Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(82)

Unified Diff: extensions/browser/api/web_request/web_request_permissions.cc

Issue 1658913002: Make extensions use a correct same-origin check. (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@master
Patch Set: Created 4 years, 11 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
« no previous file with comments | « no previous file | extensions/browser/guest_view/extension_options/extension_options_guest.cc » ('j') | no next file with comments »
Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
Index: extensions/browser/api/web_request/web_request_permissions.cc
diff --git a/extensions/browser/api/web_request/web_request_permissions.cc b/extensions/browser/api/web_request/web_request_permissions.cc
index fd73304e17ace4cc22c45edd7cf531d7f07b6589..eed1b26fd85c596befbfba1239e9afdbf71a7189 100644
--- a/extensions/browser/api/web_request/web_request_permissions.cc
+++ b/extensions/browser/api/web_request/web_request_permissions.cc
@@ -15,6 +15,7 @@
#include "extensions/common/permissions/permissions_data.h"
#include "net/url_request/url_request.h"
#include "url/gurl.h"
+#include "url/origin.h"
using content::ResourceRequestInfo;
@@ -130,7 +131,8 @@ bool WebRequestPermissions::CanExtensionAccessURL(
// anyway.
if (!((url.SchemeIs(url::kAboutScheme) ||
extension->permissions_data()->HasHostPermission(url) ||
- url.GetOrigin() == extension->url()))) {
+ url::Origin(url).IsSameOriginWith(
+ url::Origin(extension->url()))))) {
meacer 2016/02/02 01:35:08 While you are at it, do you mind applying De Morga
palmer 2016/02/02 23:12:38 Good idea. But, it should be !url.SchemeIs(ur
meacer 2016/02/02 23:27:22 Sure :)
return false;
}
break;
« no previous file with comments | « no previous file | extensions/browser/guest_view/extension_options/extension_options_guest.cc » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698