Branch: refs/heads/webkitglib/2.54
  Home:   https://github.com/WebKit/WebKit
  Commit: a177813af8c85c78f2cb32b5381953bc16ad8443
      
https://github.com/WebKit/WebKit/commit/a177813af8c85c78f2cb32b5381953bc16ad8443
  Author: John Cardullo <[email protected]>
  Date:   2026-10-01 (Thu, 01 Oct 2026)

  Changed paths:
    M Source/WebCore/dom/DataTransfer.cpp
    M Source/WebCore/dom/DataTransfer.h
    M Source/WebCore/platform/glib/PasteboardGLib.cpp

  Log Message:
  -----------
  Cherry-pick 321801@main (4b76c46dfef5). 
https://bugs.webkit.org/show_bug.cgi?id=325114

    [GLib][GTK] Allow pasting in-memory image data from clipboard

    https://bugs.webkit.org/show_bug.cgi?id=325114

    Reviewed by Michael Catanzaro and Adrian Perez de Castro.

    In 303828@main (89838b9164a1), DataTransfer::allowsFileAccess() was 
hardcoded to
    return false on all non-Cocoa ports to mitigate CVE-2025-13947 (bug #303434)
    regarding drag-and-drop file access.

    However, this unintentionally broke pasting image data from the clipboard
    (previously fixed in 301877@main / bug #218519), because 
DataTransfer::types()
    and DataTransfer::filesFromPasteboardAndItemList() suppress clipboard file 
and item
    access when allowsFileAccess() returns false. Pasteboard::fileContentState()
    in PasteboardGLib.cpp also incorrectly returned 
FileContentState::MayContainFilePaths
    instead of FileContentState::InMemoryImage when an image was present on the 
clipboard.

    This patch:
    1. Implements DataTransfer::allowsFileAccess() for GTK and WPE ports to 
allow
       file access during copy-and-paste (!forDrag()) when the pasteboard 
content
       state is Pasteboard::FileContentState::InMemoryImage. Because in-memory 
images
       do not reference files on disk, this does not expose local file paths and
       maintains the security fix from bug #303434. Drag-and-drop file access 
remains
       disabled for GTK/WPE until bug #271957 is resolved.
    2. Updates Pasteboard::fileContentState() in PasteboardGLib.cpp to return
       FileContentState::InMemoryImage when image data is present on the 
clipboard
       without file paths.

    * Source/WebCore/dom/DataTransfer.cpp:
    (WebCore::DataTransfer::allowsFileAccess const):
    * Source/WebCore/dom/DataTransfer.h:
    (WebCore::DataTransfer::allowsFileAccess const):
    * Source/WebCore/platform/glib/PasteboardGLib.cpp:
    (WebCore::Pasteboard::fileContentState):

    Canonical link: https://commits.webkit.org/321801@main

Canonical link: https://commits.webkit.org/317695.378@webkitglib/2.54


  Commit: f10c36f9c8d7f9e408ce2fc4b76e75545e544502
      
https://github.com/WebKit/WebKit/commit/f10c36f9c8d7f9e408ce2fc4b76e75545e544502
  Author: Diego Pino Garcia <[email protected]>
  Date:   2026-10-01 (Thu, 01 Oct 2026)

  Changed paths:
    R 
LayoutTests/platform/gtk/editing/pasteboard/paste-image-does-not-reveal-file-url-expected.txt
    R 
LayoutTests/platform/gtk/http/tests/pasteboard/copy-image-from-context-menu-expected.txt
    M Source/WebCore/platform/glib/PasteboardGLib.cpp

  Log Message:
  -----------
  Cherry-pick 322320@main (6a9025b13923). 
https://bugs.webkit.org/show_bug.cgi?id=325803

    [GLIB] http/tests/pasteboard/copy-image-from-context-menu.html is a 
constant failure
    https://bugs.webkit.org/show_bug.cgi?id=325803

    Reviewed by Patrick Griffis.

    After 321801@main, the number of items in WebKitGTK's clipboard became 4, 
making the
    test 'copy-image-from-context-menu.html' fail.

    Before that change the number of items was 2, which matched the general 
test baseline.
    However, the MIME types of those 2 items were already different even before 
321801@main
    ('text/uri-list' and 'text/html', instead of 'text/html' and 'image/png').

    The difference in size is explained by the fact that WebKitGTK puts too 
many entries
    on the clipboard when copying an image. The image URL is copied together 
with the
    image, which adds 'text/uri-list' and 'text/plain'. Before 321801@main the 
image was
    not exposed in the clipboard DataTransfer. After 321801@main it is, so the 
clipboard
    shows 'text/uri-list', 'text/html', 'text/plain' and the image (4 items in 
total).

    Changeset 304166@main landed a fix for the Mac port that stopped copying 
the image URL
    when copying images to the clipboard. This patch implements the same change 
for GLib
    ports. As a consequence, the clipboard has 2 items again and their MIME 
types match the
    general baseline, so the WebKitGTK specific baseline should no longer be 
needed.

    * 
LayoutTests/platform/gtk/http/tests/pasteboard/copy-image-from-context-menu-expected.txt:
 Removed.
    * Source/WebCore/platform/glib/PasteboardGLib.cpp:
    (WebCore::Pasteboard::write(const PasteboardImage&)):
    (WebCore::Pasteboard::write):
    * 
LayoutTests/platform/gtk/editing/pasteboard/paste-image-does-not-reveal-file-url-expected.txt:
 Removed.

    Canonical link: https://commits.webkit.org/322320@main

Canonical link: https://commits.webkit.org/317695.379@webkitglib/2.54


Compare: https://github.com/WebKit/WebKit/compare/c930277ca0aa...f10c36f9c8d7

To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to