Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(712)

Side by Side Diff: third_party/WebKit/Source/core/frame/History.h

Issue 2972073002: Mitigate the pushState IPC storm DoS. (Closed)
Patch Set: Move the check to |StateObjectAdded|. Created 3 years, 5 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
« no previous file with comments | « no previous file | third_party/WebKit/Source/core/frame/History.cpp » ('j') | no next file with comments »
Toggle Intra-line Diffs ('i') | Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
OLDNEW
1 /* 1 /*
2 * Copyright (C) 2007 Apple Inc. All rights reserved. 2 * Copyright (C) 2007 Apple Inc. All rights reserved.
3 * 3 *
4 * Redistribution and use in source and binary forms, with or without 4 * Redistribution and use in source and binary forms, with or without
5 * modification, are permitted provided that the following conditions 5 * modification, are permitted provided that the following conditions
6 * are met: 6 * are met:
7 * 1. Redistributions of source code must retain the above copyright 7 * 1. Redistributions of source code must retain the above copyright
8 * notice, this list of conditions and the following disclaimer. 8 * notice, this list of conditions and the following disclaimer.
9 * 2. Redistributions in binary form must reproduce the above copyright 9 * 2. Redistributions in binary form must reproduce the above copyright
10 * notice, this list of conditions and the following disclaimer in the 10 * notice, this list of conditions and the following disclaimer in the
11 * documentation and/or other materials provided with the distribution. 11 * documentation and/or other materials provided with the distribution.
12 * 12 *
13 * THIS SOFTWARE IS PROVIDED BY APPLE COMPUTER, INC. ``AS IS'' AND ANY 13 * THIS SOFTWARE IS PROVIDED BY APPLE COMPUTER, INC. ``AS IS'' AND ANY
14 * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 14 * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
15 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR 15 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
16 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL APPLE COMPUTER, INC. OR 16 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL APPLE COMPUTER, INC. OR
17 * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, 17 * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
18 * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, 18 * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
19 * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR 19 * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
20 * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY 20 * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY
21 * OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 21 * OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
22 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE 22 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
23 * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 23 * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
24 */ 24 */
25 25
26 #ifndef History_h 26 #ifndef History_h
27 #define History_h 27 #define History_h
28 28
29 #include <utility>
30
29 #include "base/gtest_prod_util.h" 31 #include "base/gtest_prod_util.h"
30 #include "bindings/core/v8/serialization/SerializedScriptValue.h" 32 #include "bindings/core/v8/serialization/SerializedScriptValue.h"
31 #include "core/dom/ContextLifecycleObserver.h" 33 #include "core/dom/ContextLifecycleObserver.h"
32 #include "core/loader/FrameLoaderTypes.h" 34 #include "core/loader/FrameLoaderTypes.h"
33 #include "platform/bindings/ScriptWrappable.h" 35 #include "platform/bindings/ScriptWrappable.h"
34 #include "platform/heap/Handle.h" 36 #include "platform/heap/Handle.h"
35 #include "platform/wtf/Forward.h" 37 #include "platform/wtf/Forward.h"
38 #include "platform/wtf/HashMap.h"
36 39
37 namespace blink { 40 namespace blink {
38 41
39 class LocalFrame; 42 class LocalFrame;
40 class KURL; 43 class KURL;
41 class ExceptionState; 44 class ExceptionState;
42 class SecurityOrigin; 45 class SecurityOrigin;
43 class ScriptState; 46 class ScriptState;
44 47
45 // This class corresponds to the History interface. 48 // This class corresponds to the History interface.
(...skipping 49 matching lines...) Expand 10 before | Expand all | Expand 10 after
95 98
96 void StateObjectAdded(PassRefPtr<SerializedScriptValue>, 99 void StateObjectAdded(PassRefPtr<SerializedScriptValue>,
97 const String& title, 100 const String& title,
98 const String& url, 101 const String& url,
99 HistoryScrollRestorationType, 102 HistoryScrollRestorationType,
100 FrameLoadType, 103 FrameLoadType,
101 ExceptionState&); 104 ExceptionState&);
102 SerializedScriptValue* StateInternal() const; 105 SerializedScriptValue* StateInternal() const;
103 HistoryScrollRestorationType ScrollRestorationInternal() const; 106 HistoryScrollRestorationType ScrollRestorationInternal() const;
104 107
108 bool IsHostFloodingPushState(const String& hostname) const;
109
105 RefPtr<SerializedScriptValue> last_state_object_requested_; 110 RefPtr<SerializedScriptValue> last_state_object_requested_;
111
112 using HostLimit = std::pair<int, double>;
113 using HostLimits = HashMap<String, HostLimit>;
114 mutable HostLimits host_limits;
dcheng 2017/07/06 23:03:40 As history is tied to the Window object, shall we
palmer 2017/07/06 23:53:06 Do you mean we don't need to keep track of the hos
106 }; 115 };
107 116
108 } // namespace blink 117 } // namespace blink
109 118
110 #endif // History_h 119 #endif // History_h
OLDNEW
« no previous file with comments | « no previous file | third_party/WebKit/Source/core/frame/History.cpp » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698