Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(204)

Unified Diff: chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc

Issue 2486843003: Allow navigations to non-web-accessible resources from chrome schemes. (Closed)
Patch Set: nit Created 4 years, 1 month ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
« no previous file with comments | « no previous file | chrome/browser/extensions/window_open_apitest.cc » ('j') | no next file with comments »
Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
Index: chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc
diff --git a/chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc b/chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc
index e192ef01251f3407f0f3897a8cdbe1d22b34b17d..ee934ab8b7794ed6fe1a815a841531e2ac4b1b5b 100644
--- a/chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc
+++ b/chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc
@@ -25,6 +25,7 @@
#include "chrome/common/chrome_constants.h"
#include "chrome/common/chrome_switches.h"
#include "chrome/common/extensions/extension_process_policy.h"
+#include "chrome/common/url_constants.h"
#include "components/guest_view/browser/guest_view_message_filter.h"
#include "content/public/browser/browser_thread.h"
#include "content/public/browser/browser_url_handler.h"
@@ -36,6 +37,7 @@
#include "content/public/browser/vpn_service_proxy.h"
#include "content/public/browser/web_contents.h"
#include "content/public/common/content_switches.h"
+#include "content/public/common/url_constants.h"
#include "extensions/browser/api/web_request/web_request_api.h"
#include "extensions/browser/api/web_request/web_request_api_helpers.h"
#include "extensions/browser/bad_message.h"
@@ -576,6 +578,19 @@ bool ChromeContentBrowserClientExtensionsPart::ShouldAllowOpenURL(
return true;
}
+ // Navigations from chrome:// or chrome-search:// pages need to be allowed,
+ // even if |to_url| is not web-accessible. See https://crbug.com/662602.
+ //
+ // Note that this is intentionally done after the check for blob: and
+ // filesystem: URLs above, for consistency with the renderer-side checks
+ // which already disallow navigations from chrome URLs to blob/filesystem
+ // URLs.
+ if (site_url.SchemeIs(content::kChromeUIScheme) ||
+ site_url.SchemeIs(chrome::kChromeSearchScheme)) {
+ *result = true;
+ return true;
+ }
+
if (WebAccessibleResourcesInfo::IsResourceWebAccessible(to_extension,
to_url.path())) {
*result = true;
« no previous file with comments | « no previous file | chrome/browser/extensions/window_open_apitest.cc » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698