Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(387)

Unified Diff: Source/core/css/CSSFontFaceSrcValue.cpp

Issue 1250793008: Webfont fetch should be CORS-enabled even for same-origin URL (Closed) Base URL: https://chromium.googlesource.com/chromium/blink.git@master
Patch Set: Created 5 years, 5 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
« no previous file with comments | « Source/core/css/CSSFontFaceSrcValue.h ('k') | no next file » | no next file with comments »
Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
Index: Source/core/css/CSSFontFaceSrcValue.cpp
diff --git a/Source/core/css/CSSFontFaceSrcValue.cpp b/Source/core/css/CSSFontFaceSrcValue.cpp
index 3f1fe5c89684800770c640b65c97dd71ae2d5c01..5b4751bab5c7062d3e05a92dc4839c0f659daa46 100644
--- a/Source/core/css/CSSFontFaceSrcValue.cpp
+++ b/Source/core/css/CSSFontFaceSrcValue.cpp
@@ -73,22 +73,13 @@ bool CSSFontFaceSrcValue::hasFailedOrCanceledSubresources() const
return m_fetched && m_fetched->loadFailedOrCanceled();
}
-bool CSSFontFaceSrcValue::shouldSetCrossOriginAccessControl(const KURL& resource, SecurityOrigin* securityOrigin)
-{
- if (resource.isLocalFile() || resource.protocolIsData())
- return false;
- return !securityOrigin->canRequestNoSuborigin(resource);
-}
-
FontResource* CSSFontFaceSrcValue::fetch(Document* document)
{
if (!m_fetched) {
FetchRequest request(ResourceRequest(document->completeURL(m_resource)), FetchInitiatorTypeNames::css);
request.setContentSecurityCheck(m_shouldCheckContentSecurityPolicy);
SecurityOrigin* securityOrigin = document->securityOrigin();
- if (shouldSetCrossOriginAccessControl(request.url(), securityOrigin)) {
- request.setCrossOriginAccessControl(securityOrigin, DoNotAllowStoredCredentials);
- }
+ request.setCrossOriginAccessControl(securityOrigin, DoNotAllowStoredCredentials);
request.mutableResourceRequest().setHTTPReferrer(SecurityPolicy::generateReferrer(m_referrer.referrerPolicy, request.url(), m_referrer.referrer));
m_fetched = FontResource::fetch(request, document->fetcher());
} else {
« no previous file with comments | « Source/core/css/CSSFontFaceSrcValue.h ('k') | no next file » | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698