Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(507)

Issue 906453002: ServiceWorker: Make browser-side check stricter for non-HTTP(s) schemes (Closed)

Created:
5 years, 10 months ago by kinuko
Modified:
5 years, 10 months ago
Reviewers:
falken
CC:
chromium-reviews, michaeln, jsbell+serviceworker_chromium.org, tzik, serviceworker-reviews, jam, nhiroki, darin-cc_chromium.org, horo+watch_chromium.org, kinuko+serviceworker, kinuko+watch
Base URL:
https://chromium.googlesource.com/chromium/src.git@master
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

ServiceWorker: Make browser-side check stricter for non-HTTP(s) schemes As a follow-up for filesystem: URL patch: https://code.google.com/p/chromium/issues/detail?id=453982 As of http://src.chromium.org/viewvc/blink?view=revision&revision=189570 we started to check non-HTTP(s) schemes in renderer process, so any requests for registering non-HTTP(s) schemes in the browser should be considererd malicious / invalid and we should just do BadMessageReceived(). BUG=455115 TEST=ServiceWorkerDispatcherHostTest.* TEST=no layout tests should crash swith this change Committed: https://crrev.com/3cfec3142d8b6dbb1cecb03125aa81bbbcda6500 Cr-Commit-Position: refs/heads/master@{#315199}

Patch Set 1 #

Patch Set 2 : #

Unified diffs Side-by-side diffs Delta from patch set Stats (+64 lines, -85 lines) Patch
M content/browser/service_worker/service_worker_dispatcher_host.cc View 4 chunks +3 lines, -20 lines 0 comments Download
M content/browser/service_worker/service_worker_dispatcher_host_unittest.cc View 1 10 chunks +61 lines, -65 lines 0 comments Download

Messages

Total messages: 9 (3 generated)
kinuko
PTL
5 years, 10 months ago (2015-02-06 07:55:24 UTC) #2
falken
lgtm but Register_NonSecureOriginShouldFail is failing, looks like the test just needs to be updated.
5 years, 10 months ago (2015-02-06 10:26:27 UTC) #3
kinuko
On 2015/02/06 10:26:27, falken wrote: > lgtm but Register_NonSecureOriginShouldFail is failing, looks like the test ...
5 years, 10 months ago (2015-02-07 07:58:57 UTC) #5
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/patch-status/906453002/20001
5 years, 10 months ago (2015-02-07 07:59:07 UTC) #7
commit-bot: I haz the power
Committed patchset #2 (id:20001)
5 years, 10 months ago (2015-02-07 12:34:49 UTC) #8
commit-bot: I haz the power
5 years, 10 months ago (2015-02-07 12:36:06 UTC) #9
Message was sent while issue was closed.
Patchset 2 (id:??) landed as
https://crrev.com/3cfec3142d8b6dbb1cecb03125aa81bbbcda6500
Cr-Commit-Position: refs/heads/master@{#315199}

Powered by Google App Engine
This is Rietveld 408576698