Index: chrome/renderer/chrome_content_renderer_client.cc |
diff --git a/chrome/renderer/chrome_content_renderer_client.cc b/chrome/renderer/chrome_content_renderer_client.cc |
index c5bdf1e7733b8387e4fe70daa3118ee70a7ece3d..719eb1710cf7de8bbad97197814c05bd95382c8a 100644 |
--- a/chrome/renderer/chrome_content_renderer_client.cc |
+++ b/chrome/renderer/chrome_content_renderer_client.cc |
@@ -485,6 +485,13 @@ void ChromeContentRendererClient::RenderThreadStarted() { |
ASCIIToUTF16(extensions::kExtensionResourceScheme)); |
WebSecurityPolicy::registerURLSchemeAsSecure(extension_resource_scheme); |
+ // chrome-search: and chrome-extension-resource: pages should not directly |
+ // embed insecure resources. |
+ WebSecurityPolicy::registerURLSchemeAsRestrictingMixedContent( |
+ chrome_search_scheme); |
+ WebSecurityPolicy::registerURLSchemeAsRestrictingMixedContent( |
+ extension_resource_scheme); |
+ |
// chrome:, chrome-extension:, chrome-extension-resource: resources should be |
// allowed to receive CORS requests. |
WebSecurityPolicy::registerURLSchemeAsCORSEnabled(extension_scheme); |