Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: 62614d87c068947096fbc7515a50fbe316d3d92a
      
https://github.com/WebKit/WebKit/commit/62614d87c068947096fbc7515a50fbe316d3d92a
  Author: Roberto Rodriguez <[email protected]>
  Date:   2026-10-01 (Thu, 01 Oct 2026)

  Changed paths:
    A 
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-createhtmldocument-adopt-expected.txt
    A 
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-createhtmldocument-adopt.html
    A 
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-domparser-adopt-expected.txt
    A 
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-domparser-adopt.html
    A 
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-template-move-expected.txt
    A 
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-template-move.html
    M Source/WebCore/dom/StyledElement.cpp
    M Source/WebCore/dom/StyledElement.h

  Log Message:
  -----------
  CSP style-src-attr does not block a style attribute parsed in a document with 
no browsing context
https://bugs.webkit.org/show_bug.cgi?id=322934
rdar://186196093

Reviewed by Anne van Kesteren.

StyledElement::styleAttributeChanged() checks a style attribute against the 
policy of the
element's own document when the attribute is set. A document created by 
DOMParser,
createHTMLDocument or a template has no browsing context and starts with an 
empty policy,
so the check allows the attribute and the parsed style stays on the element. 
When the
element moves into a page whose policy sets style-src-attr to none, nothing 
checks the
style again and it is applied. CSP Level 3 4.2.3 defines this check, and HTML 
section
3.2.6.5 requires that blocked style rules are not applied to the element.

Fix by checking the style attribute against the policy of the document returned 
by
contextDocument(). That is the document recorded as the creator of a DOMParser 
result,
a createHTMLDocument document or template contents, and the element's own 
document when
none is recorded. Add three web-platform tests for the DOMParser, 
createHTMLDocument
and template paths.

Tests: 
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-createhtmldocument-adopt.html
       
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-domparser-adopt.html
       
imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-template-move.html

* 
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-createhtmldocument-adopt-expected.txt:
 Added.
* 
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-createhtmldocument-adopt.html:
 Added.
* 
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-domparser-adopt-expected.txt:
 Added.
* 
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-domparser-adopt.html:
 Added.
* 
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-template-move-expected.txt:
 Added.
* 
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/style-src/style-src-attr-blocked-template-move.html:
 Added.
* Source/WebCore/dom/StyledElement.cpp:
(WebCore::StyledElement::isStyleAttributeAllowedByContentSecurityPolicy):
(WebCore::StyledElement::styleAttributeChanged):
* Source/WebCore/dom/StyledElement.h:

Canonical link: https://commits.webkit.org/322461@main



To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to