Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(43)

Issue 2747823002: CSP: New test with form-action and a redirect into a new window. (Closed)

Created:
3 years, 9 months ago by arthursonzogni
Modified:
3 years, 9 months ago
Reviewers:
Mike West
CC:
alexmos, blink-reviews, chromium-reviews, clamy, jam, nasko
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

CSP: New test with form-action and a redirect into a new window. This test shows that the CSP of the navigating frame are used instead of the CSP of the frame that has initiated the navigation. BUG=700964 Review-Url: https://codereview.chromium.org/2747823002 Cr-Commit-Position: refs/heads/master@{#456656} Committed: https://chromium.googlesource.com/chromium/src/+/def680801ab5c196b089e67a6e2a1d3768b4a7d3

Patch Set 1 : CSP: New test with form-action and a redirect into a new window. #

Messages

Total messages: 14 (9 generated)
arthursonzogni
Hi Mike, Can you take a look? This test shows that during a navigation, the ...
3 years, 9 months ago (2017-03-13 17:27:23 UTC) #5
Mike West
LGTM, thanks for filing the bug.
3 years, 9 months ago (2017-03-13 20:04:12 UTC) #8
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2747823002/20001
3 years, 9 months ago (2017-03-14 08:41:28 UTC) #10
commit-bot: I haz the power
Committed patchset #1 (id:20001) as https://chromium.googlesource.com/chromium/src/+/def680801ab5c196b089e67a6e2a1d3768b4a7d3
3 years, 9 months ago (2017-03-14 08:45:40 UTC) #13
arthursonzogni
3 years, 9 months ago (2017-03-14 16:45:08 UTC) #14
Message was sent while issue was closed.
A revert of this CL (patchset #1 id:20001) has been created in
https://codereview.chromium.org/2746333004/ by arthursonzogni@chromium.org.

The reason for reverting is: It looks like the test is passing with
site-isolation, so they have the wrong file expectation. There is also a minor
problem when accessing namedWindow.location.href.

I will fix the test and try to understand why it seems to work with
site-isolation..

Powered by Google App Engine
This is Rietveld 408576698