Title: [276666] branches/safari-611-branch
Revision
276666
Author
[email protected]
Date
2021-04-27 14:07:24 -0700 (Tue, 27 Apr 2021)

Log Message

Cherry-pick r276012. rdar://problem/77211405

    REGRESSION(Safari 14): iframe with blob url does not work with sandboxing
    https://bugs.webkit.org/show_bug.cgi?id=222312
    <rdar://problem/74927624>

    Reviewed by Chris Dumez.

    Source/WebCore:

    In https://trac.webkit.org/r275884, we correctly compute whether a blob is to be considered secure or not.
    For that, we need to have the blob URL registered with its document origin.
    Update PolicyChecker to properly register the temporoary blob URL with its document origin.

    Test: http/tests/security/sandbox-iframe-and-blob.https.html

    * loader/PolicyChecker.cpp:
    (WebCore::FrameLoader::PolicyChecker::extendBlobURLLifetimeIfNecessary const):

    LayoutTests:

    * http/tests/security/resources/sandbox-iframe-and-blob-frame.html: Added.
    * http/tests/security/sandbox-iframe-and-blob.https-expected.txt: Added.
    * http/tests/security/sandbox-iframe-and-blob.https.html: Added.
    * platform/win/TestExpectations:

    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@276012 268f45cc-cd09-0410-ab3c-d52691b4dbfc

Modified Paths

Added Paths

Diff

Modified: branches/safari-611-branch/LayoutTests/ChangeLog (276665 => 276666)


--- branches/safari-611-branch/LayoutTests/ChangeLog	2021-04-27 21:07:20 UTC (rev 276665)
+++ branches/safari-611-branch/LayoutTests/ChangeLog	2021-04-27 21:07:24 UTC (rev 276666)
@@ -1,5 +1,49 @@
 2021-04-27  Russell Epstein  <[email protected]>
 
+        Cherry-pick r276012. rdar://problem/77211405
+
+    REGRESSION(Safari 14): iframe with blob url does not work with sandboxing
+    https://bugs.webkit.org/show_bug.cgi?id=222312
+    <rdar://problem/74927624>
+    
+    Reviewed by Chris Dumez.
+    
+    Source/WebCore:
+    
+    In https://trac.webkit.org/r275884, we correctly compute whether a blob is to be considered secure or not.
+    For that, we need to have the blob URL registered with its document origin.
+    Update PolicyChecker to properly register the temporoary blob URL with its document origin.
+    
+    Test: http/tests/security/sandbox-iframe-and-blob.https.html
+    
+    * loader/PolicyChecker.cpp:
+    (WebCore::FrameLoader::PolicyChecker::extendBlobURLLifetimeIfNecessary const):
+    
+    LayoutTests:
+    
+    * http/tests/security/resources/sandbox-iframe-and-blob-frame.html: Added.
+    * http/tests/security/sandbox-iframe-and-blob.https-expected.txt: Added.
+    * http/tests/security/sandbox-iframe-and-blob.https.html: Added.
+    * platform/win/TestExpectations:
+    
+    
+    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@276012 268f45cc-cd09-0410-ab3c-d52691b4dbfc
+
+    2021-04-15  Youenn Fablet  <[email protected]>
+
+            REGRESSION(Safari 14): iframe with blob url does not work with sandboxing
+            https://bugs.webkit.org/show_bug.cgi?id=222312
+            <rdar://problem/74927624>
+
+            Reviewed by Chris Dumez.
+
+            * http/tests/security/resources/sandbox-iframe-and-blob-frame.html: Added.
+            * http/tests/security/sandbox-iframe-and-blob.https-expected.txt: Added.
+            * http/tests/security/sandbox-iframe-and-blob.https.html: Added.
+            * platform/win/TestExpectations:
+
+2021-04-27  Russell Epstein  <[email protected]>
+
         Cherry-pick r274170. rdar://problem/77194450
 
     REGRESSION (r273003): Animated style may lose original display property value

Added: branches/safari-611-branch/LayoutTests/http/tests/security/resources/sandbox-iframe-and-blob-frame.html (0 => 276666)


--- branches/safari-611-branch/LayoutTests/http/tests/security/resources/sandbox-iframe-and-blob-frame.html	                        (rev 0)
+++ branches/safari-611-branch/LayoutTests/http/tests/security/resources/sandbox-iframe-and-blob-frame.html	2021-04-27 21:07:24 UTC (rev 276666)
@@ -0,0 +1,15 @@
+<!DOCTYPE html>
+<html>
+<body>
+    <iframe id="myFrame"></iframe>
+    <script>
+const html = "<body" + ">PASS<script" + ">parent.postMessage('loaded', '*')</"+ "script></" + "body>";
+var blob = new Blob([html], {type: 'text/html'});
+var url = ""
+myFrame.src = ""
+window._onmessage_ = (event) => {
+    parent.postMessage(event.data, '*');
+};
+    </script>
+</body>
+</html>

Added: branches/safari-611-branch/LayoutTests/http/tests/security/sandbox-iframe-and-blob.https-expected.txt (0 => 276666)


--- branches/safari-611-branch/LayoutTests/http/tests/security/sandbox-iframe-and-blob.https-expected.txt	                        (rev 0)
+++ branches/safari-611-branch/LayoutTests/http/tests/security/sandbox-iframe-and-blob.https-expected.txt	2021-04-27 21:07:24 UTC (rev 276666)
@@ -0,0 +1,4 @@
+
+
+PASS Verify blob URLs are loaded with sandbox iframes
+

Added: branches/safari-611-branch/LayoutTests/http/tests/security/sandbox-iframe-and-blob.https.html (0 => 276666)


--- branches/safari-611-branch/LayoutTests/http/tests/security/sandbox-iframe-and-blob.https.html	                        (rev 0)
+++ branches/safari-611-branch/LayoutTests/http/tests/security/sandbox-iframe-and-blob.https.html	2021-04-27 21:07:24 UTC (rev 276666)
@@ -0,0 +1,23 @@
+<!DOCTYPE html>
+<html>
+<head>
+    <meta charset="UTF-8">
+    <script src=""
+    <script src=""
+</head>
+<body>
+    <iframe id="myFrame" sandbox="allow-scripts"></iframe>
+    <script>
+promise_test(async () => {
+    myFrame.src = ""
+    const result = await new Promise((resolve, reject) => {
+        window._onmessage_ = (event) => {
+            resolve(event.data);
+        };
+        setTimeout(() => reject("iframe load timed out"), 5000);
+    });
+    assert_equals(result, 'loaded');
+}, "Verify blob URLs are loaded with sandbox iframes");
+    </script>
+</body>
+</html>

Modified: branches/safari-611-branch/LayoutTests/platform/win/TestExpectations (276665 => 276666)


--- branches/safari-611-branch/LayoutTests/platform/win/TestExpectations	2021-04-27 21:07:20 UTC (rev 276665)
+++ branches/safari-611-branch/LayoutTests/platform/win/TestExpectations	2021-04-27 21:07:24 UTC (rev 276666)
@@ -2330,6 +2330,7 @@
 http/tests/security/contentSecurityPolicy/navigate-self-to-blob.html [ Skip ]
 http/tests/security/contentSecurityPolicy/report-document-uri-blob.html [ Skip ]
 fast/frames/restoring-page-cache-should-not-run-scripts-via-style-update.html [ Skip ]
+http/tests/security/sandbox-iframe-and-blob.https.html [ Skip ]
 
 # Clear Key not implemented
 http/tests/media/clearkey/clear-key-hls-aes128.html [ Skip ] # Timeout

Modified: branches/safari-611-branch/Source/WebCore/ChangeLog (276665 => 276666)


--- branches/safari-611-branch/Source/WebCore/ChangeLog	2021-04-27 21:07:20 UTC (rev 276665)
+++ branches/safari-611-branch/Source/WebCore/ChangeLog	2021-04-27 21:07:24 UTC (rev 276666)
@@ -1,5 +1,53 @@
 2021-04-27  Russell Epstein  <[email protected]>
 
+        Cherry-pick r276012. rdar://problem/77211405
+
+    REGRESSION(Safari 14): iframe with blob url does not work with sandboxing
+    https://bugs.webkit.org/show_bug.cgi?id=222312
+    <rdar://problem/74927624>
+    
+    Reviewed by Chris Dumez.
+    
+    Source/WebCore:
+    
+    In https://trac.webkit.org/r275884, we correctly compute whether a blob is to be considered secure or not.
+    For that, we need to have the blob URL registered with its document origin.
+    Update PolicyChecker to properly register the temporoary blob URL with its document origin.
+    
+    Test: http/tests/security/sandbox-iframe-and-blob.https.html
+    
+    * loader/PolicyChecker.cpp:
+    (WebCore::FrameLoader::PolicyChecker::extendBlobURLLifetimeIfNecessary const):
+    
+    LayoutTests:
+    
+    * http/tests/security/resources/sandbox-iframe-and-blob-frame.html: Added.
+    * http/tests/security/sandbox-iframe-and-blob.https-expected.txt: Added.
+    * http/tests/security/sandbox-iframe-and-blob.https.html: Added.
+    * platform/win/TestExpectations:
+    
+    
+    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@276012 268f45cc-cd09-0410-ab3c-d52691b4dbfc
+
+    2021-04-15  Youenn Fablet  <[email protected]>
+
+            REGRESSION(Safari 14): iframe with blob url does not work with sandboxing
+            https://bugs.webkit.org/show_bug.cgi?id=222312
+            <rdar://problem/74927624>
+
+            Reviewed by Chris Dumez.
+
+            In https://trac.webkit.org/r275884, we correctly compute whether a blob is to be considered secure or not.
+            For that, we need to have the blob URL registered with its document origin.
+            Update PolicyChecker to properly register the temporoary blob URL with its document origin.
+
+            Test: http/tests/security/sandbox-iframe-and-blob.https.html
+
+            * loader/PolicyChecker.cpp:
+            (WebCore::FrameLoader::PolicyChecker::extendBlobURLLifetimeIfNecessary const):
+
+2021-04-27  Russell Epstein  <[email protected]>
+
         Cherry-pick r276611. rdar://problem/77211533
 
     Remove redundant frameDetached() from the SVGImage destructor

Modified: branches/safari-611-branch/Source/WebCore/loader/PolicyChecker.cpp (276665 => 276666)


--- branches/safari-611-branch/Source/WebCore/loader/PolicyChecker.cpp	2021-04-27 21:07:20 UTC (rev 276665)
+++ branches/safari-611-branch/Source/WebCore/loader/PolicyChecker.cpp	2021-04-27 21:07:24 UTC (rev 276666)
@@ -47,6 +47,7 @@
 #include "HTMLFrameOwnerElement.h"
 #include "HTMLPlugInElement.h"
 #include "Logging.h"
+#include "ThreadableBlobRegistry.h"
 #include <wtf/CompletionHandler.h>
 
 #if USE(QUICK_LOOK)
@@ -111,12 +112,12 @@
 
     // Create a new temporary blobURL in case this one gets revoked during the asynchronous navigation policy decision.
     URL temporaryBlobURL = BlobURL::createPublicURL(&m_frame.document()->securityOrigin());
-    blobRegistry().registerBlobURL(temporaryBlobURL, request.url());
+    ThreadableBlobRegistry::registerBlobURL(&m_frame.document()->securityOrigin(), temporaryBlobURL, request.url());
     request.setURL(temporaryBlobURL);
     if (loader)
         loader->request().setURL(temporaryBlobURL);
     return CompletionHandler<void()>([temporaryBlobURL = WTFMove(temporaryBlobURL)] {
-        blobRegistry().unregisterBlobURL(temporaryBlobURL);
+        ThreadableBlobRegistry::unregisterBlobURL(temporaryBlobURL);
     });
 }
 
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes

Reply via email to