Chromium Code Reviews
Help | Chromium Project | Gerrit Changes | Sign in
(3)

Issue 18865003: Do not allow HTTP refresh headers to refresh to javascript: URLs. (Closed)

Created:
4 years, 7 months ago by Tom Sepez
Modified:
4 years, 7 months ago
Reviewers:
abarth-chromium
CC:
blink-reviews, dglazkov+blink, Nate Chapin, eae+blinkwatch, adamk+blink_chromium.org, gavinp+loader_chromium.org
Visibility:
Public.

Description

Do not allow HTTP refresh headers to refresh to javascript: URLs. This behaviour has been standard in IE since IE7. This makes us both more compatible and less vulnerable to XSS. BUG=258151 R=abarth@chromium.org Committed: https://src.chromium.org/viewvc/blink?view=rev&revision=153912

Patch Set 1 #

Unified diffs Side-by-side diffs Delta from patch set Stats (+33 lines, -7 lines) Patch
A + LayoutTests/http/tests/security/no-javascript-refresh.php View 1 chunk +6 lines, -5 lines 0 comments Download
A LayoutTests/http/tests/security/no-javascript-refresh-expected.txt View 1 chunk +2 lines, -0 lines 0 comments Download
A LayoutTests/http/tests/security/no-javascript-refresh-static.html View 1 chunk +11 lines, -0 lines 0 comments Download
A LayoutTests/http/tests/security/no-javascript-refresh-static-expected.txt View 1 chunk +2 lines, -0 lines 0 comments Download
M Source/core/dom/Document.cpp View 1 chunk +6 lines, -1 line 0 comments Download
M Source/core/loader/FrameLoader.cpp View 1 chunk +6 lines, -1 line 0 comments Download

Messages

Total messages: 4 (0 generated)
Tom Sepez
Adam, please review.
4 years, 7 months ago (2013-07-09 21:07:49 UTC) #1
abarth-chromium
LGTM. We might want to mention this change in the blog post for M30. Would ...
4 years, 7 months ago (2013-07-09 21:11:15 UTC) #2
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-status.appspot.com/cq/tsepez@chromium.org/18865003/1
4 years, 7 months ago (2013-07-10 16:16:15 UTC) #3
commit-bot: I haz the power
4 years, 7 months ago (2013-07-10 18:02:37 UTC) #4
Message was sent while issue was closed.
Change committed as 153912

Powered by Google App Engine
This is Rietveld 408576698