Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(291)

Unified Diff: third_party/WebKit/Source/core/html/HTMLImageElement.cpp

Issue 1532473002: Add a origin clean flag in ImageBitmap class (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@master
Patch Set: Created 5 years ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: third_party/WebKit/Source/core/html/HTMLImageElement.cpp
diff --git a/third_party/WebKit/Source/core/html/HTMLImageElement.cpp b/third_party/WebKit/Source/core/html/HTMLImageElement.cpp
index 858b47ac3fcf904668c8797fc5d24b541e5e6fc5..4f6361b01b3853d8f03de67340e43b253b504aa2 100644
--- a/third_party/WebKit/Source/core/html/HTMLImageElement.cpp
+++ b/third_party/WebKit/Source/core/html/HTMLImageElement.cpp
@@ -700,16 +700,10 @@ ScriptPromise HTMLImageElement::createImageBitmap(ScriptState* scriptState, Even
exceptionState.throwDOMException(IndexSizeError, String::format("The source %s provided is 0.", sw ? "height" : "width"));
return ScriptPromise();
}
- if (!cachedImage()->image()->currentFrameHasSingleSecurityOrigin()) {
- exceptionState.throwSecurityError("The source image contains image data from multiple origins.");
- return ScriptPromise();
- }
Document* document = eventTarget.toDOMWindow()->document();
- if (!cachedImage()->passesAccessControlCheck(document->securityOrigin()) && document->securityOrigin()->taintsCanvas(src())) {
- exceptionState.throwSecurityError("Cross-origin access to the source image is denied.");
- return ScriptPromise();
- }
- return ImageBitmapSource::fulfillImageBitmap(scriptState, ImageBitmap::create(this, IntRect(sx, sy, sw, sh)));
+ return ImageBitmapSource::fulfillImageBitmap(scriptState, ImageBitmap::create(this, IntRect(sx, sy, sw, sh),
+ !(!cachedImage()->image()->currentFrameHasSingleSecurityOrigin()
+ || (!cachedImage()->passesAccessControlCheck(document->securityOrigin()) && document->securityOrigin()->taintsCanvas(src())))));
}
void HTMLImageElement::selectSourceURL(ImageLoader::UpdateFromElementBehavior behavior)

Powered by Google App Engine
This is Rietveld 408576698