| Index: content/browser/renderer_host/database_message_filter.cc
|
| ===================================================================
|
| --- content/browser/renderer_host/database_message_filter.cc (revision 183642)
|
| +++ content/browser/renderer_host/database_message_filter.cc (working copy)
|
| @@ -284,6 +284,13 @@
|
| const string16& description,
|
| int64 estimated_size) {
|
| DCHECK(BrowserThread::CurrentlyOn(BrowserThread::FILE));
|
| +
|
| + if (!DatabaseUtil::IsValidOriginIdentifier(origin_identifier)) {
|
| + RecordAction(UserMetricsAction("BadMessageTerminate_DBMF"));
|
| + BadMessageReceived();
|
| + return;
|
| + }
|
| +
|
| int64 database_size = 0;
|
| db_tracker_->DatabaseOpened(origin_identifier, database_name, description,
|
| estimated_size, &database_size);
|
| @@ -325,6 +332,12 @@
|
| const string16& database_name,
|
| int error) {
|
| DCHECK(BrowserThread::CurrentlyOn(BrowserThread::FILE));
|
| + if (!DatabaseUtil::IsValidOriginIdentifier(origin_identifier)) {
|
| + RecordAction(UserMetricsAction("BadMessageTerminate_DBMF"));
|
| + BadMessageReceived();
|
| + return;
|
| + }
|
| +
|
| db_tracker_->HandleSqliteError(origin_identifier, database_name, error);
|
| }
|
|
|
|
|