Chromium Code Reviews
DescriptionUse data:, rather than about:blank as a substitute form action so the resulting blank page will have an unique origin.
This is similar to the work we did in XSSAuditorDelegate for the mode=block
case, where we used the SecurityOrigin::urlWithUniqueOrign constant. We can't
use that here due to threading.
Testing is covered by rebasing the existing test cases.
BUG=331060
R=abarth@chromium.org
Committed: https://src.chromium.org/viewvc/blink?view=rev&revision=164538
Patch Set 1 #
Messages
Total messages: 4 (0 generated)
|
||||||||||||||||||||||||||||||||||||||||||||||