Branch: refs/heads/main
Home: https://github.com/WebKit/WebKit
Commit: 62614d87c068947096fbc7515a50fbe316d3d92a
https://github.com/WebKit/WebKit/commit/62614d87c068947096fbc7515a50fbe316d3d92a
Author: Roberto Rodriguez <[email protected]>
Date: 2026-10-01 (Thu, 01 Oct 2026)
Changed paths:
A
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-createhtmldocument-adopt-expected.txt
A
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-createhtmldocument-adopt.html
A
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-domparser-adopt-expected.txt
A
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-domparser-adopt.html
A
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-template-move-expected.txt
A
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-template-move.html
M Source/WebCore/dom/StyledElement.cpp
M Source/WebCore/dom/StyledElement.h
Log Message:
-----------
CSP style-src-attr does not block a style attribute parsed in a document with
no browsing context
https://bugs.webkit.org/show_bug.cgi?id=322934
rdar://186196093
Reviewed by Anne van Kesteren.
StyledElement::styleAttributeChanged() checks a style attribute against the
policy of the
element's own document when the attribute is set. A document created by
DOMParser,
createHTMLDocument or a template has no browsing context and starts with an
empty policy,
so the check allows the attribute and the parsed style stays on the element.
When the
element moves into a page whose policy sets style-src-attr to none, nothing
checks the
style again and it is applied. CSP Level 3 4.2.3 defines this check, and HTML
section
3.2.6.5 requires that blocked style rules are not applied to the element.
Fix by checking the style attribute against the policy of the document returned
by
contextDocument(). That is the document recorded as the creator of a DOMParser
result,
a createHTMLDocument document or template contents, and the element's own
document when
none is recorded. Add three web-platform tests for the DOMParser,
createHTMLDocument
and template paths.
Tests:
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-createhtmldocument-adopt.html
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-domparser-adopt.html
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-template-move.html
*
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-createhtmldocument-adopt-expected.txt:
Added.
*
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-createhtmldocument-adopt.html:
Added.
*
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-domparser-adopt-expected.txt:
Added.
*
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-domparser-adopt.html:
Added.
*
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-template-move-expected.txt:
Added.
*
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-template-move.html:
Added.
* Source/WebCore/dom/StyledElement.cpp:
(WebCore::StyledElement::isStyleAttributeAllowedByContentSecurityPolicy):
(WebCore::StyledElement::styleAttributeChanged):
* Source/WebCore/dom/StyledElement.h:
Canonical link: https://commits.webkit.org/322461@main
To unsubscribe from these emails, change your notification settings at
https://github.com/WebKit/WebKit/settings/notifications