Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(3588)

Unified Diff: extensions/browser/guest_view/extension_view/extension_view_guest.cc

Issue 1658913002: Make extensions use a correct same-origin check. (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@master
Patch Set: Created 4 years, 11 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: extensions/browser/guest_view/extension_view/extension_view_guest.cc
diff --git a/extensions/browser/guest_view/extension_view/extension_view_guest.cc b/extensions/browser/guest_view/extension_view/extension_view_guest.cc
index d2db41e00959a7bd5ea331f60d4c08ee333ab3e8..b4858668c92efbf0a092c466de35365eb48dec24 100644
--- a/extensions/browser/guest_view/extension_view/extension_view_guest.cc
+++ b/extensions/browser/guest_view/extension_view/extension_view_guest.cc
@@ -17,6 +17,7 @@
#include "extensions/common/constants.h"
#include "extensions/common/extension_messages.h"
#include "extensions/strings/grit/extensions_strings.h"
+#include "url/origin.h"
using content::WebContents;
using guest_view::GuestViewBase;
@@ -45,8 +46,9 @@ bool ExtensionViewGuest::NavigateGuest(const std::string& src,
// If the URL is not valid, about:blank, or the same origin as the extension,
// then navigate to about:blank.
- bool url_not_allowed = (url != GURL(url::kAboutBlankURL)) &&
- (url.GetOrigin() != extension_url_.GetOrigin());
+ bool url_not_allowed =
+ url != GURL(url::kAboutBlankURL) &&
+ !url::Origin(url).IsSameOriginWith(url::Origin(extension_url_));
if (!url.is_valid() || url_not_allowed)
return NavigateGuest(url::kAboutBlankURL, true /* force_navigation */);
@@ -135,7 +137,8 @@ void ExtensionViewGuest::DidCommitProvisionalLoadForFrame(
void ExtensionViewGuest::DidNavigateMainFrame(
const content::LoadCommittedDetails& details,
const content::FrameNavigateParams& params) {
- if (attached() && (params.url.GetOrigin() != url_.GetOrigin())) {
+ if (attached() &&
+ !url::Origin(params.url).IsSameOriginWith(url::Origin(url_))) {
bad_message::ReceivedBadMessage(web_contents()->GetRenderProcessHost(),
bad_message::EVG_BAD_ORIGIN);
}

Powered by Google App Engine
This is Rietveld 408576698