mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-30 12:27:29 +09:00
moebius#230: Consider blocking top level window data: URIs (part 3/3 without tests)
https://github.com/MoonchildProductions/moebius/pull/230
This commit is contained in:
parent
73f89fe562
commit
18d312235d
20 changed files with 143 additions and 3 deletions
|
|
@ -39,6 +39,10 @@ nsContentSecurityManager::AllowTopLevelNavigationToDataURI(nsIChannel* aChannel)
|
|||
if (loadInfo->GetExternalContentPolicyType() != nsIContentPolicy::TYPE_DOCUMENT) {
|
||||
return true;
|
||||
}
|
||||
if (loadInfo->GetForceAllowDataURI()) {
|
||||
// if the loadinfo explicitly allows the data URI navigation, let's allow it now
|
||||
return true;
|
||||
}
|
||||
nsCOMPtr<nsIURI> uri;
|
||||
nsresult rv = NS_GetFinalChannelURI(aChannel, getter_AddRefs(uri));
|
||||
NS_ENSURE_SUCCESS(rv, true);
|
||||
|
|
|
|||
|
|
@ -9,3 +9,6 @@ support-files =
|
|||
[browser_test_data_text_csv.js]
|
||||
support-files =
|
||||
file_data_text_csv.html
|
||||
[browser_test_view_image_data_navigation.js]
|
||||
support-files =
|
||||
file_view_image_data_navigation.html
|
||||
|
|
|
|||
|
|
@ -0,0 +1,30 @@
|
|||
"use strict";
|
||||
|
||||
const TEST_PAGE = getRootDirectory(gTestPath) + "file_view_image_data_navigation.html";
|
||||
|
||||
add_task(async function test_principal_right_click_open_link_in_new_tab() {
|
||||
await SpecialPowers.pushPrefEnv({
|
||||
"set": [["security.data_uri.block_toplevel_data_uri_navigations", true]],
|
||||
});
|
||||
|
||||
await BrowserTestUtils.withNewTab(TEST_PAGE, async function(browser) {
|
||||
let loadPromise = BrowserTestUtils.browserLoaded(gBrowser.selectedBrowser, true);
|
||||
|
||||
// simulate right-click->view-image
|
||||
BrowserTestUtils.waitForEvent(document, "popupshown", false, event => {
|
||||
// These are operations that must be executed synchronously with the event.
|
||||
document.getElementById("context-viewimage").doCommand();
|
||||
event.target.hidePopup();
|
||||
return true;
|
||||
});
|
||||
BrowserTestUtils.synthesizeMouseAtCenter("#testimage",
|
||||
{ type: "contextmenu", button: 2 },
|
||||
gBrowser.selectedBrowser);
|
||||
await loadPromise;
|
||||
|
||||
await ContentTask.spawn(gBrowser.selectedBrowser, {}, async function() {
|
||||
ok(content.document.location.toString().startsWith("data:image/svg+xml;"),
|
||||
"data:image/svg navigation allowed through right-click view-image")
|
||||
});
|
||||
});
|
||||
});
|
||||
|
|
@ -0,0 +1,12 @@
|
|||
<!DOCTYPE HTML>
|
||||
<html>
|
||||
<head>
|
||||
<meta charset="utf-8">
|
||||
<title>Bug 1407891: Test navigation for right-click view-image on data:image/svg</title>
|
||||
</head>
|
||||
<body>
|
||||
|
||||
<img id="testimage" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIxNiIgaGVpZ2h0PSIxNiIgdmlld0JveD0iMCAwIDE2IDE2Ij4KICA8cGF0aCBkPSJNOCwxMkwzLDcsNCw2bDQsNCw0LTQsMSwxWiIgZmlsbD0iIzZBNkE2QSIgLz4KPC9zdmc+Cg=="></img>
|
||||
|
||||
</body>
|
||||
</html>
|
||||
Loading…
Add table
Add a link
Reference in a new issue