Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(266)

Unified Diff: media/blink/resource_multibuffer_data_provider.cc

Issue 1958123004: fix service worker cross-origin problem in multibuffers (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@master
Patch Set: all tests pass Created 4 years, 7 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: media/blink/resource_multibuffer_data_provider.cc
diff --git a/media/blink/resource_multibuffer_data_provider.cc b/media/blink/resource_multibuffer_data_provider.cc
index 0acae612b9d2deeaacd1920a965d609ac91a74d8..fa29d9efe713ee7eb2972b847f2c40c1d1c1f5a7 100644
--- a/media/blink/resource_multibuffer_data_provider.cc
+++ b/media/blink/resource_multibuffer_data_provider.cc
@@ -312,6 +312,14 @@ void ResourceMultiBufferDataProvider::didReceiveResponse(
// cause clients to start using the new UrlData.
old_url_data->RedirectTo(destination_url_data);
}
+
+ // This test is vital for security!
DaleCurtis 2016/05/10 00:16:08 Needs unit test too then; did we lose a test from
hubbe 2016/05/10 22:33:23 Turns out we missed one test (added after fork), a
+ const GURL& original_url = response.wasFetchedViaServiceWorker()
+ ? response.originalURLViaServiceWorker()
+ : response.url();
+ if (!url_data_->ValidateDataOrigin(original_url.GetOrigin())) {
+ url_data_->Fail();
+ }
}
void ResourceMultiBufferDataProvider::didReceiveData(WebURLLoader* loader,

Powered by Google App Engine
This is Rietveld 408576698