Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(414)

Unified Diff: content/browser/web_contents/web_contents_view_aura.cc

Issue 2568893002: Prevent drag-and-drop events from firing over cross-site, same-page frames. (Closed)
Patch Set: Created 4 years ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
« no previous file with comments | « content/browser/web_contents/web_contents_view_aura.h ('k') | no next file » | no next file with comments »
Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
Index: content/browser/web_contents/web_contents_view_aura.cc
diff --git a/content/browser/web_contents/web_contents_view_aura.cc b/content/browser/web_contents/web_contents_view_aura.cc
index 709ea5dd5d1cbccdfe063040cbdc20419c3638c7..dba6ff9264201fda8daf6e5d610fd3ef9bc8c896 100644
--- a/content/browser/web_contents/web_contents_view_aura.cc
+++ b/content/browser/web_contents/web_contents_view_aura.cc
@@ -516,6 +516,8 @@ WebContentsViewAura::WebContentsViewAura(WebContentsImpl* web_contents,
current_drag_op_(blink::WebDragOperationNone),
drag_dest_delegate_(nullptr),
current_rvh_for_drag_(nullptr),
+ drag_source_rph_(nullptr),
+ drag_source_rvh_(nullptr),
current_overscroll_gesture_(OVERSCROLL_NONE),
completed_overscroll_gesture_(OVERSCROLL_NONE),
navigation_overlay_(nullptr),
@@ -563,8 +565,8 @@ void WebContentsViewAura::EndDrag(RenderWidgetHost* source_rwh,
if (screen_position_client)
screen_position_client->ConvertPointFromScreen(window, &client_loc);
- // TODO(paulmeyer): In the OOPIF case, should |client_loc| be converted to
- // the coordinates local to |drag_start_rwh_|? See crbug.com/647249.
+ // TODO(paulmeyer): In the OOPIF case, should |client_loc| be converted to the
+ // coordinates local to |source_rwh|? See crbug.com/647249.
web_contents_->DragSourceEndedAt(client_loc.x(), client_loc.y(),
screen_loc.x(), screen_loc.y(), ops,
source_rwh);
@@ -907,6 +909,9 @@ void WebContentsViewAura::StartDragging(
base::WeakPtr<RenderWidgetHostImpl> source_rwh_weak_ptr =
source_rwh->GetWeakPtr();
+ drag_source_rph_ = source_rwh->GetProcess();
lfg 2016/12/12 20:34:21 Would it be possible that a RenderProcessHost is d
Charlie Reis 2016/12/12 20:57:02 Yes, I'm concerned about the void* pointers as wel
paulmeyer 2016/12/13 20:57:30 Done.
paulmeyer 2016/12/13 20:57:30 Done.
+ drag_source_rvh_ = web_contents_->GetRenderViewHost();
+
ui::TouchSelectionController* selection_controller = GetSelectionController();
if (selection_controller)
selection_controller->HideAndDisallowShowingAutomatically();
@@ -1130,12 +1135,18 @@ void WebContentsViewAura::OnMouseEvent(ui::MouseEvent* event) {
void WebContentsViewAura::OnDragEntered(const ui::DropTargetEvent& event) {
gfx::Point transformed_pt;
- current_rwh_for_drag_ =
+ RenderWidgetHostImpl* target_rwh =
web_contents_->GetInputEventRouter()->GetRenderWidgetHostAtPoint(
web_contents_->GetRenderViewHost()->GetWidget()->GetView(),
- event.location(), &transformed_pt)->GetWeakPtr();
- current_rvh_for_drag_ = web_contents_->GetRenderViewHost();
+ event.location(), &transformed_pt);
+
+ if (drag_source_rvh_ == web_contents_->GetRenderViewHost() &&
lfg 2016/12/12 20:34:21 I don't understand this check. This would only be
paulmeyer 2016/12/13 20:57:30 Per offline discussion, I will continue checking t
+ drag_source_rph_ != target_rwh->GetProcess()) {
+ return;
+ }
+ current_rwh_for_drag_ = target_rwh->GetWeakPtr();
+ current_rvh_for_drag_ = web_contents_->GetRenderViewHost();
current_drop_data_.reset(new DropData());
PrepareDropData(current_drop_data_.get(), event.data());
current_rwh_for_drag_->FilterDropData(current_drop_data_.get());
@@ -1171,6 +1182,11 @@ int WebContentsViewAura::OnDragUpdated(const ui::DropTargetEvent& event) {
web_contents_->GetRenderViewHost()->GetWidget()->GetView(),
event.location(), &transformed_pt);
+ if (drag_source_rvh_ == web_contents_->GetRenderViewHost() &&
+ drag_source_rph_ != target_rwh->GetProcess()) {
+ return ui::DragDropTypes::DRAG_NONE;
+ }
+
if (target_rwh != current_rwh_for_drag_.get()) {
if (current_rwh_for_drag_)
current_rwh_for_drag_->DragTargetDragLeave();
@@ -1216,6 +1232,11 @@ int WebContentsViewAura::OnPerformDrop(const ui::DropTargetEvent& event) {
web_contents_->GetRenderViewHost()->GetWidget()->GetView(),
event.location(), &transformed_pt);
+ if (drag_source_rvh_ == web_contents_->GetRenderViewHost() &&
+ drag_source_rph_ != target_rwh->GetProcess()) {
+ return ui::DragDropTypes::DRAG_NONE;
+ }
+
if (target_rwh != current_rwh_for_drag_.get()) {
if (current_rwh_for_drag_)
current_rwh_for_drag_->DragTargetDragLeave();
« no previous file with comments | « content/browser/web_contents/web_contents_view_aura.h ('k') | no next file » | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698