Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(125)

Issue 2012393003: Replace frame-src with child-src in WebUI CSP (Closed)

Created:
4 years, 6 months ago by wychen
Modified:
4 years, 6 months ago
CC:
chromium-reviews, dbeam+watch-ntp_chromium.org, skanuj+watch_chromium.org, melevin+watch_chromium.org, oshima+watch_chromium.org, dzhioev+watch_chromium.org, dhollowa+watch_chromium.org, dougw+watch_chromium.org, donnd+watch_chromium.org, achuith+watch_chromium.org, jam, jfweitz+watch_chromium.org, David Black, samarth+watch_chromium.org, darin-cc_chromium.org, kmadhusu+watch_chromium.org, Jered, pedrosimonetti+watch_chromium.org
Base URL:
https://chromium.googlesource.com/a/chromium/src.git@csp
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

Replace frame-src with child-src in WebUI CSP "frame-src" is deprecated, and is replaced by "child-src". BUG=81636, 336788 Committed: https://crrev.com/d6eb7796599ed3880244b2f292dee17a3bb8722a Cr-Commit-Position: refs/heads/master@{#397869}

Patch Set 1 #

Unified diffs Side-by-side diffs Delta from patch set Stats (+30 lines, -30 lines) Patch
M chrome/browser/search/local_ntp_source.h View 1 chunk +1 line, -1 line 0 comments Download
M chrome/browser/search/local_ntp_source.cc View 1 chunk +2 lines, -2 lines 0 comments Download
M chrome/browser/ui/webui/chromeos/login/oobe_ui.cc View 1 chunk +2 lines, -2 lines 0 comments Download
M chrome/browser/ui/webui/ntp/new_tab_ui.h View 1 chunk +1 line, -1 line 0 comments Download
M chrome/browser/ui/webui/ntp/new_tab_ui.cc View 1 chunk +2 lines, -2 lines 0 comments Download
M chrome/browser/ui/webui/print_preview/print_preview_ui.cc View 1 chunk +1 line, -1 line 0 comments Download
M chrome/browser/ui/webui/signin/inline_login_ui.cc View 1 chunk +1 line, -1 line 0 comments Download
M chrome/browser/ui/webui/uber/uber_ui.cc View 2 chunks +2 lines, -2 lines 0 comments Download
M components/dom_distiller/content/browser/dom_distiller_viewer_source.h View 1 chunk +1 line, -1 line 0 comments Download
M components/dom_distiller/content/browser/dom_distiller_viewer_source.cc View 1 chunk +2 lines, -2 lines 0 comments Download
M content/browser/webui/url_data_manager_backend.cc View 4 chunks +6 lines, -6 lines 0 comments Download
M content/browser/webui/web_ui_data_source_impl.h View 1 chunk +1 line, -1 line 0 comments Download
M content/browser/webui/web_ui_data_source_impl.cc View 2 chunks +3 lines, -3 lines 0 comments Download
M content/public/browser/url_data_source.h View 1 chunk +2 lines, -2 lines 0 comments Download
M content/public/browser/url_data_source.cc View 1 chunk +2 lines, -2 lines 0 comments Download
M content/public/browser/web_ui_data_source.h View 1 chunk +1 line, -1 line 0 comments Download

Depends on Patchset:

Messages

Total messages: 21 (10 generated)
wychen
PTAL
4 years, 6 months ago (2016-05-28 00:29:35 UTC) #5
Avi (use Gerrit)
lgtm
4 years, 6 months ago (2016-05-28 00:50:11 UTC) #7
huangs
Not sure why I'm on this review. Anyway, "frame-src" still appears in some test files, ...
4 years, 6 months ago (2016-05-30 14:57:03 UTC) #8
wychen
On 2016/05/30 14:57:03, huangs wrote: > Not sure why I'm on this review. Anyway, "frame-src" ...
4 years, 6 months ago (2016-05-31 07:54:19 UTC) #11
huangs
Ah okay. LGTM for those files then.
4 years, 6 months ago (2016-05-31 14:54:02 UTC) #12
mdjones
lgtm
4 years, 6 months ago (2016-05-31 16:13:02 UTC) #13
Tom Sepez
lgtm
4 years, 6 months ago (2016-05-31 16:14:46 UTC) #14
Dan Beam
lgtm
4 years, 6 months ago (2016-05-31 19:16:24 UTC) #15
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/patch-status/2012393003/1
4 years, 6 months ago (2016-06-03 23:35:24 UTC) #17
commit-bot: I haz the power
Committed patchset #1 (id:1)
4 years, 6 months ago (2016-06-04 00:53:07 UTC) #19
commit-bot: I haz the power
4 years, 6 months ago (2016-06-04 00:54:24 UTC) #21
Message was sent while issue was closed.
Patchset 1 (id:??) landed as
https://crrev.com/d6eb7796599ed3880244b2f292dee17a3bb8722a
Cr-Commit-Position: refs/heads/master@{#397869}

Powered by Google App Engine
This is Rietveld 408576698