Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(200)

Issue 2744413002: Set view source without creating a unique origin in XMLDocumentParser (Closed)

Created:
3 years, 9 months ago by adithyas
Modified:
3 years, 9 months ago
CC:
blink-reviews, blink-reviews-dom_chromium.org, chromium-reviews, dglazkov+blink, dominicc+watchlist_chromium.org, eae+blinkwatch, rwlbuis, sof
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

Set view source without creating a unique origin in XMLDocumentParser BUG=697830 Review-Url: https://codereview.chromium.org/2744413002 Cr-Commit-Position: refs/heads/master@{#457168} Committed: https://chromium.googlesource.com/chromium/src/+/3de53e557c2b84aed1cb4ba9ed1133ac361da46c

Patch Set 1 #

Patch Set 2 : Add test #

Total comments: 2

Patch Set 3 : Remove unique security origin #

Unified diffs Side-by-side diffs Delta from patch set Stats (+15 lines, -8 lines) Patch
A third_party/WebKit/LayoutTests/http/tests/xmlviewer/no-unique-origin.html View 1 1 chunk +15 lines, -0 lines 0 comments Download
M third_party/WebKit/Source/core/dom/Document.cpp View 1 2 2 chunks +0 lines, -8 lines 0 comments Download

Messages

Total messages: 30 (17 generated)
adithyas
3 years, 9 months ago (2017-03-14 17:57:54 UTC) #6
haraken
LGTM but I want to have jochen@ confirm this.
3 years, 9 months ago (2017-03-14 18:13:34 UTC) #9
jochen (gone - plz use gerrit)
what kind of scripts do we run in the xml document? Similar to how we ...
3 years, 9 months ago (2017-03-14 20:13:53 UTC) #10
adithyas
On 2017/03/14 at 20:13:53, jochen wrote: > what kind of scripts do we run in ...
3 years, 9 months ago (2017-03-14 20:55:15 UTC) #13
adithyas
Actually, I tried looking into which document types use setViewSource, and its just the XML ...
3 years, 9 months ago (2017-03-14 22:35:34 UTC) #14
jochen (gone - plz use gerrit)
yeah, if we inject in an isolated world, we should be able to leave canExecuteScript ...
3 years, 9 months ago (2017-03-15 15:53:45 UTC) #15
adithyas
I removed the creation of a unique origin & the viewSource check in canExecuteScripts, PTAL.
3 years, 9 months ago (2017-03-15 18:17:46 UTC) #20
jochen (gone - plz use gerrit)
lgtm
3 years, 9 months ago (2017-03-15 18:38:49 UTC) #21
dcheng
LGTM based on the fact that https://cs.chromium.org/chromium/src/third_party/WebKit/Source/core/xml/DocumentXMLTreeViewer.cpp?dr=CSs seems to be using isolated worlds. However, I ...
3 years, 9 months ago (2017-03-15 18:48:05 UTC) #22
adithyas
On 2017/03/15 at 18:48:05, dcheng wrote: > LGTM based on the fact that https://cs.chromium.org/chromium/src/third_party/WebKit/Source/core/xml/DocumentXMLTreeViewer.cpp?dr=CSs seems ...
3 years, 9 months ago (2017-03-15 19:26:07 UTC) #23
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2744413002/40001
3 years, 9 months ago (2017-03-15 19:26:53 UTC) #26
commit-bot: I haz the power
Committed patchset #3 (id:40001) as https://chromium.googlesource.com/chromium/src/+/3de53e557c2b84aed1cb4ba9ed1133ac361da46c
3 years, 9 months ago (2017-03-15 19:37:23 UTC) #29
dcheng
3 years, 9 months ago (2017-03-15 19:51:55 UTC) #30
Message was sent while issue was closed.
On 2017/03/15 19:26:07, adithyas wrote:
> On 2017/03/15 at 18:48:05, dcheng wrote:
> > LGTM based on the fact that
>
https://cs.chromium.org/chromium/src/third_party/WebKit/Source/core/xml/Docum...
> seems to be using isolated worlds.
> > 
> > However, I am a bit nervous about this change overall. I'm wondering if two
> followup changes would make sense:
> > - Change view source to be a const field and set at construction time. This
> will be harder for the XML tree viewer, but we do have some precedent for
> switching documents during XML processing already:
>
https://cs.chromium.org/chromium/src/third_party/WebKit/Source/core/xml/XSLTP...
> > - Restrict script execution on view source docs to only be allowed in the
> view-source isolated world.
> > 
> > WDYT?
> 
> Hmm, currently only XMLTreeViewer seems to be running any script, so I don't
> know if we really need to be generalizing this right now for future cases.
> Right now, does being a view source document have any special significance
right
> now other than the fact it loads and uses a common stylesheet (i.e.
> view-source.css)? Calling setViewSource() right now just affects style and I
> don't know if that really needs to be set at construction time.

View source docs are kind of weird, and I want to make it less likely for weird
bugs to creep in. For example, we used to have this weird bug where content
scripts would be injected into view-source URLs: https://crbug.com/43384 -- so
if we could strongly enforce invariants we know should be true, that would help
preventatively.

Powered by Google App Engine
This is Rietveld 408576698