Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(233)

Issue 2295153004: Fix a null-deref in Upgrade-Insecure-Request's handling of unique origins. (Closed)

Created:
4 years, 3 months ago by Mike West
Modified:
4 years, 3 months ago
CC:
blink-reviews, chromium-reviews, elawrence
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

Fix a null-deref in Upgrade-Insecure-Request's handling of unique origins. If a page is sandboxed into a unique origin, the current code which enforces upgrading insecure requests will end up doing dereferencing the origin's host. Unfortunately the origin has no host, and we end up doing a null-deref on the StringImpl. Whoops. This patch aligns our behavior with the spec's mandate to use the protected resource's URL's host instead: https://www.w3.org/TR/upgrade-insecure-requests/#delivery. It also changes the 'isNull' check to an 'isEmpty' check to handle URLs without hosts, like 'data:'. BUG=643084 Committed: https://crrev.com/33153e2598026b19f247a2c6ee2362124b5aea4e Cr-Commit-Position: refs/heads/master@{#415921}

Patch Set 1 #

Patch Set 2 : Drop variable. #

Patch Set 3 : Test #

Unified diffs Side-by-side diffs Delta from patch set Stats (+12 lines, -13 lines) Patch
A + third_party/WebKit/LayoutTests/http/tests/security/upgrade-insecure-requests/sandbox-upgrade.https.php View 2 chunks +6 lines, -6 lines 0 comments Download
M third_party/WebKit/Source/core/frame/csp/ContentSecurityPolicy.cpp View 1 2 chunks +4 lines, -6 lines 0 comments Download
M third_party/WebKit/Source/core/frame/csp/ContentSecurityPolicyTest.cpp View 1 2 1 chunk +2 lines, -1 line 0 comments Download

Messages

Total messages: 16 (11 generated)
Mike West
WDYT, Jochen? FYI: elawrence@.
4 years, 3 months ago (2016-09-01 07:10:24 UTC) #5
jochen (gone - plz use gerrit)
lgtm
4 years, 3 months ago (2016-09-01 07:12:19 UTC) #8
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2295153004/40001
4 years, 3 months ago (2016-09-01 08:39:17 UTC) #13
commit-bot: I haz the power
Committed patchset #3 (id:40001)
4 years, 3 months ago (2016-09-01 10:12:03 UTC) #14
commit-bot: I haz the power
4 years, 3 months ago (2016-09-01 10:13:31 UTC) #16
Message was sent while issue was closed.
Patchset 3 (id:??) landed as
https://crrev.com/33153e2598026b19f247a2c6ee2362124b5aea4e
Cr-Commit-Position: refs/heads/master@{#415921}

Powered by Google App Engine
This is Rietveld 408576698