Title: [130657] trunk
- Revision
- 130657
- Author
- [email protected]
- Date
- 2012-10-08 11:15:01 -0700 (Mon, 08 Oct 2012)
Log Message
Null-check for DOMWindow before feeding it to FeatureObserver.
https://bugs.webkit.org/show_bug.cgi?id=98624
Reviewed by Adam Barth.
Source/WebCore:
We shouldn't call out to FeatureObserver in
ContentSecurityPolicy::didReceiveHeader if the policy's document doesn't
have a DOMWindow.
Test: http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash.html
* page/ContentSecurityPolicy.cpp:
(WebCore::ContentSecurityPolicy::didReceiveHeader):
Null check 'document->domWindow' before passing it on.
* page/FeatureObserver.cpp:
(WebCore::FeatureObserver::observe):
ASSERT 'domWindow'.
LayoutTests:
* http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash-expected.txt: Added.
* http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash.html: Added.
This test shouldn't crash.
Modified Paths
Added Paths
Diff
Modified: trunk/LayoutTests/ChangeLog (130656 => 130657)
--- trunk/LayoutTests/ChangeLog 2012-10-08 18:10:17 UTC (rev 130656)
+++ trunk/LayoutTests/ChangeLog 2012-10-08 18:15:01 UTC (rev 130657)
@@ -1,3 +1,14 @@
+2012-10-08 Mike West <[email protected]>
+
+ Null-check for DOMWindow before feeding it to FeatureObserver.
+ https://bugs.webkit.org/show_bug.cgi?id=98624
+
+ Reviewed by Adam Barth.
+
+ * http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash-expected.txt: Added.
+ * http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash.html: Added.
+ This test shouldn't crash.
+
2012-10-08 Tony Chang <[email protected]>
Unreviewed, new baseline for fast/table/colspanMinWidth-vertical.html.
Added: trunk/LayoutTests/http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash-expected.txt (0 => 130657)
--- trunk/LayoutTests/http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash-expected.txt (rev 0)
+++ trunk/LayoutTests/http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash-expected.txt 2012-10-08 18:15:01 UTC (rev 130657)
@@ -0,0 +1,2 @@
+PASS: [object HTMLDocument]
+Loading a frameless document (like those generated via XMLHttpRequest) shouldn't crash the CSP parser.
Added: trunk/LayoutTests/http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash.html (0 => 130657)
--- trunk/LayoutTests/http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash.html (rev 0)
+++ trunk/LayoutTests/http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash.html 2012-10-08 18:15:01 UTC (rev 130657)
@@ -0,0 +1,35 @@
+<!DOCTYPE html>
+<html>
+ <head>
+ <script>
+ if (window.testRunner) {
+ testRunner.dumpAsText();
+ testRunner.waitUntilDone();
+ }
+ </script>
+ </head>
+ <body>
+ <pre id="console"></pre>
+ <script>
+ function log(msg)
+ {
+ document.getElementById("console").appendChild(document.createTextNode(msg + "\n"));
+ }
+
+ var protectedResource = "http://127.0.0.1:8000/security/contentSecurityPolicy/resources/generate-csp-report.html";
+ var xhr = new XMLHttpRequest();
+ xhr.responseType = "document";
+ xhr._onreadystatechange_ = function () {
+ if (xhr.readyState == 4) {
+ log("PASS: " + this.response);
+ if (window.testRunner)
+ testRunner.notifyDone();
+ }
+ };
+ xhr.open("GET", protectedResource, true);
+ xhr.send();
+ </script>
+ <p>Loading a frameless document (like those generated via XMLHttpRequest)
+ shouldn't crash the CSP parser.</p>
+ </body>
+</html>
Modified: trunk/Source/WebCore/ChangeLog (130656 => 130657)
--- trunk/Source/WebCore/ChangeLog 2012-10-08 18:10:17 UTC (rev 130656)
+++ trunk/Source/WebCore/ChangeLog 2012-10-08 18:15:01 UTC (rev 130657)
@@ -1,3 +1,23 @@
+2012-10-08 Mike West <[email protected]>
+
+ Null-check for DOMWindow before feeding it to FeatureObserver.
+ https://bugs.webkit.org/show_bug.cgi?id=98624
+
+ Reviewed by Adam Barth.
+
+ We shouldn't call out to FeatureObserver in
+ ContentSecurityPolicy::didReceiveHeader if the policy's document doesn't
+ have a DOMWindow.
+
+ Test: http/tests/security/contentSecurityPolicy/xmlhttprequest-protected-resource-does-not-crash.html
+
+ * page/ContentSecurityPolicy.cpp:
+ (WebCore::ContentSecurityPolicy::didReceiveHeader):
+ Null check 'document->domWindow' before passing it on.
+ * page/FeatureObserver.cpp:
+ (WebCore::FeatureObserver::observe):
+ ASSERT 'domWindow'.
+
2012-10-08 Nate Chapin <[email protected]>
Loader cleanup : Simplify FrameLoader/DocumentLoader setupForReplace()
Modified: trunk/Source/WebCore/page/ContentSecurityPolicy.cpp (130656 => 130657)
--- trunk/Source/WebCore/page/ContentSecurityPolicy.cpp 2012-10-08 18:10:17 UTC (rev 130656)
+++ trunk/Source/WebCore/page/ContentSecurityPolicy.cpp 2012-10-08 18:15:01 UTC (rev 130657)
@@ -1306,7 +1306,8 @@
{
if (m_scriptExecutionContext->isDocument()) {
Document* document = static_cast<Document*>(m_scriptExecutionContext);
- FeatureObserver::observe(document->domWindow(), FeatureObserver::PrefixedContentSecurityPolicy);
+ if (document->domWindow())
+ FeatureObserver::observe(document->domWindow(), FeatureObserver::PrefixedContentSecurityPolicy);
}
// RFC2616, section 4.2 specifies that headers appearing multiple times can
Modified: trunk/Source/WebCore/page/FeatureObserver.cpp (130656 => 130657)
--- trunk/Source/WebCore/page/FeatureObserver.cpp 2012-10-08 18:10:17 UTC (rev 130656)
+++ trunk/Source/WebCore/page/FeatureObserver.cpp 2012-10-08 18:15:01 UTC (rev 130657)
@@ -54,6 +54,8 @@
void FeatureObserver::observe(DOMWindow* domWindow, Feature feature)
{
+ ASSERT(domWindow);
+
Document* document = domWindow->document();
if (!document)
return;
_______________________________________________
webkit-changes mailing list
[email protected]
http://lists.webkit.org/mailman/listinfo/webkit-changes