Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(17)

Issue 2893483007: android:Early reject non-https origins for postMessage (Closed)

Created:
3 years, 7 months ago by Yusuf
Modified:
3 years, 7 months ago
Reviewers:
Benoit L
CC:
chromium-reviews, lizeb+watch-custom-tabs_chromium.org, agrieve+watch_chromium.org
Target Ref:
refs/heads/master
Project:
chromium
Visibility:
Public.

Description

Early reject non-https origins for postMessage For security reasons, we only accept https postMessage origins verified through Digital Asset Links for postMessage. Add a way to early reject all other origins. BUG=719096 Review-Url: https://codereview.chromium.org/2893483007 Cr-Commit-Position: refs/heads/master@{#473739} Committed: https://chromium.googlesource.com/chromium/src/+/fd352340a07c78ff117285aadcac01ac5af2aab1

Patch Set 1 #

Total comments: 2

Patch Set 2 : lizeb@ comments #

Patch Set 3 : Lint #

Unified diffs Side-by-side diffs Delta from patch set Stats (+35 lines, -0 lines) Patch
M chrome/android/java/src/org/chromium/chrome/browser/customtabs/OriginVerifier.java View 1 2 3 chunks +11 lines, -0 lines 0 comments Download
M chrome/android/javatests/src/org/chromium/chrome/browser/customtabs/ClientManagerTest.java View 2 chunks +24 lines, -0 lines 0 comments Download

Messages

Total messages: 20 (13 generated)
Yusuf
3 years, 7 months ago (2017-05-19 23:04:15 UTC) #6
Benoit L
lgtm with a small comment. Can you also start the commit message with "android:"? postMessage() ...
3 years, 7 months ago (2017-05-22 12:50:22 UTC) #7
Yusuf
https://codereview.chromium.org/2893483007/diff/1/chrome/android/java/src/org/chromium/chrome/browser/customtabs/OriginVerifier.java File chrome/android/java/src/org/chromium/chrome/browser/customtabs/OriginVerifier.java (right): https://codereview.chromium.org/2893483007/diff/1/chrome/android/java/src/org/chromium/chrome/browser/customtabs/OriginVerifier.java#newcode113 chrome/android/java/src/org/chromium/chrome/browser/customtabs/OriginVerifier.java:113: if (!mOrigin.getScheme().equals(UrlConstants.HTTPS_SCHEME)) { On 2017/05/22 12:50:22, Benoit L wrote: ...
3 years, 7 months ago (2017-05-22 22:00:16 UTC) #9
commit-bot: I haz the power
CQ is trying da patch. Follow status at: https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2893483007/20001
3 years, 7 months ago (2017-05-22 22:01:09 UTC) #12
commit-bot: I haz the power
Try jobs failed on following builders: android_n5x_swarming_rel on master.tryserver.chromium.android (JOB_FAILED, https://build.chromium.org/p/tryserver.chromium.android/builders/android_n5x_swarming_rel/builds/183855)
3 years, 7 months ago (2017-05-22 22:26:36 UTC) #14
commit-bot: I haz the power
CQ is trying da patch. Follow status at: https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2893483007/40001
3 years, 7 months ago (2017-05-22 22:35:09 UTC) #17
commit-bot: I haz the power
3 years, 7 months ago (2017-05-22 23:16:14 UTC) #20
Message was sent while issue was closed.
Committed patchset #3 (id:40001) as
https://chromium.googlesource.com/chromium/src/+/fd352340a07c78ff117285aadcac...

Powered by Google App Engine
This is Rietveld 408576698