Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(1045)

Unified Diff: media/blink/resource_multibuffer_data_provider.cc

Issue 1993083002: The cross-origin checks in the multibuffer code are not sufficient, as they only trigger when a red… (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@2704
Patch Set: Created 4 years, 7 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: media/blink/resource_multibuffer_data_provider.cc
diff --git a/media/blink/resource_multibuffer_data_provider.cc b/media/blink/resource_multibuffer_data_provider.cc
index c686c16cd3797905d896d64172609a8ea5c90103..d714618fe2967752cdeabd37629bc3ea238f1a8e 100644
--- a/media/blink/resource_multibuffer_data_provider.cc
+++ b/media/blink/resource_multibuffer_data_provider.cc
@@ -174,7 +174,9 @@ void ResourceMultiBufferDataProvider::willFollowRedirect(
if (url_data_->multibuffer()->map().empty() && fifo_.empty())
return;
+ active_loader_ = nullptr;
url_data_->Fail();
+ return; // "this" may be deleted now.
}
}
}
@@ -288,8 +290,9 @@ void ResourceMultiBufferDataProvider::didReceiveResponse(
destination_url_data->multibuffer()->OnDataProviderEvent(this);
return;
} else {
+ active_loader_ = nullptr;
destination_url_data->Fail();
- return;
+ return; // "this" may be deleted now.
}
} else {
destination_url_data->set_range_supported();
@@ -322,6 +325,16 @@ void ResourceMultiBufferDataProvider::didReceiveResponse(
// cause clients to start using the new UrlData.
old_url_data->RedirectTo(destination_url_data);
}
+
+ // This test is vital for security!
+ const GURL& original_url = response.wasFetchedViaServiceWorker()
+ ? response.originalURLViaServiceWorker()
+ : response.url();
+ if (!url_data_->ValidateDataOrigin(original_url.GetOrigin())) {
+ active_loader_ = nullptr;
+ url_data_->Fail();
+ return; // "this" may be deleted now.
+ }
}
void ResourceMultiBufferDataProvider::didReceiveData(WebURLLoader* loader,
@@ -397,9 +410,9 @@ void ResourceMultiBufferDataProvider::didFinishLoading(
base::TimeDelta::FromMilliseconds(kLoaderPartialRetryDelayMs));
return;
} else {
- scoped_ptr<ActiveLoader> active_loader = std::move(active_loader_);
+ active_loader_ = nullptr;
url_data_->Fail();
- return;
+ return; // "this" may be deleted now.
}
}
« no previous file with comments | « media/blink/multibuffer_data_source_unittest.cc ('k') | media/blink/resource_multibuffer_data_provider_unittest.cc » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698