Chromium Code Reviews
DescriptionRevert of Change wildcard source expression matching to conform latest spec (patchset #5 id:80001 of https://codereview.chromium.org/2160983002/ )
Reason for revert:
This breaks PDFium's handling of PDFs hosted on `file:`. Unfortunately, we didn't have tests covering this functionality, but we still need to fix it. :)
Original issue's description:
> Change wildcard source expression matching to conform latest spec
>
> This changes wildcard source expression matching to require
> any schemes other than http/https/ws/wss be explicitly present
> in the source list to match, per
> https://w3c.github.io/webappsec-csp/#match-url-to-source-expression
>
> This also updates CSP injected in chrome/browser/ui/webui/ to explicitly allow
> `chrome:` as in `connect-src chrome:` to fix failing tests.
>
> Previous CL at https://codereview.chromium.org/1973933002/ is stale,
> so creating a new one to nail it this time.
> BUG=611314
> R=mkwst@chromium.org
>
> Committed: https://crrev.com/6104167b0bf16a3520a898dbe67227637d1c214e
> Cr-Commit-Position: refs/heads/master@{#408654}
TBR=jochen@chromium.org,mfoltz@chromium.org,shekyan@gmail.com
# Not skipping CQ checks because original CL landed more than 1 days ago.
BUG=611314
Committed: https://crrev.com/14f3d8cdac5f46ec73fd38e5d9d731e57966427f
Cr-Commit-Position: refs/heads/master@{#409480}
Patch Set 1 #
Messages
Total messages: 7 (3 generated)
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||