Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(56)

Side by Side Diff: Source/core/dom/ScriptLoader.cpp

Issue 566083003: Implementation of subresource integrity attribute for secure origins. (Closed) Base URL: https://chromium.googlesource.com/chromium/blink.git@master
Patch Set: Fixed broken build Created 6 years, 3 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
« no previous file with comments | « Source/core/core.gypi ('k') | Source/core/frame/SubresourceIntegrity.h » ('j') | no next file with comments »
Toggle Intra-line Diffs ('i') | Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
OLDNEW
1 /* 1 /*
2 * Copyright (C) 1999 Lars Knoll (knoll@kde.org) 2 * Copyright (C) 1999 Lars Knoll (knoll@kde.org)
3 * (C) 1999 Antti Koivisto (koivisto@kde.org) 3 * (C) 1999 Antti Koivisto (koivisto@kde.org)
4 * (C) 2001 Dirk Mueller (mueller@kde.org) 4 * (C) 2001 Dirk Mueller (mueller@kde.org)
5 * Copyright (C) 2003, 2004, 2005, 2006, 2007, 2008 Apple Inc. All rights reserv ed. 5 * Copyright (C) 2003, 2004, 2005, 2006, 2007, 2008 Apple Inc. All rights reserv ed.
6 * Copyright (C) 2008 Nikolas Zimmermann <zimmermann@kde.org> 6 * Copyright (C) 2008 Nikolas Zimmermann <zimmermann@kde.org>
7 * 7 *
8 * This library is free software; you can redistribute it and/or 8 * This library is free software; you can redistribute it and/or
9 * modify it under the terms of the GNU Library General Public 9 * modify it under the terms of the GNU Library General Public
10 * License as published by the Free Software Foundation; either 10 * License as published by the Free Software Foundation; either
(...skipping 24 matching lines...) Expand all
35 #include "core/dom/ScriptRunner.h" 35 #include "core/dom/ScriptRunner.h"
36 #include "core/dom/ScriptableDocumentParser.h" 36 #include "core/dom/ScriptableDocumentParser.h"
37 #include "core/dom/Text.h" 37 #include "core/dom/Text.h"
38 #include "core/fetch/FetchRequest.h" 38 #include "core/fetch/FetchRequest.h"
39 #include "core/fetch/ResourceFetcher.h" 39 #include "core/fetch/ResourceFetcher.h"
40 #include "core/fetch/ScriptResource.h" 40 #include "core/fetch/ScriptResource.h"
41 #include "core/html/HTMLScriptElement.h" 41 #include "core/html/HTMLScriptElement.h"
42 #include "core/html/imports/HTMLImport.h" 42 #include "core/html/imports/HTMLImport.h"
43 #include "core/html/parser/HTMLParserIdioms.h" 43 #include "core/html/parser/HTMLParserIdioms.h"
44 #include "core/frame/LocalFrame.h" 44 #include "core/frame/LocalFrame.h"
45 #include "core/frame/SubresourceIntegrity.h"
45 #include "core/frame/csp/ContentSecurityPolicy.h" 46 #include "core/frame/csp/ContentSecurityPolicy.h"
46 #include "core/inspector/ConsoleMessage.h" 47 #include "core/inspector/ConsoleMessage.h"
47 #include "core/svg/SVGScriptElement.h" 48 #include "core/svg/SVGScriptElement.h"
48 #include "platform/MIMETypeRegistry.h" 49 #include "platform/MIMETypeRegistry.h"
49 #include "platform/weborigin/SecurityOrigin.h" 50 #include "platform/weborigin/SecurityOrigin.h"
50 #include "wtf/StdLibExtras.h" 51 #include "wtf/StdLibExtras.h"
51 #include "wtf/text/StringBuilder.h" 52 #include "wtf/text/StringBuilder.h"
52 #include "wtf/text/StringHash.h" 53 #include "wtf/text/StringHash.h"
53 54
54 namespace blink { 55 namespace blink {
(...skipping 260 matching lines...) Expand 10 before | Expand all | Expand 10 after
315 316
316 if (!m_isExternalScript && (!shouldBypassMainWorldCSP && !csp->allowInlineSc ript(elementDocument->url(), m_startLineNumber))) 317 if (!m_isExternalScript && (!shouldBypassMainWorldCSP && !csp->allowInlineSc ript(elementDocument->url(), m_startLineNumber)))
317 return; 318 return;
318 319
319 if (m_isExternalScript) { 320 if (m_isExternalScript) {
320 ScriptResource* resource = m_resource ? m_resource.get() : sourceCode.re source(); 321 ScriptResource* resource = m_resource ? m_resource.get() : sourceCode.re source();
321 if (resource && !resource->mimeTypeAllowedByNosniff()) { 322 if (resource && !resource->mimeTypeAllowedByNosniff()) {
322 contextDocument->addConsoleMessage(ConsoleMessage::create(SecurityMe ssageSource, ErrorMessageLevel, "Refused to execute script from '" + resource->u rl().elidedString() + "' because its MIME type ('" + resource->mimeType() + "') is not executable, and strict MIME type checking is enabled.")); 323 contextDocument->addConsoleMessage(ConsoleMessage::create(SecurityMe ssageSource, ErrorMessageLevel, "Refused to execute script from '" + resource->u rl().elidedString() + "' because its MIME type ('" + resource->mimeType() + "') is not executable, and strict MIME type checking is enabled."));
323 return; 324 return;
324 } 325 }
326
327 // FIXME: On failure, SRI should probably provide an error message for t he console.
328 if (!SubresourceIntegrity::CheckSubresourceIntegrity(*m_element, sourceC ode.source(), sourceCode.resource()->url()))
329 return;
325 } 330 }
326 331
327 // FIXME: Can this be moved earlier in the function? 332 // FIXME: Can this be moved earlier in the function?
328 // Why are we ever attempting to execute scripts without a frame? 333 // Why are we ever attempting to execute scripts without a frame?
329 if (!frame) 334 if (!frame)
330 return; 335 return;
331 336
332 const bool isImportedScript = contextDocument != elementDocument; 337 const bool isImportedScript = contextDocument != elementDocument;
333 // http://www.whatwg.org/specs/web-apps/current-work/#execute-the-script-blo ck step 2.3 338 // http://www.whatwg.org/specs/web-apps/current-work/#execute-the-script-blo ck step 2.3
334 // with additional support for HTML imports. 339 // with additional support for HTML imports.
(...skipping 111 matching lines...) Expand 10 before | Expand all | Expand 10 after
446 if (isHTMLScriptLoader(element)) 451 if (isHTMLScriptLoader(element))
447 return toHTMLScriptElement(element)->loader(); 452 return toHTMLScriptElement(element)->loader();
448 453
449 if (isSVGScriptLoader(element)) 454 if (isSVGScriptLoader(element))
450 return toSVGScriptElement(element)->loader(); 455 return toSVGScriptElement(element)->loader();
451 456
452 return 0; 457 return 0;
453 } 458 }
454 459
455 } 460 }
OLDNEW
« no previous file with comments | « Source/core/core.gypi ('k') | Source/core/frame/SubresourceIntegrity.h » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698