Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(98)

Issue 1770313004: Not saving whitelist icon paths that reference the parent. (Closed)

Created:
4 years, 9 months ago by atanasova
Modified:
4 years, 9 months ago
CC:
chromium-reviews, pam+watch_chromium.org, Bernhard Bauer
Base URL:
https://chromium.googlesource.com/chromium/src.git@master
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

Not saving whitelist icon paths that reference the parent. If the icon path that we get from the manifest contains a reference to the parent directory ("..") we would not save it and associate with the whitelist. This is done in order to avoid malicious access to parent folders. Committed: https://crrev.com/6b03d171d4137691637129ebad5cab20f4babbbb Cr-Commit-Position: refs/heads/master@{#381557}

Patch Set 1 #

Total comments: 3

Patch Set 2 : #

Total comments: 2

Patch Set 3 : Addressing Bernhard's comment #

Unified diffs Side-by-side diffs Delta from patch set Stats (+18 lines, -16 lines) Patch
M chrome/browser/component_updater/supervised_user_whitelist_installer.cc View 1 2 1 chunk +18 lines, -16 lines 0 comments Download

Messages

Total messages: 20 (8 generated)
atanasova
4 years, 9 months ago (2016-03-09 14:39:29 UTC) #2
Marc Treib
https://codereview.chromium.org/1770313004/diff/1/chrome/browser/component_updater/supervised_user_whitelist_installer.cc File chrome/browser/component_updater/supervised_user_whitelist_installer.cc (right): https://codereview.chromium.org/1770313004/diff/1/chrome/browser/component_updater/supervised_user_whitelist_installer.cc#newcode83 chrome/browser/component_updater/supervised_user_whitelist_installer.cc:83: return base::FilePath(); Probably the same should apply below for ...
4 years, 9 months ago (2016-03-09 14:50:54 UTC) #3
atanasova
https://codereview.chromium.org/1770313004/diff/1/chrome/browser/component_updater/supervised_user_whitelist_installer.cc File chrome/browser/component_updater/supervised_user_whitelist_installer.cc (right): https://codereview.chromium.org/1770313004/diff/1/chrome/browser/component_updater/supervised_user_whitelist_installer.cc#newcode83 chrome/browser/component_updater/supervised_user_whitelist_installer.cc:83: return base::FilePath(); On 2016/03/09 14:50:53, Marc Treib wrote: > ...
4 years, 9 months ago (2016-03-10 10:35:28 UTC) #4
Marc Treib
LGTM!
4 years, 9 months ago (2016-03-10 10:45:45 UTC) #5
atanasova
Adding Soring for OWNERS approval
4 years, 9 months ago (2016-03-10 10:47:04 UTC) #8
atanasova
Friendly ping
4 years, 9 months ago (2016-03-15 08:44:01 UTC) #10
Bernhard Bauer
https://codereview.chromium.org/1770313004/diff/1/chrome/browser/component_updater/supervised_user_whitelist_installer.cc File chrome/browser/component_updater/supervised_user_whitelist_installer.cc (right): https://codereview.chromium.org/1770313004/diff/1/chrome/browser/component_updater/supervised_user_whitelist_installer.cc#newcode83 chrome/browser/component_updater/supervised_user_whitelist_installer.cc:83: return base::FilePath(); On 2016/03/09 14:50:53, Marc Treib wrote: > ...
4 years, 9 months ago (2016-03-15 09:34:52 UTC) #11
atanasova
https://codereview.chromium.org/1770313004/diff/20001/chrome/browser/component_updater/supervised_user_whitelist_installer.cc File chrome/browser/component_updater/supervised_user_whitelist_installer.cc (right): https://codereview.chromium.org/1770313004/diff/20001/chrome/browser/component_updater/supervised_user_whitelist_installer.cc#newcode72 chrome/browser/component_updater/supervised_user_whitelist_installer.cc:72: base::FilePath path; On 2016/03/15 09:34:52, bauerb catching up on ...
4 years, 9 months ago (2016-03-15 11:22:06 UTC) #12
Sorin Jianu
lgtm Thank you! I apologize for the late review. Please always IM me when I ...
4 years, 9 months ago (2016-03-16 20:58:15 UTC) #13
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/patch-status/1770313004/40001 View timeline at https://chromium-cq-status.appspot.com/patch-timeline/1770313004/40001
4 years, 9 months ago (2016-03-16 21:00:18 UTC) #16
commit-bot: I haz the power
Committed patchset #3 (id:40001)
4 years, 9 months ago (2016-03-16 21:47:23 UTC) #18
commit-bot: I haz the power
4 years, 9 months ago (2016-03-16 21:49:11 UTC) #20
Message was sent while issue was closed.
Patchset 3 (id:??) landed as
https://crrev.com/6b03d171d4137691637129ebad5cab20f4babbbb
Cr-Commit-Position: refs/heads/master@{#381557}

Powered by Google App Engine
This is Rietveld 408576698