Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(1024)

Unified Diff: Source/core/page/CreateWindow.cpp

Issue 208853004: Don't propagate sandbox flags to an opened window unless triggered entirely by script. (Closed) Base URL: svn://svn.chromium.org/blink/trunk
Patch Set: Created 6 years, 9 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
« no previous file with comments | « LayoutTests/http/tests/navigation/resources/new-window-sandboxed-iframe-iframe.html ('k') | no next file » | no next file with comments »
Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
Index: Source/core/page/CreateWindow.cpp
diff --git a/Source/core/page/CreateWindow.cpp b/Source/core/page/CreateWindow.cpp
index 9c2adf361bc9891dae8cc126686e181fe0a85ee3..4eb99754adb375fdef70fe78b72dae905084ecaa 100644
--- a/Source/core/page/CreateWindow.cpp
+++ b/Source/core/page/CreateWindow.cpp
@@ -81,8 +81,6 @@ static LocalFrame* createWindow(LocalFrame& openerFrame, LocalFrame& lookupFrame
ASSERT(page->mainFrame());
LocalFrame& frame = *page->mainFrame();
- frame.loader().forceSandboxFlags(openerFrame.document()->sandboxFlags());
-
if (request.frameName() != "_blank")
frame.tree().setName(request.frameName());
@@ -141,6 +139,9 @@ LocalFrame* createWindow(const String& urlString, const AtomicString& frameName,
if (!newFrame)
return 0;
+ if (newFrame != &openerFrame && newFrame != openerFrame.tree().top())
+ newFrame->loader().forceSandboxFlags(openerFrame.document()->sandboxFlags());
+
newFrame->loader().setOpener(&openerFrame);
newFrame->page()->setOpenedByDOM();
« no previous file with comments | « LayoutTests/http/tests/navigation/resources/new-window-sandboxed-iframe-iframe.html ('k') | no next file » | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698