Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(763)

Issue 1704713002: Fix issue security issue in Gold (Closed)

Created:
4 years, 10 months ago by stephana
Modified:
4 years, 10 months ago
Reviewers:
jcgregorio, dogben
CC:
reviews_skia.org
Base URL:
https://skia.googlesource.com/buildbot@master
Target Ref:
refs/heads/master
Visibility:
Public.

Description

Fix issue security issue in Gold To reliably fix internal b/26768421 (not just in gold) we need to wrap the error response in JSON object instead of returning a string. BUG=skia: Committed: https://skia.googlesource.com/buildbot/+/6753a5174a9a78020a328298a4fd45507090bfc3

Patch Set 1 #

Patch Set 2 : Added more headers to prevent XSS #

Patch Set 3 : #

Patch Set 4 : Fixed poller_test #

Unified diffs Side-by-side diffs Delta from patch set Stats (+2 lines, -2 lines) Patch
M ct/go/poller/poller_test.go View 1 2 3 1 chunk +1 line, -1 line 0 comments Download
M go/util/http.go View 1 2 1 chunk +1 line, -1 line 0 comments Download

Messages

Total messages: 24 (11 generated)
commit-bot: I haz the power
Dry run: CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/patch-status/1704713002/1 View timeline at https://chromium-cq-status.appspot.com/patch-timeline/1704713002/1
4 years, 10 months ago (2016-02-16 22:45:31 UTC) #2
commit-bot: I haz the power
Dry run: Try jobs failed on following builders: Infra-PerCommit-Trybot on client.skia.fyi (JOB_FAILED, http://build.chromium.org/p/client.skia.fyi/builders/Infra-PerCommit-Trybot/builds/3100)
4 years, 10 months ago (2016-02-16 22:49:53 UTC) #6
stephana
PTAL: I cannot think of a better way to address this issue in general. I ...
4 years, 10 months ago (2016-02-16 22:50:24 UTC) #7
dogben
I'm not sure that JSON responses are safe either. See the link in the bug ...
4 years, 10 months ago (2016-02-16 23:49:50 UTC) #9
stephana
On 2016/02/16 23:49:50, Ben Wagner wrote: > I'm not sure that JSON responses are safe ...
4 years, 10 months ago (2016-02-17 03:15:03 UTC) #10
jcgregorio
On 2016/02/17 at 03:15:03, stephana wrote: > On 2016/02/16 23:49:50, Ben Wagner wrote: > > ...
4 years, 10 months ago (2016-02-17 14:41:19 UTC) #11
stephana
On 2016/02/17 14:41:19, jcgregorio wrote: > On 2016/02/17 at 03:15:03, stephana wrote: > > On ...
4 years, 10 months ago (2016-02-17 15:21:25 UTC) #12
stephana
On 2016/02/17 14:41:19, jcgregorio wrote: > On 2016/02/17 at 03:15:03, stephana wrote: > > On ...
4 years, 10 months ago (2016-02-17 15:21:30 UTC) #13
jcgregorio
lgtm
4 years, 10 months ago (2016-02-17 15:23:00 UTC) #14
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/patch-status/1704713002/40001 View timeline at https://chromium-cq-status.appspot.com/patch-timeline/1704713002/40001
4 years, 10 months ago (2016-02-17 21:06:17 UTC) #17
commit-bot: I haz the power
Try jobs failed on following builders: Infra-PerCommit-Trybot on client.skia.fyi (JOB_FAILED, http://build.chromium.org/p/client.skia.fyi/builders/Infra-PerCommit-Trybot/builds/3112)
4 years, 10 months ago (2016-02-17 21:12:28 UTC) #19
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/patch-status/1704713002/60001 View timeline at https://chromium-cq-status.appspot.com/patch-timeline/1704713002/60001
4 years, 10 months ago (2016-02-18 14:46:01 UTC) #22
commit-bot: I haz the power
4 years, 10 months ago (2016-02-18 14:52:30 UTC) #24
Message was sent while issue was closed.
Committed patchset #4 (id:60001) as
https://skia.googlesource.com/buildbot/+/6753a5174a9a78020a328298a4fd45507090...

Powered by Google App Engine
This is Rietveld 408576698