Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(2442)

Unified Diff: content/browser/frame_host/frame_tree_node.h

Issue 2756913002: Revert of PlzNavigate: Enforce 'frame-src' CSP on the browser. (Closed)
Patch Set: Created 3 years, 9 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
« no previous file with comments | « content/browser/frame_host/ancestor_throttle.cc ('k') | content/browser/frame_host/frame_tree_node.cc » ('j') | no next file with comments »
Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
Index: content/browser/frame_host/frame_tree_node.h
diff --git a/content/browser/frame_host/frame_tree_node.h b/content/browser/frame_host/frame_tree_node.h
index f48f00c49e9b38424bce679210c51eb282b00086..7368c7f4a8611b23f72650560f58bb3dde748569 100644
--- a/content/browser/frame_host/frame_tree_node.h
+++ b/content/browser/frame_host/frame_tree_node.h
@@ -17,6 +17,7 @@
#include "content/browser/frame_host/render_frame_host_impl.h"
#include "content/browser/frame_host/render_frame_host_manager.h"
#include "content/common/content_export.h"
+#include "content/common/content_security_policy/content_security_policy.h"
#include "content/common/frame_owner_properties.h"
#include "content/common/frame_replication_state.h"
#include "third_party/WebKit/public/platform/WebInsecureRequestPolicy.h"
@@ -169,12 +170,14 @@
// Add CSP header to replication state, notify proxies about the update and
// enforce it on the browser.
- void AddContentSecurityPolicy(const ContentSecurityPolicyHeader& header);
+ void AddContentSecurityPolicy(
+ const ContentSecurityPolicyHeader& header,
+ const std::vector<ContentSecurityPolicy>& policies);
// Discards previous CSP headers and notifies proxies about the update.
// Typically invoked after committing navigation to a new document (since the
// new document comes with a fresh set of CSP http headers).
- void ResetCspHeaders();
+ void ResetContentSecurityPolicy();
// Sets the current insecure request policy, and notifies proxies about the
// update.
@@ -401,6 +404,9 @@
// to the core logic of FrameTreeNode.
FrameTreeNodeBlameContext blame_context_;
+ // A set of Content-Security-Policies to enforce on the browser-side.
+ std::vector<ContentSecurityPolicy> csp_policies_;
+
DISALLOW_COPY_AND_ASSIGN(FrameTreeNode);
};
« no previous file with comments | « content/browser/frame_host/ancestor_throttle.cc ('k') | content/browser/frame_host/frame_tree_node.cc » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698