Title: [130657] trunk
Revision
130657
Author
[email protected]
Date
2012-10-08 11:15:01 -0700 (Mon, 08 Oct 2012)

Log Message

Null-check for DOMWindow before feeding it to FeatureObserver.
https://bugs.webkit.org/show_bug.cgi?id=98624

Reviewed by Adam Barth.

Source/WebCore:

We shouldn't call out to FeatureObserver in
ContentSecurityPolicy::didReceiveHeader if the policy's document doesn't
have a DOMWindow.

Test: http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash.html

* page/ContentSecurityPolicy.cpp:
(WebCore::ContentSecurityPolicy::didReceiveHeader):
    Null check 'document->domWindow' before passing it on.
* page/FeatureObserver.cpp:
(WebCore::FeatureObserver::observe):
    ASSERT 'domWindow'.

LayoutTests:

* http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash-expected.txt: Added.
* http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash.html: Added.
    This test shouldn't crash.

Modified Paths

Added Paths

Diff

Modified: trunk/LayoutTests/ChangeLog (130656 => 130657)


--- trunk/LayoutTests/ChangeLog	2012-10-08 18:10:17 UTC (rev 130656)
+++ trunk/LayoutTests/ChangeLog	2012-10-08 18:15:01 UTC (rev 130657)
@@ -1,3 +1,14 @@
+2012-10-08  Mike West  <[email protected]>
+
+        Null-check for DOMWindow before feeding it to FeatureObserver.
+        https://bugs.webkit.org/show_bug.cgi?id=98624
+
+        Reviewed by Adam Barth.
+
+        * http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash-expected.txt: Added.
+        * http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash.html: Added.
+            This test shouldn't crash.
+
 2012-10-08  Tony Chang  <[email protected]>
 
         Unreviewed, new baseline for fast/table/colspanMinWidth-vertical.html.

Added: trunk/LayoutTests/http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash-expected.txt (0 => 130657)


--- trunk/LayoutTests/http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash-expected.txt	                        (rev 0)
+++ trunk/LayoutTests/http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash-expected.txt	2012-10-08 18:15:01 UTC (rev 130657)
@@ -0,0 +1,2 @@
+PASS: [object HTMLDocument]
+Loading a frameless document (like those generated via XMLHttpRequest) shouldn't crash the CSP parser.

Added: trunk/LayoutTests/http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash.html (0 => 130657)


--- trunk/LayoutTests/http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash.html	                        (rev 0)
+++ trunk/LayoutTests/http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash.html	2012-10-08 18:15:01 UTC (rev 130657)
@@ -0,0 +1,35 @@
+<!DOCTYPE html>
+<html>
+  <head>
+    <script>
+      if (window.testRunner) {
+          testRunner.dumpAsText();
+          testRunner.waitUntilDone();
+      }
+    </script>
+  </head>
+  <body>
+    <pre id="console"></pre>
+    <script>
+      function log(msg)
+      {
+          document.getElementById("console").appendChild(document.createTextNode(msg + "\n"));
+      }
+
+      var protectedResource = "http://127.0.0.1:8000/security/contentSecurityPolicy/resources/generate-csp-report.html";
+      var xhr = new XMLHttpRequest();
+      xhr.responseType = "document";
+      xhr._onreadystatechange_ = function () {
+        if (xhr.readyState == 4) {
+          log("PASS: " + this.response);
+          if (window.testRunner)
+              testRunner.notifyDone();
+        }
+      };
+      xhr.open("GET", protectedResource, true);
+      xhr.send();
+    </script>
+    <p>Loading a frameless document (like those generated via XMLHttpRequest)
+    shouldn't crash the CSP parser.</p>
+  </body>
+</html>

Modified: trunk/Source/WebCore/ChangeLog (130656 => 130657)


--- trunk/Source/WebCore/ChangeLog	2012-10-08 18:10:17 UTC (rev 130656)
+++ trunk/Source/WebCore/ChangeLog	2012-10-08 18:15:01 UTC (rev 130657)
@@ -1,3 +1,23 @@
+2012-10-08  Mike West  <[email protected]>
+
+        Null-check for DOMWindow before feeding it to FeatureObserver.
+        https://bugs.webkit.org/show_bug.cgi?id=98624
+
+        Reviewed by Adam Barth.
+
+        We shouldn't call out to FeatureObserver in
+        ContentSecurityPolicy::didReceiveHeader if the policy's document doesn't
+        have a DOMWindow.
+
+        Test: http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash.html
+
+        * page/ContentSecurityPolicy.cpp:
+        (WebCore::ContentSecurityPolicy::didReceiveHeader):
+            Null check 'document->domWindow' before passing it on.
+        * page/FeatureObserver.cpp:
+        (WebCore::FeatureObserver::observe):
+            ASSERT 'domWindow'.
+
 2012-10-08  Nate Chapin  <[email protected]>
 
         Loader cleanup : Simplify FrameLoader/DocumentLoader setupForReplace()

Modified: trunk/Source/WebCore/page/ContentSecurityPolicy.cpp (130656 => 130657)


--- trunk/Source/WebCore/page/ContentSecurityPolicy.cpp	2012-10-08 18:10:17 UTC (rev 130656)
+++ trunk/Source/WebCore/page/ContentSecurityPolicy.cpp	2012-10-08 18:15:01 UTC (rev 130657)
@@ -1306,7 +1306,8 @@
 {
     if (m_scriptExecutionContext->isDocument()) {
         Document* document = static_cast<Document*>(m_scriptExecutionContext);
-        FeatureObserver::observe(document->domWindow(), FeatureObserver::PrefixedContentSecurityPolicy);
+        if (document->domWindow())
+            FeatureObserver::observe(document->domWindow(), FeatureObserver::PrefixedContentSecurityPolicy);
     }
 
     // RFC2616, section 4.2 specifies that headers appearing multiple times can

Modified: trunk/Source/WebCore/page/FeatureObserver.cpp (130656 => 130657)


--- trunk/Source/WebCore/page/FeatureObserver.cpp	2012-10-08 18:10:17 UTC (rev 130656)
+++ trunk/Source/WebCore/page/FeatureObserver.cpp	2012-10-08 18:15:01 UTC (rev 130657)
@@ -54,6 +54,8 @@
 
 void FeatureObserver::observe(DOMWindow* domWindow, Feature feature)
 {
+    ASSERT(domWindow);
+
     Document* document = domWindow->document();
     if (!document)
         return;
_______________________________________________
webkit-changes mailing list
[email protected]
http://lists.webkit.org/mailman/listinfo/webkit-changes

Reply via email to