Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(83)

Unified Diff: content/browser/frame_host/navigator_impl.cc

Issue 2655463006: PlzNavigate: Enforce 'frame-src' CSP on the browser. (Closed)
Patch Set: Rebase. Created 3 years, 9 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: content/browser/frame_host/navigator_impl.cc
diff --git a/content/browser/frame_host/navigator_impl.cc b/content/browser/frame_host/navigator_impl.cc
index 95de1ccbbea9c12bd299148a1845846e7a4c4ce8..9c6d3a43fa5335f7ed4257f36b2957389906c3c0 100644
--- a/content/browser/frame_host/navigator_impl.cc
+++ b/content/browser/frame_host/navigator_impl.cc
@@ -231,7 +231,8 @@ void NavigatorImpl::DidStartProvisionalLoad(
validated_url, validated_redirect_chain,
render_frame_host->frame_tree_node(), is_renderer_initiated,
false, // is_same_page
- navigation_start, pending_nav_entry_id, started_from_context_menu));
+ navigation_start, pending_nav_entry_id, started_from_context_menu,
+ CSPDisposition::CHECK)); // should_check_main_world_csp
}
void NavigatorImpl::DidFailProvisionalLoadWithError(
@@ -606,7 +607,8 @@ void NavigatorImpl::DidNavigate(
// Navigating to a new location means a new, fresh set of http headers and/or
// <meta> elements - we need to reset CSP and Feature Policy.
if (!is_navigation_within_page) {
- render_frame_host->frame_tree_node()->ResetContentSecurityPolicy();
+ render_frame_host->ResetContentSecurityPolicies();
+ render_frame_host->frame_tree_node()->ResetCspHeaders();
render_frame_host->frame_tree_node()->ResetFeaturePolicyHeader();
}
@@ -665,7 +667,7 @@ void NavigatorImpl::DidNavigate(
// stay correct even if the render_frame_host later becomes pending deletion.
// The URL is set regardless of whether it's for a net error or not.
render_frame_host->frame_tree_node()->SetCurrentURL(params.url);
- render_frame_host->set_last_committed_origin(params.origin);
+ render_frame_host->SetLastCommittedOrigin(params.origin);
// Separately, update the frame's last successful URL except for net error
// pages, since those do not end up in the correct process after transfers
« no previous file with comments | « content/browser/frame_host/navigation_request.cc ('k') | content/browser/frame_host/render_frame_host_impl.h » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698