Issue #2736 - Part 3: Use TriggeringPrincipal for image loads.

The imgLoader code consistently uses the term `loadingPrincipal` for
the principal that is called the `triggeringPrincipal` everywhere else.
This aligns the naming to avoid confusion in later changes.
This commit is contained in:
Moonchild 2025-04-28 10:04:07 +02:00 • committed by roytam1
commit 166b25a42c
3 changed files with 49 additions and 48 deletions

View file

@ -547,7 +547,7 @@ ShouldRevalidateEntry(imgCacheEntry* aEntry,
static bool static bool
ShouldLoadCachedImage(imgRequest* aImgRequest, ShouldLoadCachedImage(imgRequest* aImgRequest,
nsISupports* aLoadingContext, nsISupports* aLoadingContext,
nsIPrincipal* aLoadingPrincipal, nsIPrincipal* aTriggeringPrincipal,
nsContentPolicyType aPolicyType) nsContentPolicyType aPolicyType)
{ {
/* Call content policies on cached images - Bug 1082837 /* Call content policies on cached images - Bug 1082837
@ -567,8 +567,8 @@ ShouldLoadCachedImage(imgRequest* aImgRequest,
int16_t decision = nsIContentPolicy::REJECT_REQUEST; int16_t decision = nsIContentPolicy::REJECT_REQUEST;
rv = NS_CheckContentLoadPolicy(aPolicyType, rv = NS_CheckContentLoadPolicy(aPolicyType,
contentLocation, contentLocation,
aLoadingPrincipal, // loading principal aTriggeringPrincipal, // loading principal
aLoadingPrincipal, // triggering principal aTriggeringPrincipal, // triggering principal
aLoadingContext, aLoadingContext,
EmptyCString(), //mime guess EmptyCString(), //mime guess
nullptr, //aExtra nullptr, //aExtra
@ -582,11 +582,11 @@ ShouldLoadCachedImage(imgRequest* aImgRequest,
// We call all Content Policies above, but we also have to call mcb // We call all Content Policies above, but we also have to call mcb
// individually to check the intermediary redirect hops are secure. // individually to check the intermediary redirect hops are secure.
if (insecureRedirect) { if (insecureRedirect) {
if (!nsContentUtils::IsSystemPrincipal(aLoadingPrincipal)) { if (!nsContentUtils::IsSystemPrincipal(aTriggeringPrincipal)) {
// Set the requestingLocation from the aLoadingPrincipal. // Set the requestingLocation from the aTriggeringPrincipal.
nsCOMPtr<nsIURI> requestingLocation; nsCOMPtr<nsIURI> requestingLocation;
if (aLoadingPrincipal) { if (aTriggeringPrincipal) {
rv = aLoadingPrincipal->GetURI(getter_AddRefs(requestingLocation)); rv = aTriggeringPrincipal->GetURI(getter_AddRefs(requestingLocation));
NS_ENSURE_SUCCESS(rv, false); NS_ENSURE_SUCCESS(rv, false);
} }
@ -599,7 +599,7 @@ ShouldLoadCachedImage(imgRequest* aImgRequest,
aLoadingContext, aLoadingContext,
EmptyCString(), //mime guess EmptyCString(), //mime guess
nullptr, nullptr,
aLoadingPrincipal, aTriggeringPrincipal,
&decision); &decision);
if (NS_FAILED(rv) || !NS_CP_ACCEPTED(decision)) { if (NS_FAILED(rv) || !NS_CP_ACCEPTED(decision)) {
return false; return false;
@ -616,7 +616,7 @@ ShouldLoadCachedImage(imgRequest* aImgRequest,
// referrers/policies may generate different responses. // referrers/policies may generate different responses.
static bool static bool
ValidateSecurityInfo(imgRequest* request, bool forcePrincipalCheck, ValidateSecurityInfo(imgRequest* request, bool forcePrincipalCheck,
int32_t corsmode, nsIPrincipal* loadingPrincipal, int32_t corsmode, nsIPrincipal* triggeringPrincipal,
nsISupports* aCX, nsContentPolicyType aPolicyType, nsISupports* aCX, nsContentPolicyType aPolicyType,
ReferrerPolicy referrerPolicy) ReferrerPolicy referrerPolicy)
{ {
@ -634,17 +634,17 @@ ValidateSecurityInfo(imgRequest* request, bool forcePrincipalCheck,
return false; return false;
} else if (request->GetCORSMode() != imgIRequest::CORS_NONE || } else if (request->GetCORSMode() != imgIRequest::CORS_NONE ||
forcePrincipalCheck) { forcePrincipalCheck) {
nsCOMPtr<nsIPrincipal> otherprincipal = request->GetLoadingPrincipal(); nsCOMPtr<nsIPrincipal> otherprincipal = request->GetTriggeringPrincipal();
// If we previously had a principal, but we don't now, we can't use this // If we previously had a principal, but we don't now, we can't use this
// request. // request.
if (otherprincipal && !loadingPrincipal) { if (otherprincipal && !triggeringPrincipal) {
return false; return false;
} }
if (otherprincipal && loadingPrincipal) { if (otherprincipal && triggeringPrincipal) {
bool equals = false; bool equals = false;
otherprincipal->Equals(loadingPrincipal, &equals); otherprincipal->Equals(triggeringPrincipal, &equals);
if (!equals) { if (!equals) {
return false; return false;
} }
@ -652,7 +652,7 @@ ValidateSecurityInfo(imgRequest* request, bool forcePrincipalCheck,
} }
// Content Policy Check on Cached Images // Content Policy Check on Cached Images
return ShouldLoadCachedImage(request, aCX, loadingPrincipal, aPolicyType); return ShouldLoadCachedImage(request, aCX, triggeringPrincipal, aPolicyType);
} }
static nsresult static nsresult
@ -662,7 +662,7 @@ NewImageChannel(nsIChannel** aResult,
// assuming we have a cache hit on a cache entry that we // assuming we have a cache hit on a cache entry that we
// create for this channel. This is an out param that should // create for this channel. This is an out param that should
// be set to true if this channel ends up depending on // be set to true if this channel ends up depending on
// aLoadingPrincipal and false otherwise. // aTriggeringPrincipal and false otherwise.
bool* aForcePrincipalCheckForCacheEntry, bool* aForcePrincipalCheckForCacheEntry,
nsIURI* aURI, nsIURI* aURI,
nsIURI* aInitialDocumentURI, nsIURI* aInitialDocumentURI,
@ -673,7 +673,7 @@ NewImageChannel(nsIChannel** aResult,
const nsCString& aAcceptHeader, const nsCString& aAcceptHeader,
nsLoadFlags aLoadFlags, nsLoadFlags aLoadFlags,
nsContentPolicyType aPolicyType, nsContentPolicyType aPolicyType,
nsIPrincipal* aLoadingPrincipal, nsIPrincipal* aTriggeringPrincipal,
nsISupports* aRequestingContext, nsISupports* aRequestingContext,
bool aRespectPrivacy) bool aRespectPrivacy)
{ {
@ -720,11 +720,11 @@ NewImageChannel(nsIChannel** aResult,
// node and a principal. This is for things like background images that are // node and a principal. This is for things like background images that are
// specified by user stylesheets, where the document is being styled, but // specified by user stylesheets, where the document is being styled, but
// the principal is that of the user stylesheet. // the principal is that of the user stylesheet.
if (requestingNode && aLoadingPrincipal) { if (requestingNode && aTriggeringPrincipal) {
rv = NS_NewChannelWithTriggeringPrincipal(aResult, rv = NS_NewChannelWithTriggeringPrincipal(aResult,
aURI, aURI,
requestingNode, requestingNode,
aLoadingPrincipal, aTriggeringPrincipal,
securityFlags, securityFlags,
aPolicyType, aPolicyType,
nullptr, // loadGroup nullptr, // loadGroup
@ -737,10 +737,10 @@ NewImageChannel(nsIChannel** aResult,
if (aPolicyType == nsIContentPolicy::TYPE_INTERNAL_IMAGE_FAVICON) { if (aPolicyType == nsIContentPolicy::TYPE_INTERNAL_IMAGE_FAVICON) {
// If this is a favicon loading, we will use the originAttributes from the // If this is a favicon loading, we will use the originAttributes from the
// loadingPrincipal as the channel's originAttributes. This allows the favicon // triggeringPrincipal as the channel's originAttributes. This allows the favicon
// loading from XUL will use the correct originAttributes. // loading from XUL will use the correct originAttributes.
NeckoOriginAttributes neckoAttrs; NeckoOriginAttributes neckoAttrs;
neckoAttrs.InheritFromDocToNecko(BasePrincipal::Cast(aLoadingPrincipal)->OriginAttributesRef()); neckoAttrs.InheritFromDocToNecko(BasePrincipal::Cast(aTriggeringPrincipal)->OriginAttributesRef());
nsCOMPtr<nsILoadInfo> loadInfo = (*aResult)->GetLoadInfo(); nsCOMPtr<nsILoadInfo> loadInfo = (*aResult)->GetLoadInfo();
rv = loadInfo->SetOriginAttributes(neckoAttrs); rv = loadInfo->SetOriginAttributes(neckoAttrs);
@ -748,7 +748,7 @@ NewImageChannel(nsIChannel** aResult,
} else { } else {
// either we are loading something inside a document, in which case // either we are loading something inside a document, in which case
// we should always have a requestingNode, or we are loading something // we should always have a requestingNode, or we are loading something
// outside a document, in which case the loadingPrincipal and // outside a document, in which case the triggeringPrincipal and
// triggeringPrincipal should always be the systemPrincipal. // triggeringPrincipal should always be the systemPrincipal.
// However, there are exceptions: one is Notifications which create a // However, there are exceptions: one is Notifications which create a
// channel in the parent prcoess in which case we can't get a requestingNode. // channel in the parent prcoess in which case we can't get a requestingNode.
@ -769,8 +769,8 @@ NewImageChannel(nsIChannel** aResult,
// and adjust the private browsing ID based on what kind of load the caller // and adjust the private browsing ID based on what kind of load the caller
// has asked us to perform. // has asked us to perform.
NeckoOriginAttributes neckoAttrs; NeckoOriginAttributes neckoAttrs;
if (aLoadingPrincipal) { if (aTriggeringPrincipal) {
neckoAttrs.InheritFromDocToNecko(BasePrincipal::Cast(aLoadingPrincipal)->OriginAttributesRef()); neckoAttrs.InheritFromDocToNecko(BasePrincipal::Cast(aTriggeringPrincipal)->OriginAttributesRef());
} }
neckoAttrs.mPrivateBrowsingId = aRespectPrivacy ? 1 : 0; neckoAttrs.mPrivateBrowsingId = aRespectPrivacy ? 1 : 0;
@ -784,9 +784,9 @@ NewImageChannel(nsIChannel** aResult,
// only inherit if we have a principal // only inherit if we have a principal
*aForcePrincipalCheckForCacheEntry = *aForcePrincipalCheckForCacheEntry =
aLoadingPrincipal && aTriggeringPrincipal &&
nsContentUtils::ChannelShouldInheritPrincipal( nsContentUtils::ChannelShouldInheritPrincipal(
aLoadingPrincipal, aTriggeringPrincipal,
aURI, aURI,
/* aInheritForAboutBlank */ false, /* aInheritForAboutBlank */ false,
/* aForceInherit */ false); /* aForceInherit */ false);
@ -1583,7 +1583,7 @@ imgLoader::ValidateRequestWithNewChannel(imgRequest* request,
nsLoadFlags aLoadFlags, nsLoadFlags aLoadFlags,
nsContentPolicyType aLoadPolicyType, nsContentPolicyType aLoadPolicyType,
imgRequestProxy** aProxyRequest, imgRequestProxy** aProxyRequest,
nsIPrincipal* aLoadingPrincipal, nsIPrincipal* aTriggeringPrincipal,
int32_t aCORSMode) int32_t aCORSMode)
{ {
// now we need to insert a new channel request object inbetween the real // now we need to insert a new channel request object inbetween the real
@ -1633,7 +1633,7 @@ imgLoader::ValidateRequestWithNewChannel(imgRequest* request,
mAcceptHeader, mAcceptHeader,
aLoadFlags, aLoadFlags,
aLoadPolicyType, aLoadPolicyType,
aLoadingPrincipal, aTriggeringPrincipal,
aCX, aCX,
mRespectPrivacy); mRespectPrivacy);
if (NS_FAILED(rv)) { if (NS_FAILED(rv)) {
@ -1706,7 +1706,7 @@ imgLoader::ValidateEntry(imgCacheEntry* aEntry,
nsContentPolicyType aLoadPolicyType, nsContentPolicyType aLoadPolicyType,
bool aCanMakeNewChannel, bool aCanMakeNewChannel,
imgRequestProxy** aProxyRequest, imgRequestProxy** aProxyRequest,
nsIPrincipal* aLoadingPrincipal, nsIPrincipal* aTriggeringPrincipal,
int32_t aCORSMode) int32_t aCORSMode)
{ {
LOG_SCOPE(gImgLog, "imgLoader::ValidateEntry"); LOG_SCOPE(gImgLog, "imgLoader::ValidateEntry");
@ -1746,7 +1746,7 @@ imgLoader::ValidateEntry(imgCacheEntry* aEntry,
} }
if (!ValidateSecurityInfo(request, aEntry->ForcePrincipalCheck(), if (!ValidateSecurityInfo(request, aEntry->ForcePrincipalCheck(),
aCORSMode, aLoadingPrincipal, aCORSMode, aTriggeringPrincipal,
aCX, aLoadPolicyType, aReferrerPolicy)) aCX, aLoadPolicyType, aReferrerPolicy))
return false; return false;
@ -1823,7 +1823,7 @@ imgLoader::ValidateEntry(imgCacheEntry* aEntry,
aReferrerURI, aReferrerPolicy, aReferrerURI, aReferrerPolicy,
aLoadGroup, aObserver, aLoadGroup, aObserver,
aCX, aLoadFlags, aLoadPolicyType, aCX, aLoadFlags, aLoadPolicyType,
aProxyRequest, aLoadingPrincipal, aProxyRequest, aTriggeringPrincipal,
aCORSMode); aCORSMode);
} }
@ -1977,7 +1977,7 @@ imgLoader::LoadImageXPCOM(nsIURI* aURI,
nsIURI* aInitialDocumentURI, nsIURI* aInitialDocumentURI,
nsIURI* aReferrerURI, nsIURI* aReferrerURI,
const nsAString& aReferrerPolicy, const nsAString& aReferrerPolicy,
nsIPrincipal* aLoadingPrincipal, nsIPrincipal* aTriggeringPrincipal,
nsILoadGroup* aLoadGroup, nsILoadGroup* aLoadGroup,
imgINotificationObserver* aObserver, imgINotificationObserver* aObserver,
nsISupports* aCX, nsISupports* aCX,
@ -1999,7 +1999,7 @@ imgLoader::LoadImageXPCOM(nsIURI* aURI,
aReferrerURI, aReferrerURI,
refpol == mozilla::net::RP_Unset ? refpol == mozilla::net::RP_Unset ?
mozilla::net::RP_Default : refpol, mozilla::net::RP_Default : refpol,
aLoadingPrincipal, aTriggeringPrincipal,
aLoadGroup, aLoadGroup,
aObserver, aObserver,
node, node,
@ -2018,7 +2018,7 @@ imgLoader::LoadImage(nsIURI* aURI,
nsIURI* aInitialDocumentURI, nsIURI* aInitialDocumentURI,
nsIURI* aReferrerURI, nsIURI* aReferrerURI,
ReferrerPolicy aReferrerPolicy, ReferrerPolicy aReferrerPolicy,
nsIPrincipal* aLoadingPrincipal, nsIPrincipal* aTriggeringPrincipal,
nsILoadGroup* aLoadGroup, nsILoadGroup* aLoadGroup,
imgINotificationObserver* aObserver, imgINotificationObserver* aObserver,
nsINode *aContext, nsINode *aContext,
@ -2101,8 +2101,8 @@ imgLoader::LoadImage(nsIURI* aURI,
// for correctly dealing with image load requests that are a result // for correctly dealing with image load requests that are a result
// of post data. // of post data.
PrincipalOriginAttributes attrs; PrincipalOriginAttributes attrs;
if (aLoadingPrincipal) { if (aTriggeringPrincipal) {
attrs = BasePrincipal::Cast(aLoadingPrincipal)->OriginAttributesRef(); attrs = BasePrincipal::Cast(aTriggeringPrincipal)->OriginAttributesRef();
} }
ImageCacheKey key(aURI, attrs, aLoadingDocument, rv); ImageCacheKey key(aURI, attrs, aLoadingDocument, rv);
NS_ENSURE_SUCCESS(rv, rv); NS_ENSURE_SUCCESS(rv, rv);
@ -2112,7 +2112,7 @@ imgLoader::LoadImage(nsIURI* aURI,
if (ValidateEntry(entry, aURI, aInitialDocumentURI, aReferrerURI, if (ValidateEntry(entry, aURI, aInitialDocumentURI, aReferrerURI,
aReferrerPolicy, aLoadGroup, aObserver, aLoadingDocument, aReferrerPolicy, aLoadGroup, aObserver, aLoadingDocument,
requestFlags, aContentPolicyType, true, _retval, requestFlags, aContentPolicyType, true, _retval,
aLoadingPrincipal, corsmode)) { aTriggeringPrincipal, corsmode)) {
request = entry->GetRequest(); request = entry->GetRequest();
// If this entry has no proxies, its request has no reference to the // If this entry has no proxies, its request has no reference to the
@ -2157,7 +2157,7 @@ imgLoader::LoadImage(nsIURI* aURI,
mAcceptHeader, mAcceptHeader,
requestFlags, requestFlags,
aContentPolicyType, aContentPolicyType,
aLoadingPrincipal, aTriggeringPrincipal,
aContext, aContext,
mRespectPrivacy); mRespectPrivacy);
if (NS_FAILED(rv)) { if (NS_FAILED(rv)) {
@ -2178,7 +2178,7 @@ imgLoader::LoadImage(nsIURI* aURI,
newChannel->GetLoadGroup(getter_AddRefs(channelLoadGroup)); newChannel->GetLoadGroup(getter_AddRefs(channelLoadGroup));
rv = request->Init(aURI, aURI, /* aHadInsecureRedirect = */ false, rv = request->Init(aURI, aURI, /* aHadInsecureRedirect = */ false,
channelLoadGroup, newChannel, entry, aLoadingDocument, channelLoadGroup, newChannel, entry, aLoadingDocument,
aLoadingPrincipal, corsmode, aReferrerPolicy); aTriggeringPrincipal, corsmode, aReferrerPolicy);
if (NS_FAILED(rv)) { if (NS_FAILED(rv)) {
return NS_ERROR_FAILURE; return NS_ERROR_FAILURE;
} }
@ -2814,7 +2814,7 @@ imgCacheValidator::OnStartRequest(nsIRequest* aRequest, nsISupports* ctxt)
int32_t corsmode = mRequest->GetCORSMode(); int32_t corsmode = mRequest->GetCORSMode();
ReferrerPolicy refpol = mRequest->GetReferrerPolicy(); ReferrerPolicy refpol = mRequest->GetReferrerPolicy();
nsCOMPtr<nsIPrincipal> loadingPrincipal = mRequest->GetLoadingPrincipal(); nsCOMPtr<nsIPrincipal> triggeringPrincipal = mRequest->GetTriggeringPrincipal();
// Doom the old request's cache entry // Doom the old request's cache entry
mRequest->RemoveFromCache(); mRequest->RemoveFromCache();
@ -2827,7 +2827,7 @@ imgCacheValidator::OnStartRequest(nsIRequest* aRequest, nsISupports* ctxt)
channel->GetOriginalURI(getter_AddRefs(originalURI)); channel->GetOriginalURI(getter_AddRefs(originalURI));
nsresult rv = nsresult rv =
mNewRequest->Init(originalURI, uri, mHadInsecureRedirect, aRequest, channel, mNewRequest->Init(originalURI, uri, mHadInsecureRedirect, aRequest, channel,
mNewEntry, context, loadingPrincipal, corsmode, refpol); mNewEntry, context, triggeringPrincipal, corsmode, refpol);
if (NS_FAILED(rv)) { if (NS_FAILED(rv)) {
return rv; return rv;
} }

View file

@ -91,7 +91,7 @@ imgRequest::Init(nsIURI *aURI,
nsIChannel *aChannel, nsIChannel *aChannel,
imgCacheEntry *aCacheEntry, imgCacheEntry *aCacheEntry,
nsISupports* aCX, nsISupports* aCX,
nsIPrincipal* aLoadingPrincipal, nsIPrincipal* aTriggeringPrincipal,
int32_t aCORSMode, int32_t aCORSMode,
ReferrerPolicy aReferrerPolicy) ReferrerPolicy aReferrerPolicy)
{ {
@ -119,7 +119,7 @@ imgRequest::Init(nsIURI *aURI,
mChannel = aChannel; mChannel = aChannel;
mTimedChannel = do_QueryInterface(mChannel); mTimedChannel = do_QueryInterface(mChannel);
mLoadingPrincipal = aLoadingPrincipal; mTriggeringPrincipal = aTriggeringPrincipal;
mCORSMode = aCORSMode; mCORSMode = aCORSMode;
mReferrerPolicy = aReferrerPolicy; mReferrerPolicy = aReferrerPolicy;

View file

@ -72,7 +72,7 @@ public:
nsIChannel* aChannel, nsIChannel* aChannel,
imgCacheEntry* aCacheEntry, imgCacheEntry* aCacheEntry,
nsISupports* aCX, nsISupports* aCX,
nsIPrincipal* aLoadingPrincipal, nsIPrincipal* aTriggeringPrincipal,
int32_t aCORSMode, int32_t aCORSMode,
ReferrerPolicy aReferrerPolicy); ReferrerPolicy aReferrerPolicy);
@ -127,9 +127,9 @@ public:
// The principal for the document that loaded this image. Used when trying to // The principal for the document that loaded this image. Used when trying to
// validate a CORS image load. // validate a CORS image load.
already_AddRefed<nsIPrincipal> GetLoadingPrincipal() const already_AddRefed<nsIPrincipal> GetTriggeringPrincipal() const
{ {
nsCOMPtr<nsIPrincipal> principal = mLoadingPrincipal; nsCOMPtr<nsIPrincipal> principal = mTriggeringPrincipal;
return principal.forget(); return principal.forget();
} }
@ -232,9 +232,10 @@ private:
RefPtr<ImageURL> mURI; RefPtr<ImageURL> mURI;
// The URI of the resource we ended up loading after all redirects, etc. // The URI of the resource we ended up loading after all redirects, etc.
nsCOMPtr<nsIURI> mCurrentURI; nsCOMPtr<nsIURI> mCurrentURI;
// The principal of the document which loaded this image. Used when // The principal which triggered the load of this image. Generally either
// validating for CORS. // the principal of the document the image is being loaded into, or of the
nsCOMPtr<nsIPrincipal> mLoadingPrincipal; // stylesheet which specified the image to load. Used when validating for CORS.
nsCOMPtr<nsIPrincipal> mTriggeringPrincipal;
// The principal of this image. // The principal of this image.
nsCOMPtr<nsIPrincipal> mPrincipal; nsCOMPtr<nsIPrincipal> mPrincipal;
nsCOMPtr<nsIProperties> mProperties; nsCOMPtr<nsIProperties> mProperties;