Branch: refs/heads/webkitglib/2.54
Home: https://github.com/WebKit/WebKit
Commit: a177813af8c85c78f2cb32b5381953bc16ad8443
https://github.com/WebKit/WebKit/commit/a177813af8c85c78f2cb32b5381953bc16ad8443
Author: John Cardullo <[email protected]>
Date: 2026-10-01 (Thu, 01 Oct 2026)
Changed paths:
M Source/WebCore/dom/DataTransfer.cpp
M Source/WebCore/dom/DataTransfer.h
M Source/WebCore/platform/glib/PasteboardGLib.cpp
Log Message:
-----------
Cherry-pick 321801@main (4b76c46dfef5).
https://bugs.webkit.org/show_bug.cgi?id=325114
[GLib][GTK] Allow pasting in-memory image data from clipboard
https://bugs.webkit.org/show_bug.cgi?id=325114
Reviewed by Michael Catanzaro and Adrian Perez de Castro.
In 303828@main (89838b9164a1), DataTransfer::allowsFileAccess() was
hardcoded to
return false on all non-Cocoa ports to mitigate CVE-2025-13947 (bug #303434)
regarding drag-and-drop file access.
However, this unintentionally broke pasting image data from the clipboard
(previously fixed in 301877@main / bug #218519), because
DataTransfer::types()
and DataTransfer::filesFromPasteboardAndItemList() suppress clipboard file
and item
access when allowsFileAccess() returns false. Pasteboard::fileContentState()
in PasteboardGLib.cpp also incorrectly returned
FileContentState::MayContainFilePaths
instead of FileContentState::InMemoryImage when an image was present on the
clipboard.
This patch:
1. Implements DataTransfer::allowsFileAccess() for GTK and WPE ports to
allow
file access during copy-and-paste (!forDrag()) when the pasteboard
content
state is Pasteboard::FileContentState::InMemoryImage. Because in-memory
images
do not reference files on disk, this does not expose local file paths and
maintains the security fix from bug #303434. Drag-and-drop file access
remains
disabled for GTK/WPE until bug #271957 is resolved.
2. Updates Pasteboard::fileContentState() in PasteboardGLib.cpp to return
FileContentState::InMemoryImage when image data is present on the
clipboard
without file paths.
* Source/WebCore/dom/DataTransfer.cpp:
(WebCore::DataTransfer::allowsFileAccess const):
* Source/WebCore/dom/DataTransfer.h:
(WebCore::DataTransfer::allowsFileAccess const):
* Source/WebCore/platform/glib/PasteboardGLib.cpp:
(WebCore::Pasteboard::fileContentState):
Canonical link: https://commits.webkit.org/321801@main
Canonical link: https://commits.webkit.org/317695.378@webkitglib/2.54
Commit: f10c36f9c8d7f9e408ce2fc4b76e75545e544502
https://github.com/WebKit/WebKit/commit/f10c36f9c8d7f9e408ce2fc4b76e75545e544502
Author: Diego Pino Garcia <[email protected]>
Date: 2026-10-01 (Thu, 01 Oct 2026)
Changed paths:
R
LayoutTests/platform/gtk/editing/pasteboard/paste-image-does-not-reveal-file-url-expected.txt
R
LayoutTests/platform/gtk/http/tests/pasteboard/copy-image-from-context-menu-expected.txt
M Source/WebCore/platform/glib/PasteboardGLib.cpp
Log Message:
-----------
Cherry-pick 322320@main (6a9025b13923).
https://bugs.webkit.org/show_bug.cgi?id=325803
[GLIB] http/tests/pasteboard/copy-image-from-context-menu.html is a
constant failure
https://bugs.webkit.org/show_bug.cgi?id=325803
Reviewed by Patrick Griffis.
After 321801@main, the number of items in WebKitGTK's clipboard became 4,
making the
test 'copy-image-from-context-menu.html' fail.
Before that change the number of items was 2, which matched the general
test baseline.
However, the MIME types of those 2 items were already different even before
321801@main
('text/uri-list' and 'text/html', instead of 'text/html' and 'image/png').
The difference in size is explained by the fact that WebKitGTK puts too
many entries
on the clipboard when copying an image. The image URL is copied together
with the
image, which adds 'text/uri-list' and 'text/plain'. Before 321801@main the
image was
not exposed in the clipboard DataTransfer. After 321801@main it is, so the
clipboard
shows 'text/uri-list', 'text/html', 'text/plain' and the image (4 items in
total).
Changeset 304166@main landed a fix for the Mac port that stopped copying
the image URL
when copying images to the clipboard. This patch implements the same change
for GLib
ports. As a consequence, the clipboard has 2 items again and their MIME
types match the
general baseline, so the WebKitGTK specific baseline should no longer be
needed.
*
LayoutTests/platform/gtk/http/tests/pasteboard/copy-image-from-context-menu-expected.txt:
Removed.
* Source/WebCore/platform/glib/PasteboardGLib.cpp:
(WebCore::Pasteboard::write(const PasteboardImage&)):
(WebCore::Pasteboard::write):
*
LayoutTests/platform/gtk/editing/pasteboard/paste-image-does-not-reveal-file-url-expected.txt:
Removed.
Canonical link: https://commits.webkit.org/322320@main
Canonical link: https://commits.webkit.org/317695.379@webkitglib/2.54
Compare: https://github.com/WebKit/WebKit/compare/c930277ca0aa...f10c36f9c8d7
To unsubscribe from these emails, change your notification settings at
https://github.com/WebKit/WebKit/settings/notifications