Chromium Code Reviews
Help | Chromium Project | Gerrit Changes | Sign in
(1)

Issue 2540983003: CSP: Dedicated workers always inherit policy. (Closed)

Can't Edit
Can't Publish+Mail
Start Review
Created:
8 months, 2 weeks ago by Mike West
Modified:
4 months, 4 weeks ago
CC:
blink-reviews, blink-worker-reviews_chromium.org, chromium-reviews, falken+watch_chromium.org, horo+watch_chromium.org, kinuko+worker_chromium.org, shimazu+worker_chromium.org
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

CSP: Dedicated workers always inherit policy. Based on the discussion in https://github.com/w3c/webappsec-csp/issues/146, we're dropping the distinct policy for dedicated workers; they will now always inherit the policy of their responsible document (just like every other script executing in that page's context). Intent to Ship: https://groups.google.com/a/chromium.org/d/msg/blink-dev/npKDoKVOUAs/ogtlIFmLBAAJ BUG=662930 Review-Url: https://codereview.chromium.org/2540983003 Cr-Commit-Position: refs/heads/master@{#458039} Committed: https://chromium.googlesource.com/chromium/src/+/d81303c8e08b491495d5fc425aaeb191f7be3418

Patch Set 1 #

Patch Set 2 : Rebase. #

Unified diffs Side-by-side diffs Delta from patch set Stats (+180 lines, -156 lines) Patch
M third_party/WebKit/LayoutTests/http/tests/security/contentSecurityPolicy/resources/testharness-helper.js View 1 chunk +9 lines, -0 lines 0 comments Download
D third_party/WebKit/LayoutTests/http/tests/security/contentSecurityPolicy/worker-connect-src-allowed.html View 1 chunk +0 lines, -29 lines 0 comments Download
D third_party/WebKit/LayoutTests/http/tests/security/contentSecurityPolicy/worker-connect-src-allowed-expected.txt View 1 chunk +0 lines, -2 lines 0 comments Download
D third_party/WebKit/LayoutTests/http/tests/security/contentSecurityPolicy/worker-connect-src-blocked.html View 1 chunk +0 lines, -29 lines 0 comments Download
D third_party/WebKit/LayoutTests/http/tests/security/contentSecurityPolicy/worker-connect-src-blocked-expected.txt View 1 chunk +0 lines, -4 lines 0 comments Download
M third_party/WebKit/LayoutTests/http/tests/security/contentSecurityPolicy/worker-eval-blocked.html View 1 1 chunk +6 lines, -4 lines 0 comments Download
D third_party/WebKit/LayoutTests/http/tests/security/contentSecurityPolicy/worker-multiple-csp-headers.html View 1 chunk +0 lines, -31 lines 0 comments Download
D third_party/WebKit/LayoutTests/http/tests/security/contentSecurityPolicy/worker-redirect-blocked-by-connect-src.html View 1 chunk +0 lines, -18 lines 0 comments Download
D third_party/WebKit/LayoutTests/http/tests/security/contentSecurityPolicy/worker-without-own-csp.html View 1 chunk +0 lines, -31 lines 0 comments Download
A third_party/WebKit/LayoutTests/http/tests/security/contentSecurityPolicy/workers/dedicated-eval.html View 1 chunk +37 lines, -0 lines 0 comments Download
A third_party/WebKit/LayoutTests/http/tests/security/contentSecurityPolicy/workers/dedicated-inheritance.html View 1 chunk +37 lines, -0 lines 0 comments Download
A third_party/WebKit/LayoutTests/http/tests/security/contentSecurityPolicy/workers/resources/connect-src-self.js View 1 chunk +64 lines, -0 lines 0 comments Download
A third_party/WebKit/LayoutTests/http/tests/security/contentSecurityPolicy/workers/resources/script-src-self.js View 1 chunk +25 lines, -0 lines 0 comments Download
M third_party/WebKit/Source/core/workers/InProcessWorkerBase.cpp View 1 2 chunks +0 lines, -2 lines 0 comments Download
M third_party/WebKit/Source/core/workers/InProcessWorkerMessagingProxy.h View 1 1 chunk +0 lines, -1 line 0 comments Download
M third_party/WebKit/Source/core/workers/InProcessWorkerMessagingProxy.cpp View 1 2 chunks +1 line, -4 lines 0 comments Download
M third_party/WebKit/Source/core/workers/WorkerScriptLoader.h View 1 2 chunks +1 line, -1 line 0 comments Download
Trybot results:  linux_chromium_rel_ng   ios-simulator   chromium_presubmit   win_chromium_x64_rel_ng   chromium_presubmit   linux_chromium_chromeos_rel_ng   win_clang   ios-device   linux_chromium_rel_ng   linux_chromium_asan_rel_ng   ios-simulator-xcode-clang   mac_chromium_rel_ng   linux_chromium_tsan_rel_ng   win_chromium_compile_dbg_ng   linux_chromium_chromeos_ozone_rel_ng   win_chromium_rel_ng   ios-device-xcode-clang   linux_chromium_compile_dbg_ng   ios-simulator   chromeos_daisy_chromium_compile_only_ng   mac_chromium_compile_dbg_ng   linux_android_rel_ng   android_clang_dbg_recipe   cast_shell_linux   android_arm64_dbg_recipe   android_compile_dbg   chromeos_amd64-generic_chromium_compile_only_ng   android_n5x_swarming_rel   android_cronet   cast_shell_android   linux_chromium_asan_rel_ng   linux_chromium_chromeos_rel_ng   linux_chromium_tsan_rel_ng   ios-device-xcode-clang   ios-simulator   chromium_presubmit   linux_chromium_chromeos_ozone_rel_ng   linux_chromium_rel_ng   cast_shell_android   ios-device   android_clang_dbg_recipe   win_clang   win_chromium_compile_dbg_ng   chromeos_daisy_chromium_compile_only_ng   mac_chromium_compile_dbg_ng   linux_android_rel_ng   android_cronet   win_chromium_rel_ng   mac_chromium_rel_ng   ios-simulator-xcode-clang   android_arm64_dbg_recipe   android_compile_dbg   win_chromium_x64_rel_ng   chromeos_amd64-generic_chromium_compile_only_ng   linux_chromium_compile_dbg_ng   cast_shell_linux   android_n5x_swarming_rel 
Commit queue not available (can’t edit this change).

Depends on Patchset:

Dependent Patchsets:

Messages

Total messages: 21 (17 generated)
Mike West
Emily, Jochen, Andy, WDYT about this followup to https://codereview.chromium.org/2533313002?
5 months ago (2017-03-17 12:26:42 UTC) #10
jochen (gone - plz use gerrit)
lgtm
4 months, 4 weeks ago (2017-03-20 07:23:28 UTC) #13
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2540983003/20001
4 months, 4 weeks ago (2017-03-20 09:11:24 UTC) #18
commit-bot: I haz the power
4 months, 4 weeks ago (2017-03-20 11:28:15 UTC) #21
Message was sent while issue was closed.
Committed patchset #2 (id:20001) as
https://chromium.googlesource.com/chromium/src/+/d81303c8e08b491495d5fc425aae...
Sign in to reply to this message.

Powered by Google App Engine
RSS Feeds Recent Issues | This issue
This is Rietveld b40b6558b