noreferrer", "noopener"];
 for (var i = 0; i < areaRelSupportedValues.length; i++) {
     shouldBeTrue("area.relList.supports(areaRelSupportedValues[i])");
     shouldBeTrue("area.relList.supports(areaRelSupportedValues[i].toUpperCase())");

Added: trunk/LayoutTests/fast/dom/Window/a-rel-noopener-expected.txt (0 => 207840)


--- trunk/LayoutTests/fast/dom/Window/a-rel-noopener-expected.txt	                        (rev 0)
+++ trunk/LayoutTests/fast/dom/Window/a-rel-noopener-expected.txt	2016-10-25 20:17:36 UTC (rev 207840)
@@ -0,0 +1,3 @@
+Test that window.opener is null when a new window is opened from an anchor element with rel='noopener'.
+
+PASS: window.opener is null

Added: trunk/LayoutTests/fast/dom/Window/a-rel-noopener.html (0 => 207840)


--- trunk/LayoutTests/fast/dom/Window/a-rel-noopener.html	                        (rev 0)
+++ trunk/LayoutTests/fast/dom/Window/a-rel-noopener.html	2016-10-25 20:17:36 UTC (rev 207840)
@@ -0,0 +1,9 @@
+<!DOCTYPE html>
+<html>
+<body>
+    <p>Test that window.opener is null when a new window is opened from an anchor element with rel='noopener'.</p>
+    <a id="link" href="" target="_blank" rel="noopener"></a>
+    <div id="console"></div>
+    <script src=""
+</body>
+</html>

Added: trunk/LayoutTests/fast/dom/Window/area-rel-noopener-expected.txt (0 => 207840)


--- trunk/LayoutTests/fast/dom/Window/area-rel-noopener-expected.txt	                        (rev 0)
+++ trunk/LayoutTests/fast/dom/Window/area-rel-noopener-expected.txt	2016-10-25 20:17:36 UTC (rev 207840)
@@ -0,0 +1,4 @@
+Test that window.opener is null when a new window is opened from an area element with rel='noopener'.
+
+
+PASS: window.opener is null

Added: trunk/LayoutTests/fast/dom/Window/area-rel-noopener.html (0 => 207840)


--- trunk/LayoutTests/fast/dom/Window/area-rel-noopener.html	                        (rev 0)
+++ trunk/LayoutTests/fast/dom/Window/area-rel-noopener.html	2016-10-25 20:17:36 UTC (rev 207840)
@@ -0,0 +1,12 @@
+<!DOCTYPE html>
+<html>
+<body>
+    <p>Test that window.opener is null when a new window is opened from an area element with rel='noopener'.</p>
+    <img src="" width="128" height="128" usemap=""
+    <map name="map">
+        <area id="link" shape="rect" coords="0,0,128,128" href="" target="_blank" rel="noopener">
+    </map>
+    <div id="console"></div>
+    <script src=""
+</body>
+</html>

Added: trunk/LayoutTests/fast/dom/Window/resources/rel-noopener.js (0 => 207840)


--- trunk/LayoutTests/fast/dom/Window/resources/rel-noopener.js	                        (rev 0)
+++ trunk/LayoutTests/fast/dom/Window/resources/rel-noopener.js	2016-10-25 20:17:36 UTC (rev 207840)
@@ -0,0 +1,17 @@
+if (window.testRunner) {
+    testRunner.setCanOpenWindows(true);
+    testRunner.dumpAsText();
+    testRunner.waitUntilDone();
+}
+
+if (document.location.hash === "#new-window") {
+    var console = window.open("", "originalWindow").document.getElementById("console");
+    if (window.opener)
+        console.innerText = "FAIL: window.opener is non-null";
+    else
+        console.innerText = "PASS: window.opener is null";
+    testRunner.notifyDone();
+} else {
+    window.name = "originalWindow";
+    document.getElementById("link").click();
+}

Modified: trunk/Source/WebCore/ChangeLog (207839 => 207840)


--- trunk/Source/WebCore/ChangeLog	2016-10-25 20:07:25 UTC (rev 207839)
+++ trunk/Source/WebCore/ChangeLog	2016-10-25 20:17:36 UTC (rev 207840)
@@ -1,3 +1,36 @@
+2016-10-25  Andy Estes  <[email protected]>
+
+        Implement rel=noopener
+        https://bugs.webkit.org/show_bug.cgi?id=155166
+        <rdar://problem/25193787>
+
+        Reviewed by Brent Fulgham.
+
+        Added support for rel=noopener to a and area elements.
+
+        Tests: fast/dom/Window/a-rel-noopener.html
+               fast/dom/Window/area-rel-noopener.html
+
+        * html/HTMLAnchorElement.cpp:
+        (WebCore::HTMLAnchorElement::HTMLAnchorElement): Stopped initializing m_linkRelations to 0.
+        (WebCore::HTMLAnchorElement::parseAttribute): Declared static AtomicStrings for "noreferrer"
+        and "noopener", and created a SpaceSplitString from the rel attribute value to test for these
+        two values.
+        (WebCore::HTMLAnchorElement::hasRel): Updated to use OptionSet::contains().
+        (WebCore::HTMLAnchorElement::relList): Added a check for "noopener".
+        (WebCore::HTMLAnchorElement::handleClick): Passed NewFrameOpenerPolicy::Suppress to
+        FrameLoader::urlSelected() if rel=noopener was specified.
+        * html/HTMLAnchorElement.h: Changed the Relation enum to an enum class, removed unused enum
+        values, and changed m_linkRelations from a 30-bit unsigned integer to an OptionSet<Relation>
+        (HTMLAnchorElement is still 128 bytes on 64-bit).
+        * loader/FrameLoader.cpp:
+        (WebCore::FrameLoader::urlSelected): Changed to only compute a NewFrameOpenerPolicy from the
+        referrer policy if an explicit NewFrameOpenerPolicy isn't specified. Removed the version of
+        urlSelected() that did not take a downloadAttribute parameter.
+        * loader/FrameLoader.h: Added an Optional<NewFrameOpenerPolicy> parameter to urlSelected(),
+        and set a default argument for downloadAttribute instead of having a second version of
+        urlSelected().
+
 2016-10-25  Eric Carlson  <[email protected]>
 
         [MediaStream] Add "has capture device" bit to media state flags

Modified: trunk/Source/WebCore/html/HTMLAnchorElement.cpp (207839 => 207840)


--- trunk/Source/WebCore/html/HTMLAnchorElement.cpp	2016-10-25 20:07:25 UTC (rev 207839)
+++ trunk/Source/WebCore/html/HTMLAnchorElement.cpp	2016-10-25 20:17:36 UTC (rev 207840)
@@ -59,7 +59,6 @@
     : HTMLElement(tagName, document)
     , m_hasRootEditableElementForSelectionOnMouseDown(false)
     , m_wasShiftKeyDownOnMouseDown(false)
-    , m_linkRelations(0)
     , m_cachedVisitedLinkHash(0)
 {
 }
@@ -250,8 +249,14 @@
         // Do nothing.
     } else if (name == relAttr) {
         // Update HTMLAnchorElement::relList() if more rel attributes values are supported.
-        if (SpaceSplitString::spaceSplitStringContainsValue(value, "noreferrer", true))
-            m_linkRelations |= RelationNoReferrer;
+        static NeverDestroyed<AtomicString> noReferrer("noreferrer", AtomicString::ConstructFromLiteral);
+        static NeverDestroyed<AtomicString> noOpener("noopener", AtomicString::ConstructFromLiteral);
+        const bool shouldFoldCase = true;
+        SpaceSplitString relValue(value, shouldFoldCase);
+        if (relValue.contains(noReferrer))
+            m_linkRelations |= Relation::NoReferrer;
+        if (relValue.contains(noOpener))
+            m_linkRelations |= Relation::NoOpener;
         if (m_relList)
             m_relList->associatedAttributeValueChanged(value);
     }
@@ -296,9 +301,9 @@
     setAttributeWithoutSynchronization(hrefAttr, value);
 }
 
-bool HTMLAnchorElement::hasRel(uint32_t relation) const
+bool HTMLAnchorElement::hasRel(Relation relation) const
 {
-    return m_linkRelations & relation;
+    return m_linkRelations.contains(relation);
 }
 
 DOMTokenList& HTMLAnchorElement::relList()
@@ -305,7 +310,7 @@
 {
     if (!m_relList) 
         m_relList = std::make_unique<DOMTokenList>(*this, HTMLNames::relAttr, [](StringView token) {
-            return equalIgnoringASCIICase(token, "noreferrer");
+            return equalIgnoringASCIICase(token, "noreferrer") || equalIgnoringASCIICase(token, "noopener");
         });
     return *m_relList;
 }
@@ -389,7 +394,9 @@
     }
 #endif
 
-    frame->loader().urlSelected(completedURL, target(), &event, LockHistory::No, LockBackForwardList::No, hasRel(RelationNoReferrer) ? NeverSendReferrer : MaybeSendReferrer, document().shouldOpenExternalURLsPolicyToPropagate(), downloadAttribute);
+    ShouldSendReferrer shouldSendReferrer = hasRel(Relation::NoReferrer) ? NeverSendReferrer : MaybeSendReferrer;
+    auto newFrameOpenerPolicy = hasRel(Relation::NoOpener) ? makeOptional(NewFrameOpenerPolicy::Suppress) : Nullopt;
+    frame->loader().urlSelected(completedURL, target(), &event, LockHistory::No, LockBackForwardList::No, shouldSendReferrer, document().shouldOpenExternalURLsPolicyToPropagate(), newFrameOpenerPolicy, downloadAttribute);
 
     sendPings(completedURL);
 }

Modified: trunk/Source/WebCore/html/HTMLAnchorElement.h (207839 => 207840)


--- trunk/Source/WebCore/html/HTMLAnchorElement.h	2016-10-25 20:07:25 UTC (rev 207839)
+++ trunk/Source/WebCore/html/HTMLAnchorElement.h	2016-10-25 20:17:36 UTC (rev 207840)
@@ -2,7 +2,7 @@
  * Copyright (C) 1999 Lars Knoll ([email protected])
  *           (C) 1999 Antti Koivisto ([email protected])
  *           (C) 2000 Simon Hausmann <[email protected]>
- * Copyright (C) 2007, 2008, 2009, 2010 Apple Inc. All rights reserved.
+ * Copyright (C) 2007-2016 Apple Inc. All rights reserved.
  *
  * This library is free software; you can redistribute it and/or
  * modify it under the terms of the GNU Library General Public
@@ -27,6 +27,7 @@
 #include "HTMLNames.h"
 #include "LinkHash.h"
 #include "URLUtils.h"
+#include <wtf/OptionSet.h>
 
 namespace WebCore {
 
@@ -33,26 +34,9 @@
 class DOMTokenList;
 
 // Link relation bitmask values.
-// FIXME: Uncomment as the various link relations are implemented.
-enum {
-//     RelationAlternate   = 0x00000001,
-//     RelationArchives    = 0x00000002,
-//     RelationAuthor      = 0x00000004,
-//     RelationBoomark     = 0x00000008,
-//     RelationExternal    = 0x00000010,
-//     RelationFirst       = 0x00000020,
-//     RelationHelp        = 0x00000040,
-//     RelationIndex       = 0x00000080,
-//     RelationLast        = 0x00000100,
-//     RelationLicense     = 0x00000200,
-//     RelationNext        = 0x00000400,
-//     RelationNoFolow    = 0x00000800,
-    RelationNoReferrer     = 0x00001000,
-//     RelationPrev        = 0x00002000,
-//     RelationSearch      = 0x00004000,
-//     RelationSidebar     = 0x00008000,
-//     RelationTag         = 0x00010000,
-//     RelationUp          = 0x00020000,
+enum class Relation {
+    NoReferrer = 1 << 0,
+    NoOpener = 1 << 1,
 };
 
 class HTMLAnchorElement : public HTMLElement, public URLUtils<HTMLAnchorElement> {
@@ -76,7 +60,7 @@
 
     bool willRespondToMouseClickEvents() final;
 
-    bool hasRel(uint32_t relation) const;
+    bool hasRel(Relation) const;
     
     LinkHash visitedLinkHash() const;
     void invalidateCachedVisitedLinkHash() { m_cachedVisitedLinkHash = 0; }
@@ -117,9 +101,9 @@
     void setRootEditableElementForSelectionOnMouseDown(Element*);
     void clearRootEditableElementForSelectionOnMouseDown();
 
-    bool m_hasRootEditableElementForSelectionOnMouseDown : 1;
-    bool m_wasShiftKeyDownOnMouseDown : 1;
-    uint32_t m_linkRelations : 30;
+    bool m_hasRootEditableElementForSelectionOnMouseDown;
+    bool m_wasShiftKeyDownOnMouseDown;
+    OptionSet<Relation> m_linkRelations;
     mutable LinkHash m_cachedVisitedLinkHash;
 
     std::unique_ptr<DOMTokenList> m_relList;

Modified: trunk/Source/WebCore/loader/FrameLoader.cpp (207839 => 207840)


--- trunk/Source/WebCore/loader/FrameLoader.cpp	2016-10-25 20:07:25 UTC (rev 207839)
+++ trunk/Source/WebCore/loader/FrameLoader.cpp	2016-10-25 20:17:36 UTC (rev 207840)
@@ -345,20 +345,12 @@
     urlSelected(request, nullptr);
 }
 
-void FrameLoader::urlSelected(const URL& url, const String& passedTarget, Event* triggeringEvent, LockHistory lockHistory, LockBackForwardList lockBackForwardList, ShouldSendReferrer shouldSendReferrer, ShouldOpenExternalURLsPolicy shouldOpenExternalURLsPolicy, const AtomicString& downloadAttribute)
+void FrameLoader::urlSelected(const URL& url, const String& passedTarget, Event* triggeringEvent, LockHistory lockHistory, LockBackForwardList lockBackForwardList, ShouldSendReferrer shouldSendReferrer, ShouldOpenExternalURLsPolicy shouldOpenExternalURLsPolicy, Optional<NewFrameOpenerPolicy> openerPolicy, const AtomicString& downloadAttribute)
 {
-    NewFrameOpenerPolicy newFrameOpenerPolicy = shouldSendReferrer == NeverSendReferrer ? NewFrameOpenerPolicy::Suppress : NewFrameOpenerPolicy::Allow;
-
+    NewFrameOpenerPolicy newFrameOpenerPolicy = openerPolicy.valueOr(shouldSendReferrer == NeverSendReferrer ? NewFrameOpenerPolicy::Suppress : NewFrameOpenerPolicy::Allow);
     urlSelected(FrameLoadRequest(m_frame.document()->securityOrigin(), ResourceRequest(url), passedTarget, lockHistory, lockBackForwardList, shouldSendReferrer, AllowNavigationToInvalidURL::Yes, newFrameOpenerPolicy, DoNotReplaceDocumentIfJavaScriptURL, shouldOpenExternalURLsPolicy, downloadAttribute), triggeringEvent);
 }
 
-void FrameLoader::urlSelected(const URL& url, const String& passedTarget, Event* triggeringEvent, LockHistory lockHistory, LockBackForwardList lockBackForwardList, ShouldSendReferrer shouldSendReferrer, ShouldOpenExternalURLsPolicy shouldOpenExternalURLsPolicy)
-{
-    NewFrameOpenerPolicy newFrameOpenerPolicy = shouldSendReferrer == NeverSendReferrer ? NewFrameOpenerPolicy::Suppress : NewFrameOpenerPolicy::Allow;
-
-    urlSelected(FrameLoadRequest(m_frame.document()->securityOrigin(), ResourceRequest(url), passedTarget, lockHistory, lockBackForwardList, shouldSendReferrer, AllowNavigationToInvalidURL::Yes, newFrameOpenerPolicy, DoNotReplaceDocumentIfJavaScriptURL, shouldOpenExternalURLsPolicy, nullAtom), triggeringEvent);
-}
-
 void FrameLoader::urlSelected(const FrameLoadRequest& passedRequest, Event* triggeringEvent)
 {
     Ref<Frame> protect(m_frame);

Modified: trunk/Source/WebCore/loader/FrameLoader.h (207839 => 207840)


--- trunk/Source/WebCore/loader/FrameLoader.h	2016-10-25 20:07:25 UTC (rev 207839)
+++ trunk/Source/WebCore/loader/FrameLoader.h	2016-10-25 20:17:36 UTC (rev 207840)
@@ -119,8 +119,7 @@
     unsigned long loadResourceSynchronously(const ResourceRequest&, StoredCredentials, ClientCredentialPolicy, ResourceError&, ResourceResponse&, RefPtr<SharedBuffer>& data);
 
     void changeLocation(const FrameLoadRequest&);
-    WEBCORE_EXPORT void urlSelected(const URL&, const String& target, Event*, LockHistory, LockBackForwardList, ShouldSendReferrer, ShouldOpenExternalURLsPolicy, const AtomicString& downloadAttribute);
-    WEBCORE_EXPORT void urlSelected(const URL&, const String& target, Event*, LockHistory, LockBackForwardList, ShouldSendReferrer, ShouldOpenExternalURLsPolicy);
+    WEBCORE_EXPORT void urlSelected(const URL&, const String& target, Event*, LockHistory, LockBackForwardList, ShouldSendReferrer, ShouldOpenExternalURLsPolicy, Optional<NewFrameOpenerPolicy> = Nullopt, const AtomicString& downloadAttribute = nullAtom);
     void submitForm(PassRefPtr<FormSubmission>);
 
     WEBCORE_EXPORT void reload(bool endToEndReload = false, bool contentBlockersEnabled = true);
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes

Reply via email to