| OLD | NEW |
| 1 // Copyright 2014 The Chromium Authors. All rights reserved. | 1 // Copyright 2014 The Chromium Authors. All rights reserved. |
| 2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
| 3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
| 4 | 4 |
| 5 #include "core/frame/DOMWindow.h" | 5 #include "core/frame/DOMWindow.h" |
| 6 | 6 |
| 7 #include "bindings/core/v8/ScriptCallStack.h" | 7 #include "bindings/core/v8/ScriptCallStack.h" |
| 8 #include "core/dom/Document.h" | 8 #include "core/dom/Document.h" |
| 9 #include "core/dom/ExceptionCode.h" | 9 #include "core/dom/ExceptionCode.h" |
| 10 #include "core/dom/ExecutionContext.h" | 10 #include "core/dom/ExecutionContext.h" |
| (...skipping 245 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
| 256 if (!callingWindow || !callingWindow->document() || !frame()) | 256 if (!callingWindow || !callingWindow->document() || !frame()) |
| 257 return String(); | 257 return String(); |
| 258 | 258 |
| 259 const KURL& callingWindowURL = callingWindow->document()->url(); | 259 const KURL& callingWindowURL = callingWindow->document()->url(); |
| 260 if (callingWindowURL.isNull()) | 260 if (callingWindowURL.isNull()) |
| 261 return String(); | 261 return String(); |
| 262 | 262 |
| 263 // FIXME: This message, and other console messages, have extra newlines. Sho
uld remove them. | 263 // FIXME: This message, and other console messages, have extra newlines. Sho
uld remove them. |
| 264 const SecurityOrigin* activeOrigin = callingWindow->document()->getSecurityO
rigin(); | 264 const SecurityOrigin* activeOrigin = callingWindow->document()->getSecurityO
rigin(); |
| 265 const SecurityOrigin* targetOrigin = frame()->securityContext()->getSecurity
Origin(); | 265 const SecurityOrigin* targetOrigin = frame()->securityContext()->getSecurity
Origin(); |
| 266 ASSERT(!activeOrigin->canAccessCheckSuborigins(targetOrigin)); | 266 // It's possible for a remote frame to be same origin with respect to a |
| 267 // local frame, but it must still be treated as a disallowed cross-domain |
| 268 // access. See https://crbug.com/601629. |
| 269 ASSERT(frame()->isRemoteFrame() || !activeOrigin->canAccessCheckSuborigins(t
argetOrigin)); |
| 267 | 270 |
| 268 String message = "Blocked a frame with origin \"" + activeOrigin->toString()
+ "\" from accessing a frame with origin \"" + targetOrigin->toString() + "\".
"; | 271 String message = "Blocked a frame with origin \"" + activeOrigin->toString()
+ "\" from accessing a frame with origin \"" + targetOrigin->toString() + "\".
"; |
| 269 | 272 |
| 270 // Sandbox errors: Use the origin of the frames' location, rather than their
actual origin (since we know that at least one will be "null"). | 273 // Sandbox errors: Use the origin of the frames' location, rather than their
actual origin (since we know that at least one will be "null"). |
| 271 KURL activeURL = callingWindow->document()->url(); | 274 KURL activeURL = callingWindow->document()->url(); |
| 272 // TODO(alexmos): RemoteFrames do not have a document, and their URLs | 275 // TODO(alexmos): RemoteFrames do not have a document, and their URLs |
| 273 // aren't replicated. For now, construct the URL using the replicated | 276 // aren't replicated. For now, construct the URL using the replicated |
| 274 // origin for RemoteFrames. If the target frame is remote and sandboxed, | 277 // origin for RemoteFrames. If the target frame is remote and sandboxed, |
| 275 // there isn't anything else to show other than "null" for its origin. | 278 // there isn't anything else to show other than "null" for its origin. |
| 276 KURL targetURL = isLocalDOMWindow() ? document()->url() : KURL(KURL(), targe
tOrigin->toString()); | 279 KURL targetURL = isLocalDOMWindow() ? document()->url() : KURL(KURL(), targe
tOrigin->toString()); |
| (...skipping 92 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
| 369 page->focusController().focusDocumentView(frame(), true /* notifyEmbedder */
); | 372 page->focusController().focusDocumentView(frame(), true /* notifyEmbedder */
); |
| 370 } | 373 } |
| 371 | 374 |
| 372 DEFINE_TRACE(DOMWindow) | 375 DEFINE_TRACE(DOMWindow) |
| 373 { | 376 { |
| 374 visitor->trace(m_location); | 377 visitor->trace(m_location); |
| 375 EventTargetWithInlineData::trace(visitor); | 378 EventTargetWithInlineData::trace(visitor); |
| 376 } | 379 } |
| 377 | 380 |
| 378 } // namespace blink | 381 } // namespace blink |
| OLD | NEW |