Chromium Code Reviews
DescriptionAdd a configurable parse-depth limit when parsing JFV headers, and use it for Feature-Policy Header
The limit is deliberately set higher than the actual required depth
for a valid policy, so that strings which are malformed but not
malicious can still be passed through the Feature Policy header parser
which can emit more meaningful error messages.
BUG=662920
Committed: https://crrev.com/cb3e5ca8d303f10841d9985ff350d9fcbca49c9d
Cr-Commit-Position: refs/heads/master@{#434123}
Patch Set 1 #Patch Set 2 : Rebase #
Messages
Total messages: 15 (9 generated)
|
||||||||||||||||||||||||||||||||||||||||||||||