Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(297)

Issue 2354433002: Block navigator.vibrate in cross-domain iframe. (Closed)

Created:
4 years, 3 months ago by Bin Lu
Modified:
4 years, 2 months ago
CC:
blink-reviews, chromium-reviews, emilyschechter, haraken, mlamouri+watch-blink_chromium.org, RyanS
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

Block navigator.vibrate in cross-domain iframe. Intent to implement and ship: https://groups.google.com/a/chromium.org/d/msg/blink-dev/7iVcwNcO3xw/WQSkkuk5BQAJ BUG=625044 Committed: https://crrev.com/73c8d462f16d232661175c790bf476f4cda24874 Cr-Commit-Position: refs/heads/master@{#421873}

Patch Set 1 #

Patch Set 2 : Fix a bug. #

Patch Set 3 : Modify the error message slightly. #

Patch Set 4 : Fix the header issue. #

Total comments: 1

Patch Set 5 : Make the error message a little shorter and clearer. #

Patch Set 6 : Add test and TODO. #

Patch Set 7 : Add TODO owner. #

Patch Set 8 : git cl try & #

Patch Set 9 : Fix the test & -expected.txt files. #

Total comments: 2

Patch Set 10 : Change the error message to: "A call of navigator.vibrate will be no-op inside cross-origin iframes" #

Messages

Total messages: 73 (50 generated)
Bin Lu
Hi Ojan and Nate, Is this the right way to do it? If yes, I ...
4 years, 3 months ago (2016-09-19 05:06:36 UTC) #7
Nate Chapin
That looks right to me. Just a nitpick about the error message. https://codereview.chromium.org/2354433002/diff/60001/third_party/WebKit/Source/modules/vibration/NavigatorVibration.cpp File third_party/WebKit/Source/modules/vibration/NavigatorVibration.cpp ...
4 years, 3 months ago (2016-09-19 19:33:29 UTC) #18
Bin Lu
Done. Thanks, Nate! On 2016/09/19 19:33:29, Nate Chapin wrote: > That looks right to me. ...
4 years, 3 months ago (2016-09-20 05:29:06 UTC) #23
Nate Chapin
Code looks good, but the test should probably be included in this CL.
4 years, 3 months ago (2016-09-20 18:32:18 UTC) #24
ojan
I keep going back and forth on whether we should return false or remove the ...
4 years, 3 months ago (2016-09-20 22:57:47 UTC) #25
Bin Lu
Done. Added test too although not sure if it's correct (since this is the first ...
4 years, 2 months ago (2016-09-23 06:15:33 UTC) #37
Bin Lu
Fixed the tests. PTAL. There is an empty file in the CL: "...//vibrate_in_same_origin_iframe_allowed-expected.txt". It's supposed ...
4 years, 2 months ago (2016-09-28 16:28:06 UTC) #43
ojan
lgtm
4 years, 2 months ago (2016-09-28 21:06:22 UTC) #47
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2354433002/160001
4 years, 2 months ago (2016-09-28 21:06:43 UTC) #48
ojan
https://codereview.chromium.org/2354433002/diff/160001/third_party/WebKit/LayoutTests/http/tests/security/resources/same-origin-iframe-for-vibrate-allowed.html File third_party/WebKit/LayoutTests/http/tests/security/resources/same-origin-iframe-for-vibrate-allowed.html (right): https://codereview.chromium.org/2354433002/diff/160001/third_party/WebKit/LayoutTests/http/tests/security/resources/same-origin-iframe-for-vibrate-allowed.html#newcode10 third_party/WebKit/LayoutTests/http/tests/security/resources/same-origin-iframe-for-vibrate-allowed.html:10: assert_true(navigator.vibrate(200)); Acutally...wait, does this not output a PASS line ...
4 years, 2 months ago (2016-09-28 21:08:52 UTC) #50
ojan
On 2016/09/28 at 21:08:52, ojan wrote: > https://codereview.chromium.org/2354433002/diff/160001/third_party/WebKit/LayoutTests/http/tests/security/resources/same-origin-iframe-for-vibrate-allowed.html > File third_party/WebKit/LayoutTests/http/tests/security/resources/same-origin-iframe-for-vibrate-allowed.html (right): > > https://codereview.chromium.org/2354433002/diff/160001/third_party/WebKit/LayoutTests/http/tests/security/resources/same-origin-iframe-for-vibrate-allowed.html#newcode10 ...
4 years, 2 months ago (2016-09-28 21:12:34 UTC) #51
ojan
+tkent, can you comment on what the right thing to do for -expected.txt files for ...
4 years, 2 months ago (2016-09-28 21:13:38 UTC) #52
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2354433002/160001
4 years, 2 months ago (2016-09-28 21:14:21 UTC) #54
commit-bot: I haz the power
Try jobs failed on following builders: chromium_presubmit on master.tryserver.chromium.linux (JOB_FAILED, http://build.chromium.org/p/tryserver.chromium.linux/builders/chromium_presubmit/builds/268940)
4 years, 2 months ago (2016-09-28 21:24:41 UTC) #56
Bin Lu
Hi Michael, could you please help do the owner review for Source/modules/vibration/? I'm see ** ...
4 years, 2 months ago (2016-09-28 21:33:49 UTC) #57
tkent
On 2016/09/28 at 21:13:38, ojan wrote: > +tkent, can you comment on what the right ...
4 years, 2 months ago (2016-09-28 23:25:34 UTC) #58
Michael van Ouwerkerk
lgtm with nit https://codereview.chromium.org/2354433002/diff/160001/third_party/WebKit/Source/modules/vibration/NavigatorVibration.cpp File third_party/WebKit/Source/modules/vibration/NavigatorVibration.cpp (right): https://codereview.chromium.org/2354433002/diff/160001/third_party/WebKit/Source/modules/vibration/NavigatorVibration.cpp#newcode89 third_party/WebKit/Source/modules/vibration/NavigatorVibration.cpp:89: "A cross-origin iframe may not call ...
4 years, 2 months ago (2016-09-29 13:36:16 UTC) #59
Bin Lu
> nit: Has this message been discussed? Technically, you can _call_ it, it just > ...
4 years, 2 months ago (2016-09-29 16:44:30 UTC) #60
Bin Lu
On 2016/09/28 23:25:34, tkent wrote: > On 2016/09/28 at 21:13:38, ojan wrote: > > +tkent, ...
4 years, 2 months ago (2016-09-29 16:46:39 UTC) #61
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2354433002/180001
4 years, 2 months ago (2016-09-29 18:17:29 UTC) #68
commit-bot: I haz the power
Committed patchset #10 (id:180001)
4 years, 2 months ago (2016-09-29 18:25:23 UTC) #70
commit-bot: I haz the power
Patchset 10 (id:??) landed as https://crrev.com/73c8d462f16d232661175c790bf476f4cda24874 Cr-Commit-Position: refs/heads/master@{#421873}
4 years, 2 months ago (2016-09-29 18:27:55 UTC) #72
tkent
4 years, 2 months ago (2016-09-29 23:24:29 UTC) #73
Message was sent while issue was closed.
On 2016/09/29 at 16:46:39, binlu wrote:
> > In general, it's right.  We don't check in such -expected.txt.
> > However, it doesn't mean -expected.txt becomes empty.  I think tests in the
> > latest patch set don't print assert_*() in the top-level document, and
> > -expected.txts don't contain iframe content, or tests finish before loading
> > iframe content.  I'm afraid these tests don't make sense at this moment.
> 
> The -expected.txt does have an output of the error message for the blocked
case, and only the -expected.txt for the allowed case is empty.

ok, then we can find behavior changes by the tests.
However, The tests still wrong.  They have test() and assert_*(), but
-expected.txts don't contain neither PASS nor FAIL. We should run test() in the
top-level document.

Powered by Google App Engine
This is Rietveld 408576698