| OLD | NEW |
| 1 /* | 1 /* |
| 2 * Copyright (C) 2008 Apple Inc. All Rights Reserved. | 2 * Copyright (C) 2008 Apple Inc. All Rights Reserved. |
| 3 * | 3 * |
| 4 * Redistribution and use in source and binary forms, with or without | 4 * Redistribution and use in source and binary forms, with or without |
| 5 * modification, are permitted provided that the following conditions | 5 * modification, are permitted provided that the following conditions |
| 6 * are met: | 6 * are met: |
| 7 * 1. Redistributions of source code must retain the above copyright | 7 * 1. Redistributions of source code must retain the above copyright |
| 8 * notice, this list of conditions and the following disclaimer. | 8 * notice, this list of conditions and the following disclaimer. |
| 9 * 2. Redistributions in binary form must reproduce the above copyright | 9 * 2. Redistributions in binary form must reproduce the above copyright |
| 10 * notice, this list of conditions and the following disclaimer in the | 10 * notice, this list of conditions and the following disclaimer in the |
| (...skipping 16 matching lines...) Expand all Loading... |
| 27 #include "core/fetch/CrossOriginAccessControl.h" | 27 #include "core/fetch/CrossOriginAccessControl.h" |
| 28 | 28 |
| 29 #include "core/fetch/FetchUtils.h" | 29 #include "core/fetch/FetchUtils.h" |
| 30 #include "core/fetch/Resource.h" | 30 #include "core/fetch/Resource.h" |
| 31 #include "core/fetch/ResourceLoaderOptions.h" | 31 #include "core/fetch/ResourceLoaderOptions.h" |
| 32 #include "platform/network/HTTPParsers.h" | 32 #include "platform/network/HTTPParsers.h" |
| 33 #include "platform/network/ResourceRequest.h" | 33 #include "platform/network/ResourceRequest.h" |
| 34 #include "platform/network/ResourceResponse.h" | 34 #include "platform/network/ResourceResponse.h" |
| 35 #include "platform/weborigin/SchemeRegistry.h" | 35 #include "platform/weborigin/SchemeRegistry.h" |
| 36 #include "platform/weborigin/SecurityOrigin.h" | 36 #include "platform/weborigin/SecurityOrigin.h" |
| 37 #include "wtf/PtrUtil.h" | |
| 38 #include "wtf/Threading.h" | 37 #include "wtf/Threading.h" |
| 39 #include "wtf/text/AtomicString.h" | 38 #include "wtf/text/AtomicString.h" |
| 40 #include "wtf/text/StringBuilder.h" | 39 #include "wtf/text/StringBuilder.h" |
| 41 #include <algorithm> | 40 #include <algorithm> |
| 42 #include <memory> | |
| 43 | 41 |
| 44 namespace blink { | 42 namespace blink { |
| 45 | 43 |
| 46 static std::unique_ptr<HTTPHeaderSet> createAllowedCrossOriginResponseHeadersSet
() | 44 static PassOwnPtr<HTTPHeaderSet> createAllowedCrossOriginResponseHeadersSet() |
| 47 { | 45 { |
| 48 std::unique_ptr<HTTPHeaderSet> headerSet = wrapUnique(new HashSet<String, Ca
seFoldingHash>); | 46 OwnPtr<HTTPHeaderSet> headerSet = adoptPtr(new HashSet<String, CaseFoldingHa
sh>); |
| 49 | 47 |
| 50 headerSet->add("cache-control"); | 48 headerSet->add("cache-control"); |
| 51 headerSet->add("content-language"); | 49 headerSet->add("content-language"); |
| 52 headerSet->add("content-type"); | 50 headerSet->add("content-type"); |
| 53 headerSet->add("expires"); | 51 headerSet->add("expires"); |
| 54 headerSet->add("last-modified"); | 52 headerSet->add("last-modified"); |
| 55 headerSet->add("pragma"); | 53 headerSet->add("pragma"); |
| 56 | 54 |
| 57 return headerSet; | 55 return headerSet; |
| 58 } | 56 } |
| 59 | 57 |
| 60 bool isOnAccessControlResponseHeaderWhitelist(const String& name) | 58 bool isOnAccessControlResponseHeaderWhitelist(const String& name) |
| 61 { | 59 { |
| 62 DEFINE_THREAD_SAFE_STATIC_LOCAL(HTTPHeaderSet, allowedCrossOriginResponseHea
ders, (createAllowedCrossOriginResponseHeadersSet().release())); | 60 DEFINE_THREAD_SAFE_STATIC_LOCAL(HTTPHeaderSet, allowedCrossOriginResponseHea
ders, (createAllowedCrossOriginResponseHeadersSet().leakPtr())); |
| 63 | 61 |
| 64 return allowedCrossOriginResponseHeaders.contains(name); | 62 return allowedCrossOriginResponseHeaders.contains(name); |
| 65 } | 63 } |
| 66 | 64 |
| 67 void updateRequestForAccessControl(ResourceRequest& request, SecurityOrigin* sec
urityOrigin, StoredCredentials allowCredentials) | 65 void updateRequestForAccessControl(ResourceRequest& request, SecurityOrigin* sec
urityOrigin, StoredCredentials allowCredentials) |
| 68 { | 66 { |
| 69 request.removeCredentials(); | 67 request.removeCredentials(); |
| 70 request.setAllowStoredCredentials(allowCredentials == AllowStoredCredentials
); | 68 request.setAllowStoredCredentials(allowCredentials == AllowStoredCredentials
); |
| 71 | 69 |
| 72 if (securityOrigin) | 70 if (securityOrigin) |
| (...skipping 255 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
| 328 newRequest.setHTTPOrigin(securityOrigin); | 326 newRequest.setHTTPOrigin(securityOrigin); |
| 329 // If the user didn't request credentials in the first place, update our | 327 // If the user didn't request credentials in the first place, update our |
| 330 // state so we neither request them nor expect they must be allowed. | 328 // state so we neither request them nor expect they must be allowed. |
| 331 if (options.credentialsRequested == ClientDidNotRequestCredentials) | 329 if (options.credentialsRequested == ClientDidNotRequestCredentials) |
| 332 options.allowCredentials = DoNotAllowStoredCredentials; | 330 options.allowCredentials = DoNotAllowStoredCredentials; |
| 333 } | 331 } |
| 334 return true; | 332 return true; |
| 335 } | 333 } |
| 336 | 334 |
| 337 } // namespace blink | 335 } // namespace blink |
| OLD | NEW |