Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(109)

Unified Diff: content/browser/frame_host/navigator_impl.cc

Issue 2655463006: PlzNavigate: Enforce 'frame-src' CSP on the browser. (Closed)
Patch Set: Addressed comments Created 3 years, 9 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: content/browser/frame_host/navigator_impl.cc
diff --git a/content/browser/frame_host/navigator_impl.cc b/content/browser/frame_host/navigator_impl.cc
index b2533a84e915e1e3650933c5f2ec1a26d4289824..64f10d895fdb34dc91e2a6472a0e92ba6631ca88 100644
--- a/content/browser/frame_host/navigator_impl.cc
+++ b/content/browser/frame_host/navigator_impl.cc
@@ -231,7 +231,8 @@ void NavigatorImpl::DidStartProvisionalLoad(
validated_url, validated_redirect_chain,
render_frame_host->frame_tree_node(), is_renderer_initiated,
false, // is_same_page
- navigation_start, pending_nav_entry_id, started_from_context_menu));
+ navigation_start, pending_nav_entry_id, started_from_context_menu,
+ false)); // should_bypass_main_world_csp
}
void NavigatorImpl::DidFailProvisionalLoadWithError(
@@ -612,7 +613,8 @@ void NavigatorImpl::DidNavigate(
// Navigating to a new location means a new, fresh set of http headers and/or
// <meta> elements - we need to reset CSP and Feature Policy.
if (!is_navigation_within_page) {
- render_frame_host->frame_tree_node()->ResetContentSecurityPolicy();
+ render_frame_host->ResetContentSecurityPolicies();
+ render_frame_host->frame_tree_node()->ResetCspHeaders();
render_frame_host->frame_tree_node()->ResetFeaturePolicyHeader();
}
@@ -671,7 +673,7 @@ void NavigatorImpl::DidNavigate(
// stay correct even if the render_frame_host later becomes pending deletion.
// The URL is set regardless of whether it's for a net error or not.
render_frame_host->frame_tree_node()->SetCurrentURL(params.url);
- render_frame_host->set_last_committed_origin(params.origin);
+ render_frame_host->SetLastCommittedOrigin(params.origin);
// Separately, update the frame's last successful URL except for net error
// pages, since those do not end up in the correct process after transfers

Powered by Google App Engine
This is Rietveld 408576698