Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(219)

Side by Side Diff: third_party/WebKit/Source/core/dom/Document.cpp

Issue 1507023004: Harden the implementation of '--disable-web-security' (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@master
Patch Set: exclude //content/shell Created 5 years ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
OLDNEW
1 /* 1 /*
2 * Copyright (C) 1999 Lars Knoll (knoll@kde.org) 2 * Copyright (C) 1999 Lars Knoll (knoll@kde.org)
3 * (C) 1999 Antti Koivisto (koivisto@kde.org) 3 * (C) 1999 Antti Koivisto (koivisto@kde.org)
4 * (C) 2001 Dirk Mueller (mueller@kde.org) 4 * (C) 2001 Dirk Mueller (mueller@kde.org)
5 * (C) 2006 Alexey Proskuryakov (ap@webkit.org) 5 * (C) 2006 Alexey Proskuryakov (ap@webkit.org)
6 * Copyright (C) 2004, 2005, 2006, 2007, 2008, 2009, 2011, 2012 Apple Inc. All r ights reserved. 6 * Copyright (C) 2004, 2005, 2006, 2007, 2008, 2009, 2011, 2012 Apple Inc. All r ights reserved.
7 * Copyright (C) 2008, 2009 Torch Mobile Inc. All rights reserved. (http://www.t orchmobile.com/) 7 * Copyright (C) 2008, 2009 Torch Mobile Inc. All rights reserved. (http://www.t orchmobile.com/)
8 * Copyright (C) 2008, 2009, 2011, 2012 Google Inc. All rights reserved. 8 * Copyright (C) 2008, 2009, 2011, 2012 Google Inc. All rights reserved.
9 * Copyright (C) 2010 Nokia Corporation and/or its subsidiary(-ies) 9 * Copyright (C) 2010 Nokia Corporation and/or its subsidiary(-ies)
10 * Copyright (C) Research In Motion Limited 2010-2011. All rights reserved. 10 * Copyright (C) Research In Motion Limited 2010-2011. All rights reserved.
(...skipping 4775 matching lines...) Expand 10 before | Expand all | Expand 10 after
4786 } 4786 }
4787 4787
4788 if (Settings* settings = initializer.settings()) { 4788 if (Settings* settings = initializer.settings()) {
4789 if (!settings->webSecurityEnabled()) { 4789 if (!settings->webSecurityEnabled()) {
4790 // Web security is turned off. We should let this document access ev ery other document. This is used primary by testing 4790 // Web security is turned off. We should let this document access ev ery other document. This is used primary by testing
4791 // harnesses for web sites. 4791 // harnesses for web sites.
4792 securityOrigin()->grantUniversalAccess(); 4792 securityOrigin()->grantUniversalAccess();
4793 } else if (securityOrigin()->isLocal()) { 4793 } else if (securityOrigin()->isLocal()) {
4794 if (settings->allowUniversalAccessFromFileURLs()) { 4794 if (settings->allowUniversalAccessFromFileURLs()) {
4795 // Some clients want local URLs to have universal access, but th at setting is dangerous for other clients. 4795 // Some clients want local URLs to have universal access, but th at setting is dangerous for other clients.
4796 securityOrigin()->grantUniversalAccess(); 4796 securityOrigin()->grantUniversalAccessForFileOrigins();
4797 } else if (!settings->allowFileAccessFromFileURLs()) { 4797 } else if (!settings->allowFileAccessFromFileURLs()) {
4798 // Some clients do not want local URLs to have access to other l ocal URLs. 4798 // Some clients do not want local URLs to have access to other l ocal URLs.
4799 securityOrigin()->blockLocalAccessFromLocalOrigin(); 4799 securityOrigin()->blockLocalAccessFromLocalOrigin();
4800 } 4800 }
4801 } 4801 }
4802 } 4802 }
4803 4803
4804 if (initializer.shouldTreatURLAsSrcdocDocument()) { 4804 if (initializer.shouldTreatURLAsSrcdocDocument()) {
4805 m_isSrcdocDocument = true; 4805 m_isSrcdocDocument = true;
4806 setBaseURLOverride(initializer.parentBaseURL()); 4806 setBaseURLOverride(initializer.parentBaseURL());
(...skipping 1021 matching lines...) Expand 10 before | Expand all | Expand 10 after
5828 #ifndef NDEBUG 5828 #ifndef NDEBUG
5829 using namespace blink; 5829 using namespace blink;
5830 void showLiveDocumentInstances() 5830 void showLiveDocumentInstances()
5831 { 5831 {
5832 Document::WeakDocumentSet& set = Document::liveDocumentSet(); 5832 Document::WeakDocumentSet& set = Document::liveDocumentSet();
5833 fprintf(stderr, "There are %u documents currently alive:\n", set.size()); 5833 fprintf(stderr, "There are %u documents currently alive:\n", set.size());
5834 for (Document* document : set) 5834 for (Document* document : set)
5835 fprintf(stderr, "- Document %p URL: %s\n", document, document->url().str ing().utf8().data()); 5835 fprintf(stderr, "- Document %p URL: %s\n", document, document->url().str ing().utf8().data());
5836 } 5836 }
5837 #endif 5837 #endif
OLDNEW

Powered by Google App Engine
This is Rietveld 408576698