Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(172)

Unified Diff: third_party/WebKit/Source/core/loader/TextTrackLoader.cpp

Issue 2367583002: Check CORS policy on redirect in TextTrackLoader (Closed)
Patch Set: Created 4 years, 3 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: third_party/WebKit/Source/core/loader/TextTrackLoader.cpp
diff --git a/third_party/WebKit/Source/core/loader/TextTrackLoader.cpp b/third_party/WebKit/Source/core/loader/TextTrackLoader.cpp
index bcdaccf0eed78f410fac02db5ea3325edcc16990..08346aac73b117d7146844f458533d510ccb7051 100644
--- a/third_party/WebKit/Source/core/loader/TextTrackLoader.cpp
+++ b/third_party/WebKit/Source/core/loader/TextTrackLoader.cpp
@@ -67,6 +67,18 @@ void TextTrackLoader::cancelLoad()
clearResource();
}
+void TextTrackLoader::redirectReceived(Resource* resource, ResourceRequest& request, const ResourceResponse&)
+{
+ DCHECK_EQ(this->resource(), resource);
+ if (resource->options().corsEnabled == IsCORSEnabled || document().getSecurityOrigin()->canRequestNoSuborigin(request.url()))
+ return;
+
+ corsPolicyPreventedLoad(document().getSecurityOrigin(), request.url());
+ if (!m_cueLoadTimer.isActive())
+ m_cueLoadTimer.startOneShot(0, BLINK_FROM_HERE);
+ clearResource();
+}
+
void TextTrackLoader::dataReceived(Resource* resource, const char* data, size_t length)
{
DCHECK_EQ(this->resource(), resource);

Powered by Google App Engine
This is Rietveld 408576698