Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(145)

Issue 2768863003: Fix webview-accessible resource checks in AllowCrossRendererResourceLoadHelper (Closed)

Created:
3 years, 9 months ago by alexmos
Modified:
3 years, 9 months ago
Reviewers:
Devlin, lazyboy, lfg
CC:
chromium-reviews, chromium-apps-reviews_chromium.org, extensions-reviews_chromium.org, robwu, paulmeyer
Target Ref:
refs/heads/master
Project:
chromium
Visibility:
Public.

Description

Fix webview-accessible resource checks in AllowCrossRendererResourceLoadHelper AllowCrossRendererResourceLoadHelper is supposed to check whether a resource that a webview guest tries to load is webview-accessible [1], and denies the load if it isn't. However, it currently has an exception for all web-triggerable page transitions, blindly allowing them through. This allows a webview to happily navigate itself to non-webview-accessible resources. The page transition exception seems wrong, and rob@robwu.nl made a detailed analysis of how we ended up with it in https://crbug.com/633963#c14. This CL removes it. The fix was originally proposed by Rob in https://crbug.com/640072. [1] https://developer.chrome.com/apps/tags/webview#local_resources BUG=640072, 691941 Review-Url: https://codereview.chromium.org/2768863003 Cr-Commit-Position: refs/heads/master@{#459326} Committed: https://chromium.googlesource.com/chromium/src/+/a7d08ae5f1e081b95ae6f4e1f163cbd0be6dc075

Patch Set 1 #

Patch Set 2 : Cleanup #

Total comments: 2
Unified diffs Side-by-side diffs Delta from patch set Stats (+68 lines, -10 lines) Patch
M chrome/browser/apps/guest_view/web_view_browsertest.cc View 1 chunk +20 lines, -0 lines 0 comments Download
M chrome/test/data/extensions/platform_apps/web_view/load_webview_accessible_resource/embedder.js View 2 chunks +39 lines, -0 lines 0 comments Download
M extensions/browser/url_request_util.cc View 1 1 chunk +9 lines, -10 lines 2 comments Download

Depends on Patchset:

Messages

Total messages: 22 (15 generated)
alexmos
Lucas, can you please take a look? We discussed this a while back, and I ...
3 years, 9 months ago (2017-03-23 18:23:54 UTC) #10
lfg
Thanks for fixing this, lgtm. https://codereview.chromium.org/2768863003/diff/20001/extensions/browser/url_request_util.cc File extensions/browser/url_request_util.cc (right): https://codereview.chromium.org/2768863003/diff/20001/extensions/browser/url_request_util.cc#newcode158 extensions/browser/url_request_util.cc:158: if (owner_extension != extension) ...
3 years, 9 months ago (2017-03-23 18:49:40 UTC) #11
alexmos
Thanks, adding OWNERS: - Devlin for extensions/browser/url_request_util.cc - lazyboy@ for web_view_browsertest.cc
3 years, 9 months ago (2017-03-23 21:20:44 UTC) #15
Devlin
Yay! lgtm
3 years, 9 months ago (2017-03-23 21:33:40 UTC) #16
lazyboy
tests lgtm.
3 years, 9 months ago (2017-03-24 01:08:26 UTC) #17
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2768863003/20001
3 years, 9 months ago (2017-03-24 01:13:57 UTC) #19
commit-bot: I haz the power
3 years, 9 months ago (2017-03-24 01:24:03 UTC) #22
Message was sent while issue was closed.
Committed patchset #2 (id:20001) as
https://chromium.googlesource.com/chromium/src/+/a7d08ae5f1e081b95ae6f4e1f163...

Powered by Google App Engine
This is Rietveld 408576698