| Index: chrome/renderer/chrome_content_renderer_client.cc
|
| diff --git a/chrome/renderer/chrome_content_renderer_client.cc b/chrome/renderer/chrome_content_renderer_client.cc
|
| index c5bdf1e7733b8387e4fe70daa3118ee70a7ece3d..719eb1710cf7de8bbad97197814c05bd95382c8a 100644
|
| --- a/chrome/renderer/chrome_content_renderer_client.cc
|
| +++ b/chrome/renderer/chrome_content_renderer_client.cc
|
| @@ -485,6 +485,13 @@ void ChromeContentRendererClient::RenderThreadStarted() {
|
| ASCIIToUTF16(extensions::kExtensionResourceScheme));
|
| WebSecurityPolicy::registerURLSchemeAsSecure(extension_resource_scheme);
|
|
|
| + // chrome-search: and chrome-extension-resource: pages should not directly
|
| + // embed insecure resources.
|
| + WebSecurityPolicy::registerURLSchemeAsRestrictingMixedContent(
|
| + chrome_search_scheme);
|
| + WebSecurityPolicy::registerURLSchemeAsRestrictingMixedContent(
|
| + extension_resource_scheme);
|
| +
|
| // chrome:, chrome-extension:, chrome-extension-resource: resources should be
|
| // allowed to receive CORS requests.
|
| WebSecurityPolicy::registerURLSchemeAsCORSEnabled(extension_scheme);
|
|
|