Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(461)

Unified Diff: chrome/renderer/extensions/extension_resource_request_policy.cc

Issue 8849010: Add 'web_accessible_resource" keyword for version 2 extension manifests. This makes extension res... (Closed) Base URL: svn://chrome-svn/chrome/trunk/src/
Patch Set: '' Created 9 years ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: chrome/renderer/extensions/extension_resource_request_policy.cc
===================================================================
--- chrome/renderer/extensions/extension_resource_request_policy.cc (revision 113054)
+++ chrome/renderer/extensions/extension_resource_request_policy.cc (working copy)
@@ -38,6 +38,15 @@
return false;
}
+ // Disallow loading of extension resources which are not explicitely listed
+ // as web accessible if the manifest version is 2 or greater.
+ if (extension->manifest_version() >= 2 &&
+ !extension->CanWebAccessResource(resource_url.path())) {
+ LOG(ERROR) << "Denying load of " << resource_url.spec() << " which "
+ << "is not a web accessible resource.";
+ return false;
+ }
+
return true;
}

Powered by Google App Engine
This is Rietveld 408576698