Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(27)

Issue 2803963002: Don't kill Chrome Apps that make XHRs from guests. (Closed)

Created:
3 years, 8 months ago by Charlie Reis
Modified:
3 years, 8 months ago
CC:
chromium-reviews, chromium-apps-reviews_chromium.org, extensions-reviews_chromium.org, site-isolation-reviews_chromium.org
Target Ref:
refs/heads/master
Project:
chromium
Visibility:
Public.

Description

Don't kill Chrome Apps that make XHRs from guests. It's possible for the app to make CORS requests from its guests without any webview-accessible-resources, via injected content scripts. BUG=613335 TEST=See bug comment 37 for a repro app. Review-Url: https://codereview.chromium.org/2803963002 Cr-Commit-Position: refs/heads/master@{#462704} Committed: https://chromium.googlesource.com/chromium/src/+/1d90c42584511fa8bf91f0eadddfe1634f9523fe

Patch Set 1 #

Total comments: 10

Patch Set 2 : Fix comments from review. #

Total comments: 2

Patch Set 3 : Update comment. #

Total comments: 4

Patch Set 4 : Fix nits. #

Messages

Total messages: 25 (14 generated)
Charlie Reis
Nick and Devlin, can you take a look? Now that we've confirmed that apps don't ...
3 years, 8 months ago (2017-04-06 16:18:17 UTC) #6
ncarter (slow)
nice work lgtm with one question https://codereview.chromium.org/2803963002/diff/1/chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc File chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc (right): https://codereview.chromium.org/2803963002/diff/1/chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc#newcode213 chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc:213: extensions::APIPermission::kWebView)) Do we ...
3 years, 8 months ago (2017-04-06 17:16:44 UTC) #7
Charlie Reis
Thanks! Devlin, can you take a look for owners approval? https://codereview.chromium.org/2803963002/diff/1/chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc File chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc (right): https://codereview.chromium.org/2803963002/diff/1/chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc#newcode213 ...
3 years, 8 months ago (2017-04-06 18:15:46 UTC) #8
Devlin
+lazyboy knows the webview test framework better than I do, so he may wanna take ...
3 years, 8 months ago (2017-04-06 18:32:13 UTC) #10
Charlie Reis
Thanks! lazyboy@, any thoughts before I land? https://codereview.chromium.org/2803963002/diff/1/chrome/test/data/extensions/platform_apps/web_view/content_script_fetch/content_script.js File chrome/test/data/extensions/platform_apps/web_view/content_script_fetch/content_script.js (right): https://codereview.chromium.org/2803963002/diff/1/chrome/test/data/extensions/platform_apps/web_view/content_script_fetch/content_script.js#newcode18 chrome/test/data/extensions/platform_apps/web_view/content_script_fetch/content_script.js:18: case 'start-fetch': ...
3 years, 8 months ago (2017-04-06 19:21:59 UTC) #11
alexmos
Drive-by nit https://codereview.chromium.org/2803963002/diff/20001/chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc File chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc (right): https://codereview.chromium.org/2803963002/diff/20001/chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc#newcode205 chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc:205: // itself, or by one if its ...
3 years, 8 months ago (2017-04-06 19:28:09 UTC) #14
Charlie Reis
https://codereview.chromium.org/2803963002/diff/20001/chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc File chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc (right): https://codereview.chromium.org/2803963002/diff/20001/chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc#newcode205 chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc:205: // itself, or by one if its guests if ...
3 years, 8 months ago (2017-04-06 20:21:03 UTC) #16
lazyboy
lgtm with tiny nits. https://codereview.chromium.org/2803963002/diff/40001/chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc File chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc (right): https://codereview.chromium.org/2803963002/diff/40001/chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc#newcode213 chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc:213: extensions::APIPermission::kWebView)) nit: {} https://codereview.chromium.org/2803963002/diff/40001/chrome/test/data/extensions/platform_apps/web_view/content_script_fetch/embedder.js File ...
3 years, 8 months ago (2017-04-06 21:03:29 UTC) #18
Charlie Reis
Thanks! https://codereview.chromium.org/2803963002/diff/40001/chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc File chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc (right): https://codereview.chromium.org/2803963002/diff/40001/chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc#newcode213 chrome/browser/extensions/chrome_content_browser_client_extensions_part.cc:213: extensions::APIPermission::kWebView)) On 2017/04/06 21:03:29, lazyboy wrote: > nit: ...
3 years, 8 months ago (2017-04-06 21:09:15 UTC) #19
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2803963002/60001
3 years, 8 months ago (2017-04-06 21:11:03 UTC) #22
commit-bot: I haz the power
3 years, 8 months ago (2017-04-07 00:23:05 UTC) #25
Message was sent while issue was closed.
Committed patchset #4 (id:60001) as
https://chromium.googlesource.com/chromium/src/+/1d90c42584511fa8bf91f0eadddf...

Powered by Google App Engine
This is Rietveld 408576698