Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(1547)

Unified Diff: chrome/browser/ui/webui/uber/uber_ui.cc

Issue 2012393003: Replace frame-src with child-src in WebUI CSP (Closed) Base URL: https://chromium.googlesource.com/a/chromium/src.git@csp
Patch Set: Created 4 years, 7 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: chrome/browser/ui/webui/uber/uber_ui.cc
diff --git a/chrome/browser/ui/webui/uber/uber_ui.cc b/chrome/browser/ui/webui/uber/uber_ui.cc
index ea1a5bfe9a9edeab99e41183be86b65702f4dc80..35d8eb005e5cf0feec805fdb5a2e893d3e3555a6 100644
--- a/chrome/browser/ui/webui/uber/uber_ui.cc
+++ b/chrome/browser/ui/webui/uber/uber_ui.cc
@@ -45,7 +45,7 @@ content::WebUIDataSource* CreateUberHTMLSource() {
source->AddResourcePath("uber.js", IDR_UBER_JS);
source->AddResourcePath("uber_utils.js", IDR_UBER_UTILS_JS);
source->SetDefaultResource(IDR_UBER_HTML);
- source->OverrideContentSecurityPolicyFrameSrc("frame-src chrome:;");
+ source->OverrideContentSecurityPolicyChildSrc("child-src chrome:;");
// Hack alert: continue showing "Loading..." until a real title is set.
source->AddLocalizedString("pageTitle", IDS_TAB_LOADING_TITLE);
@@ -115,7 +115,7 @@ content::WebUIDataSource* CreateUberFrameHTMLSource(
&& !overrides_history);
source->DisableDenyXFrameOptions();
- source->OverrideContentSecurityPolicyFrameSrc("frame-src chrome:;");
+ source->OverrideContentSecurityPolicyChildSrc("child-src chrome:;");
source->AddBoolean("profileIsGuest",
Profile::FromBrowserContext(browser_context)->IsGuestSession());

Powered by Google App Engine
This is Rietveld 408576698