Title: [291726] trunk
Revision
291726
Author
[email protected]
Date
2022-03-22 16:53:16 -0700 (Tue, 22 Mar 2022)

Log Message

Check if origin can access storage in Storage API
https://bugs.webkit.org/show_bug.cgi?id=238158

Reviewed by Chris Dumez.

LayoutTests/imported/w3c:

* web-platform-tests/file-system-access/opaque-origin.https.window-expected.txt:
* web-platform-tests/storage/opaque-origin.https.window-expected.txt:

Source/WebCore:

According to spec https://storage.spec.whatwg.org/#obtain-a-storage-key, origin should not access Storage API if
it's opaque. Also, origin should not access storage if it's blocked by storage policy, so we use
SecurityOrigin::canAccessStorage to perform the origin check, like what we do for the other storage APIs.

Updated expectation for imported tests.

* Modules/storage/StorageManager.cpp:
(WebCore::connectionInfo):
* page/SecurityOrigin.h:
(WebCore::SecurityOrigin::canAccessStorageManager const):

Modified Paths

Diff

Modified: trunk/LayoutTests/imported/w3c/ChangeLog (291725 => 291726)


--- trunk/LayoutTests/imported/w3c/ChangeLog	2022-03-22 23:46:50 UTC (rev 291725)
+++ trunk/LayoutTests/imported/w3c/ChangeLog	2022-03-22 23:53:16 UTC (rev 291726)
@@ -1,3 +1,13 @@
+2022-03-22  Sihui Liu  <[email protected]>
+
+        Check if origin can access storage in Storage API
+        https://bugs.webkit.org/show_bug.cgi?id=238158
+
+        Reviewed by Chris Dumez.
+
+        * web-platform-tests/file-system-access/opaque-origin.https.window-expected.txt:
+        * web-platform-tests/storage/opaque-origin.https.window-expected.txt:
+
 2022-03-22  Commit Queue  <[email protected]>
 
         Unreviewed, reverting r291546.

Modified: trunk/LayoutTests/imported/w3c/web-platform-tests/file-system-access/opaque-origin.https.window-expected.txt (291725 => 291726)


--- trunk/LayoutTests/imported/w3c/web-platform-tests/file-system-access/opaque-origin.https.window-expected.txt	2022-03-22 23:46:50 UTC (rev 291725)
+++ trunk/LayoutTests/imported/w3c/web-platform-tests/file-system-access/opaque-origin.https.window-expected.txt	2022-03-22 23:53:16 UTC (rev 291726)
@@ -2,5 +2,5 @@
 PASS showDirectoryPicker() must be undefined for data URI iframes.
 PASS FileSystemDirectoryHandle must be undefined for data URI iframes.
 FAIL navigator.storage.getDirectory() and showDirectoryPicker() must reject in a sandboxed iframe. assert_equals: expected "showDirectoryPicker(): REJECTED: SecurityError" but got "showDirectoryPicker(): EXCEPTION: TypeError"
-FAIL navigator.storage.getDirectory() and showDirectoryPicker() must reject in a sandboxed opened window. assert_equals: expected "showDirectoryPicker(): REJECTED: SecurityError" but got "showDirectoryPicker(): EXCEPTION: TypeError"
+FAIL navigator.storage.getDirectory() and showDirectoryPicker() must reject in a sandboxed opened window. assert_equals: expected "showDirectoryPicker(): REJECTED: SecurityError" but got "navigator.storage.getDirectory(): REJECTED: TypeError"
 

Modified: trunk/LayoutTests/imported/w3c/web-platform-tests/storage/opaque-origin.https.window-expected.txt (291725 => 291726)


--- trunk/LayoutTests/imported/w3c/web-platform-tests/storage/opaque-origin.https.window-expected.txt	2022-03-22 23:46:50 UTC (rev 291725)
+++ trunk/LayoutTests/imported/w3c/web-platform-tests/storage/opaque-origin.https.window-expected.txt	2022-03-22 23:53:16 UTC (rev 291726)
@@ -1,8 +1,8 @@
 
 PASS navigator.storage.persisted() in non-sandboxed iframe should not reject
-FAIL navigator.storage.persisted() in sandboxed iframe should reject with TypeError assert_equals: navigator.storage.persisted() should reject with TypeError expected "correct rejection" but got "no rejection"
+PASS navigator.storage.persisted() in sandboxed iframe should reject with TypeError
 FAIL navigator.storage.estimate() in non-sandboxed iframe should not reject assert_equals: navigator.storage.estimate() should not reject expected "no rejection" but got "API access threw"
 FAIL navigator.storage.estimate() in sandboxed iframe should reject with TypeError assert_equals: navigator.storage.estimate() should reject with TypeError expected "correct rejection" but got "API access threw"
 PASS navigator.storage.persist() in non-sandboxed iframe should not reject
-FAIL navigator.storage.persist() in sandboxed iframe should reject with TypeError assert_equals: navigator.storage.persist() should reject with TypeError expected "correct rejection" but got "no rejection"
+PASS navigator.storage.persist() in sandboxed iframe should reject with TypeError
 

Modified: trunk/Source/WebCore/ChangeLog (291725 => 291726)


--- trunk/Source/WebCore/ChangeLog	2022-03-22 23:46:50 UTC (rev 291725)
+++ trunk/Source/WebCore/ChangeLog	2022-03-22 23:53:16 UTC (rev 291726)
@@ -1,3 +1,21 @@
+2022-03-22  Sihui Liu  <[email protected]>
+
+        Check if origin can access storage in Storage API
+        https://bugs.webkit.org/show_bug.cgi?id=238158
+
+        Reviewed by Chris Dumez.
+
+        According to spec https://storage.spec.whatwg.org/#obtain-a-storage-key, origin should not access Storage API if
+        it's opaque. Also, origin should not access storage if it's blocked by storage policy, so we use 
+        SecurityOrigin::canAccessStorage to perform the origin check, like what we do for the other storage APIs.
+
+        Updated expectation for imported tests.
+
+        * Modules/storage/StorageManager.cpp:
+        (WebCore::connectionInfo):
+        * page/SecurityOrigin.h:
+        (WebCore::SecurityOrigin::canAccessStorageManager const):
+
 2022-03-22  Alan Bujtas  <[email protected]>
 
         [IFC][Integration] Rename InlineIteratorLine.cpp to InlineIteratorLineBox.cpp

Modified: trunk/Source/WebCore/Modules/storage/StorageManager.cpp (291725 => 291726)


--- trunk/Source/WebCore/Modules/storage/StorageManager.cpp	2022-03-22 23:46:50 UTC (rev 291725)
+++ trunk/Source/WebCore/Modules/storage/StorageManager.cpp	2022-03-22 23:53:16 UTC (rev 291726)
@@ -70,7 +70,10 @@
     auto* origin = context->securityOrigin();
     if (!origin)
         return Exception { InvalidStateError, "Origin is invalid"_s };
-    
+
+    if (!origin->canAccessStorageManager())
+        return Exception { TypeError, "Origin should not access storage" };
+
     if (is<Document>(context)) {
         if (auto* connection = downcast<Document>(context)->storageConnection())
             return ConnectionInfo { *connection, { context->topOrigin().data(), origin->data() } };

Modified: trunk/Source/WebCore/page/SecurityOrigin.h (291725 => 291726)


--- trunk/Source/WebCore/page/SecurityOrigin.h	2022-03-22 23:46:50 UTC (rev 291725)
+++ trunk/Source/WebCore/page/SecurityOrigin.h	2022-03-22 23:53:16 UTC (rev 291726)
@@ -149,6 +149,7 @@
     bool canAccessDatabase(const SecurityOrigin* topOrigin) const { return canAccessStorage(topOrigin); };
     bool canAccessSessionStorage(const SecurityOrigin& topOrigin) const { return canAccessStorage(&topOrigin, AlwaysAllowFromThirdParty); }
     bool canAccessLocalStorage(const SecurityOrigin* topOrigin) const { return canAccessStorage(topOrigin); };
+    bool canAccessStorageManager() const { return canAccessStorage(nullptr); }
     bool canAccessPluginStorage(const SecurityOrigin& topOrigin) const { return canAccessStorage(&topOrigin); }
     bool canAccessApplicationCache(const SecurityOrigin& topOrigin) const { return canAccessStorage(&topOrigin); }
     bool canAccessCookies() const { return !isUnique(); }
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes

Reply via email to