moebius#230: Consider blocking top level window data: URIs (part 3/3 without tests)

https://github.com/MoonchildProductions/moebius/pull/230
This commit is contained in:
janekptacijarabaci 2018-04-22 20:28:18 +02:00 • committed by Roy Tam
commit 18d312235d
20 changed files with 143 additions and 3 deletions

View file

@ -909,7 +909,8 @@ nsContextMenu.prototype = {
Ci.nsIScriptSecurityManager.DISALLOW_SCRIPT); Ci.nsIScriptSecurityManager.DISALLOW_SCRIPT);
let doc = this.target.ownerDocument; let doc = this.target.ownerDocument;
openUILink(viewURL, e, { disallowInheritPrincipal: true, openUILink(viewURL, e, { disallowInheritPrincipal: true,
referrerURI: doc.documentURIObject }); referrerURI: doc.documentURIObject,
forceAllowDataURI: true });
} }
}, },

View file

@ -205,6 +205,7 @@ function openUILinkIn(url, where, aAllowThirdPartyFixup, aPostData, aReferrerURI
openLinkIn(url, where, params); openLinkIn(url, where, params);
} }
/* eslint-disable complexity */
function openLinkIn(url, where, params) { function openLinkIn(url, where, params) {
if (!where || !url) if (!where || !url)
return; return;
@ -215,6 +216,7 @@ function openLinkIn(url, where, params) {
var aCharset = params.charset; var aCharset = params.charset;
var aReferrerURI = params.referrerURI; var aReferrerURI = params.referrerURI;
var aRelatedToCurrent = params.relatedToCurrent; var aRelatedToCurrent = params.relatedToCurrent;
var aForceAllowDataURI = params.forceAllowDataURI;
var aInBackground = params.inBackground; var aInBackground = params.inBackground;
var aDisallowInheritPrincipal = params.disallowInheritPrincipal; var aDisallowInheritPrincipal = params.disallowInheritPrincipal;
var aInitiatingDoc = params.initiatingDoc; var aInitiatingDoc = params.initiatingDoc;
@ -315,6 +317,9 @@ function openLinkIn(url, where, params) {
} }
if (aDisallowInheritPrincipal) if (aDisallowInheritPrincipal)
flags |= Ci.nsIWebNavigation.LOAD_FLAGS_DISALLOW_INHERIT_OWNER; flags |= Ci.nsIWebNavigation.LOAD_FLAGS_DISALLOW_INHERIT_OWNER;
if (aForceAllowDataURI) {
flags |= Ci.nsIWebNavigation.LOAD_FLAGS_FORCE_ALLOW_DATA_URI;
}
w.gBrowser.loadURIWithFlags(url, flags, aReferrerURI, null, aPostData); w.gBrowser.loadURIWithFlags(url, flags, aReferrerURI, null, aPostData);
break; break;
case "tabshifted": case "tabshifted":

View file

@ -1158,7 +1158,8 @@ nsContextMenu.prototype = {
this.browser.contentPrincipal, this.browser.contentPrincipal,
Ci.nsIScriptSecurityManager.DISALLOW_SCRIPT); Ci.nsIScriptSecurityManager.DISALLOW_SCRIPT);
openUILink(this.mediaURL, e, { disallowInheritPrincipal: true, openUILink(this.mediaURL, e, { disallowInheritPrincipal: true,
referrerURI: referrerURI }); referrerURI: referrerURI,
forceAllowDataURI: true });
} }
}, },

View file

@ -197,6 +197,7 @@ function openUILinkIn(url, where, aAllowThirdPartyFixup, aPostData, aReferrerURI
openLinkIn(url, where, params); openLinkIn(url, where, params);
} }
/* eslint-disable complexity */
function openLinkIn(url, where, params) { function openLinkIn(url, where, params) {
if (!where || !url) if (!where || !url)
return; return;
@ -212,6 +213,7 @@ function openLinkIn(url, where, params) {
params.referrerPolicy : Ci.nsIHttpChannel.REFERRER_POLICY_DEFAULT); params.referrerPolicy : Ci.nsIHttpChannel.REFERRER_POLICY_DEFAULT);
var aRelatedToCurrent = params.relatedToCurrent; var aRelatedToCurrent = params.relatedToCurrent;
var aAllowMixedContent = params.allowMixedContent; var aAllowMixedContent = params.allowMixedContent;
var aForceAllowDataURI = params.forceAllowDataURI;
var aInBackground = params.inBackground; var aInBackground = params.inBackground;
var aDisallowInheritPrincipal = params.disallowInheritPrincipal; var aDisallowInheritPrincipal = params.disallowInheritPrincipal;
var aInitiatingDoc = params.initiatingDoc; var aInitiatingDoc = params.initiatingDoc;
@ -378,6 +380,9 @@ function openLinkIn(url, where, params) {
if (aIndicateErrorPageLoad) { if (aIndicateErrorPageLoad) {
flags |= Ci.nsIWebNavigation.LOAD_FLAGS_ERROR_LOAD_CHANGES_RV; flags |= Ci.nsIWebNavigation.LOAD_FLAGS_ERROR_LOAD_CHANGES_RV;
} }
if (aForceAllowDataURI) {
flags |= Ci.nsIWebNavigation.LOAD_FLAGS_FORCE_ALLOW_DATA_URI;
}
let {URI_INHERITS_SECURITY_CONTEXT} = Ci.nsIProtocolHandler; let {URI_INHERITS_SECURITY_CONTEXT} = Ci.nsIProtocolHandler;
if (aForceAboutBlankViewerInCurrent && if (aForceAboutBlankViewerInCurrent &&

View file

@ -1273,6 +1273,7 @@ nsDocShell::LoadURI(nsIURI* aURI,
nsCOMPtr<nsISHEntry> shEntry; nsCOMPtr<nsISHEntry> shEntry;
nsXPIDLString target; nsXPIDLString target;
nsAutoString srcdoc; nsAutoString srcdoc;
bool forceAllowDataURI = false;
nsCOMPtr<nsIDocShell> sourceDocShell; nsCOMPtr<nsIDocShell> sourceDocShell;
nsCOMPtr<nsIURI> baseURI; nsCOMPtr<nsIURI> baseURI;
@ -1308,6 +1309,7 @@ nsDocShell::LoadURI(nsIURI* aURI,
aLoadInfo->GetSrcdocData(srcdoc); aLoadInfo->GetSrcdocData(srcdoc);
aLoadInfo->GetSourceDocShell(getter_AddRefs(sourceDocShell)); aLoadInfo->GetSourceDocShell(getter_AddRefs(sourceDocShell));
aLoadInfo->GetBaseURI(getter_AddRefs(baseURI)); aLoadInfo->GetBaseURI(getter_AddRefs(baseURI));
aLoadInfo->GetForceAllowDataURI(&forceAllowDataURI);
} }
#if defined(DEBUG) #if defined(DEBUG)
@ -1561,6 +1563,10 @@ nsDocShell::LoadURI(nsIURI* aURI,
flags |= INTERNAL_LOAD_FLAGS_IS_SRCDOC; flags |= INTERNAL_LOAD_FLAGS_IS_SRCDOC;
} }
if (forceAllowDataURI) {
flags |= INTERNAL_LOAD_FLAGS_FORCE_ALLOW_DATA_URI;
}
return InternalLoad(aURI, return InternalLoad(aURI,
originalURI, originalURI,
loadReplace, loadReplace,
@ -4822,6 +4828,9 @@ nsDocShell::LoadURIWithOptions(const char16_t* aURI,
} }
nsAutoPopupStatePusher statePusher(popupState); nsAutoPopupStatePusher statePusher(popupState);
bool forceAllowDataURI =
aLoadFlags & LOAD_FLAGS_FORCE_ALLOW_DATA_URI;
// Don't pass certain flags that aren't needed and end up confusing // Don't pass certain flags that aren't needed and end up confusing
// ConvertLoadTypeToDocShellLoadInfo. We do need to ensure that they are // ConvertLoadTypeToDocShellLoadInfo. We do need to ensure that they are
// passed to LoadURI though, since it uses them. // passed to LoadURI though, since it uses them.
@ -4851,6 +4860,7 @@ nsDocShell::LoadURIWithOptions(const char16_t* aURI,
loadInfo->SetReferrerPolicy(aReferrerPolicy); loadInfo->SetReferrerPolicy(aReferrerPolicy);
loadInfo->SetHeadersStream(aHeaderStream); loadInfo->SetHeadersStream(aHeaderStream);
loadInfo->SetBaseURI(aBaseURI); loadInfo->SetBaseURI(aBaseURI);
loadInfo->SetForceAllowDataURI(forceAllowDataURI);
if (fixupInfo) { if (fixupInfo) {
nsAutoString searchProvider, keyword; nsAutoString searchProvider, keyword;
@ -10083,6 +10093,7 @@ nsDocShell::InternalLoad(nsIURI* aURI,
// principal to inherit is: it should be aTriggeringPrincipal. // principal to inherit is: it should be aTriggeringPrincipal.
loadInfo->SetPrincipalIsExplicit(true); loadInfo->SetPrincipalIsExplicit(true);
loadInfo->SetLoadType(ConvertLoadTypeToDocShellLoadInfo(LOAD_LINK)); loadInfo->SetLoadType(ConvertLoadTypeToDocShellLoadInfo(LOAD_LINK));
loadInfo->SetForceAllowDataURI(aFlags & INTERNAL_LOAD_FLAGS_FORCE_ALLOW_DATA_URI);
rv = win->Open(NS_ConvertUTF8toUTF16(spec), rv = win->Open(NS_ConvertUTF8toUTF16(spec),
aWindowTarget, // window name aWindowTarget, // window name
@ -10728,7 +10739,9 @@ nsDocShell::InternalLoad(nsIURI* aURI,
nsINetworkPredictor::PREDICT_LOAD, this, nullptr); nsINetworkPredictor::PREDICT_LOAD, this, nullptr);
nsCOMPtr<nsIRequest> req; nsCOMPtr<nsIRequest> req;
rv = DoURILoad(aURI, aOriginalURI, aLoadReplace, loadFromExternal, aReferrer, rv = DoURILoad(aURI, aOriginalURI, aLoadReplace, loadFromExternal,
(aFlags & INTERNAL_LOAD_FLAGS_FORCE_ALLOW_DATA_URI),
aReferrer,
!(aFlags & INTERNAL_LOAD_FLAGS_DONT_SEND_REFERRER), !(aFlags & INTERNAL_LOAD_FLAGS_DONT_SEND_REFERRER),
aReferrerPolicy, aReferrerPolicy,
aTriggeringPrincipal, principalToInherit, aTypeHint, aTriggeringPrincipal, principalToInherit, aTypeHint,
@ -10809,6 +10822,7 @@ nsDocShell::DoURILoad(nsIURI* aURI,
nsIURI* aOriginalURI, nsIURI* aOriginalURI,
bool aLoadReplace, bool aLoadReplace,
bool aLoadFromExternal, bool aLoadFromExternal,
bool aForceAllowDataURI,
nsIURI* aReferrerURI, nsIURI* aReferrerURI,
bool aSendReferrer, bool aSendReferrer,
uint32_t aReferrerPolicy, uint32_t aReferrerPolicy,
@ -10954,6 +10968,7 @@ nsDocShell::DoURILoad(nsIURI* aURI,
loadInfo->SetPrincipalToInherit(aPrincipalToInherit); loadInfo->SetPrincipalToInherit(aPrincipalToInherit);
} }
loadInfo->SetLoadTriggeredFromExternal(aLoadFromExternal); loadInfo->SetLoadTriggeredFromExternal(aLoadFromExternal);
loadInfo->SetForceAllowDataURI(aForceAllowDataURI);
// We have to do this in case our OriginAttributes are different from the // We have to do this in case our OriginAttributes are different from the
// OriginAttributes of the parent document. Or in case there isn't a // OriginAttributes of the parent document. Or in case there isn't a

View file

@ -370,6 +370,7 @@ protected:
nsIURI* aOriginalURI, nsIURI* aOriginalURI,
bool aLoadReplace, bool aLoadReplace,
bool aLoadFromExternal, bool aLoadFromExternal,
bool aForceAllowDataURI,
nsIURI* aReferrer, nsIURI* aReferrer,
bool aSendReferrer, bool aSendReferrer,
uint32_t aReferrerPolicy, uint32_t aReferrerPolicy,

View file

@ -15,6 +15,7 @@ nsDocShellLoadInfo::nsDocShellLoadInfo()
: mLoadReplace(false) : mLoadReplace(false)
, mInheritPrincipal(false) , mInheritPrincipal(false)
, mPrincipalIsExplicit(false) , mPrincipalIsExplicit(false)
, mForceAllowDataURI(false)
, mSendReferrer(true) , mSendReferrer(true)
, mReferrerPolicy(mozilla::net::RP_Default) , mReferrerPolicy(mozilla::net::RP_Default)
, mLoadType(nsIDocShellLoadInfo::loadNormal) , mLoadType(nsIDocShellLoadInfo::loadNormal)
@ -126,6 +127,20 @@ nsDocShellLoadInfo::SetPrincipalIsExplicit(bool aPrincipalIsExplicit)
return NS_OK; return NS_OK;
} }
NS_IMETHODIMP
nsDocShellLoadInfo::GetForceAllowDataURI(bool* aForceAllowDataURI)
{
*aForceAllowDataURI = mForceAllowDataURI;
return NS_OK;
}
NS_IMETHODIMP
nsDocShellLoadInfo::SetForceAllowDataURI(bool aForceAllowDataURI)
{
mForceAllowDataURI = aForceAllowDataURI;
return NS_OK;
}
NS_IMETHODIMP NS_IMETHODIMP
nsDocShellLoadInfo::GetLoadType(nsDocShellInfoLoadType* aLoadType) nsDocShellLoadInfo::GetLoadType(nsDocShellInfoLoadType* aLoadType)
{ {

View file

@ -37,6 +37,7 @@ protected:
bool mLoadReplace; bool mLoadReplace;
bool mInheritPrincipal; bool mInheritPrincipal;
bool mPrincipalIsExplicit; bool mPrincipalIsExplicit;
bool mForceAllowDataURI;
bool mSendReferrer; bool mSendReferrer;
nsDocShellInfoReferrerPolicy mReferrerPolicy; nsDocShellInfoReferrerPolicy mReferrerPolicy;
nsDocShellInfoLoadType mLoadType; nsDocShellInfoLoadType mLoadType;

View file

@ -116,6 +116,9 @@ interface nsIDocShell : nsIDocShellTreeItem
const long INTERNAL_LOAD_FLAGS_NO_OPENER = 0x100; const long INTERNAL_LOAD_FLAGS_NO_OPENER = 0x100;
// Whether a top-level data URI navigation is allowed for that load
const long INTERNAL_LOAD_FLAGS_FORCE_ALLOW_DATA_URI = 0x200;
// NB: 0x80 is available. // NB: 0x80 is available.
/** /**

View file

@ -55,6 +55,12 @@ interface nsIDocShellLoadInfo : nsISupports
*/ */
attribute boolean principalIsExplicit; attribute boolean principalIsExplicit;
/**
* If this attribute is true, then a top-level navigation
* to a data URI will be allowed.
*/
attribute boolean forceAllowDataURI;
/* these are load type enums... */ /* these are load type enums... */
const long loadNormal = 0; // Normal Load const long loadNormal = 0; // Normal Load
const long loadNormalReplace = 1; // Normal Load but replaces current history slot const long loadNormalReplace = 1; // Normal Load but replaces current history slot

View file

@ -205,6 +205,12 @@ interface nsIWebNavigation : nsISupports
*/ */
const unsigned long LOAD_FLAGS_FIXUP_SCHEME_TYPOS = 0x200000; const unsigned long LOAD_FLAGS_FIXUP_SCHEME_TYPOS = 0x200000;
/**
* Allows a top-level data: navigation to occur. E.g. view-image
* is an explicit user action which should be allowed.
*/
const unsigned long LOAD_FLAGS_FORCE_ALLOW_DATA_URI = 0x400000;
/** /**
* Loads a given URI. This will give priority to loading the requested URI * Loads a given URI. This will give priority to loading the requested URI
* in the object implementing this interface. If it can't be loaded here * in the object implementing this interface. If it can't be loaded here

View file

@ -39,6 +39,10 @@ nsContentSecurityManager::AllowTopLevelNavigationToDataURI(nsIChannel* aChannel)
if (loadInfo->GetExternalContentPolicyType() != nsIContentPolicy::TYPE_DOCUMENT) { if (loadInfo->GetExternalContentPolicyType() != nsIContentPolicy::TYPE_DOCUMENT) {
return true; return true;
} }
if (loadInfo->GetForceAllowDataURI()) {
// if the loadinfo explicitly allows the data URI navigation, let's allow it now
return true;
}
nsCOMPtr<nsIURI> uri; nsCOMPtr<nsIURI> uri;
nsresult rv = NS_GetFinalChannelURI(aChannel, getter_AddRefs(uri)); nsresult rv = NS_GetFinalChannelURI(aChannel, getter_AddRefs(uri));
NS_ENSURE_SUCCESS(rv, true); NS_ENSURE_SUCCESS(rv, true);

View file

@ -9,3 +9,6 @@ support-files =
[browser_test_data_text_csv.js] [browser_test_data_text_csv.js]
support-files = support-files =
file_data_text_csv.html file_data_text_csv.html
[browser_test_view_image_data_navigation.js]
support-files =
file_view_image_data_navigation.html

View file

@ -0,0 +1,30 @@
"use strict";
const TEST_PAGE = getRootDirectory(gTestPath) + "file_view_image_data_navigation.html";
add_task(async function test_principal_right_click_open_link_in_new_tab() {
await SpecialPowers.pushPrefEnv({
"set": [["security.data_uri.block_toplevel_data_uri_navigations", true]],
});
await BrowserTestUtils.withNewTab(TEST_PAGE, async function(browser) {
let loadPromise = BrowserTestUtils.browserLoaded(gBrowser.selectedBrowser, true);
// simulate right-click->view-image
BrowserTestUtils.waitForEvent(document, "popupshown", false, event => {
// These are operations that must be executed synchronously with the event.
document.getElementById("context-viewimage").doCommand();
event.target.hidePopup();
return true;
});
BrowserTestUtils.synthesizeMouseAtCenter("#testimage",
{ type: "contextmenu", button: 2 },
gBrowser.selectedBrowser);
await loadPromise;
await ContentTask.spawn(gBrowser.selectedBrowser, {}, async function() {
ok(content.document.location.toString().startsWith("data:image/svg+xml;"),
"data:image/svg navigation allowed through right-click view-image")
});
});
});

View file

@ -0,0 +1,12 @@
<!DOCTYPE HTML>
<html>
<head>
<meta charset="utf-8">
<title>Bug 1407891: Test navigation for right-click view-image on data:image/svg</title>
</head>
<body>
<img id="testimage" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIxNiIgaGVpZ2h0PSIxNiIgdmlld0JveD0iMCAwIDE2IDE2Ij4KICA8cGF0aCBkPSJNOCwxMkwzLDcsNCw2bDQsNCw0LTQsMSwxWiIgZmlsbD0iIzZBNkE2QSIgLz4KPC9zdmc+Cg=="></img>
</body>
</html>

View file

@ -280,6 +280,7 @@ LoadInfoToLoadInfoArgs(nsILoadInfo *aLoadInfo,
aLoadInfo->GetUpgradeInsecureRequests(), aLoadInfo->GetUpgradeInsecureRequests(),
aLoadInfo->GetVerifySignedContent(), aLoadInfo->GetVerifySignedContent(),
aLoadInfo->GetEnforceSRI(), aLoadInfo->GetEnforceSRI(),
aLoadInfo->GetForceAllowDataURI(),
aLoadInfo->GetForceInheritPrincipalDropped(), aLoadInfo->GetForceInheritPrincipalDropped(),
aLoadInfo->GetInnerWindowID(), aLoadInfo->GetInnerWindowID(),
aLoadInfo->GetOuterWindowID(), aLoadInfo->GetOuterWindowID(),
@ -357,6 +358,7 @@ LoadInfoArgsToLoadInfo(const OptionalLoadInfoArgs& aOptionalLoadInfoArgs,
loadInfoArgs.upgradeInsecureRequests(), loadInfoArgs.upgradeInsecureRequests(),
loadInfoArgs.verifySignedContent(), loadInfoArgs.verifySignedContent(),
loadInfoArgs.enforceSRI(), loadInfoArgs.enforceSRI(),
loadInfoArgs.forceAllowDataURI(),
loadInfoArgs.forceInheritPrincipalDropped(), loadInfoArgs.forceInheritPrincipalDropped(),
loadInfoArgs.innerWindowID(), loadInfoArgs.innerWindowID(),
loadInfoArgs.outerWindowID(), loadInfoArgs.outerWindowID(),

View file

@ -54,6 +54,7 @@ LoadInfo::LoadInfo(nsIPrincipal* aLoadingPrincipal,
, mUpgradeInsecureRequests(false) , mUpgradeInsecureRequests(false)
, mVerifySignedContent(false) , mVerifySignedContent(false)
, mEnforceSRI(false) , mEnforceSRI(false)
, mForceAllowDataURI(false)
, mForceInheritPrincipalDropped(false) , mForceInheritPrincipalDropped(false)
, mInnerWindowID(0) , mInnerWindowID(0)
, mOuterWindowID(0) , mOuterWindowID(0)
@ -227,6 +228,7 @@ LoadInfo::LoadInfo(nsPIDOMWindowOuter* aOuterWindow,
, mUpgradeInsecureRequests(false) , mUpgradeInsecureRequests(false)
, mVerifySignedContent(false) , mVerifySignedContent(false)
, mEnforceSRI(false) , mEnforceSRI(false)
, mForceAllowDataURI(false)
, mForceInheritPrincipalDropped(false) , mForceInheritPrincipalDropped(false)
, mInnerWindowID(0) , mInnerWindowID(0)
, mOuterWindowID(0) , mOuterWindowID(0)
@ -285,6 +287,7 @@ LoadInfo::LoadInfo(const LoadInfo& rhs)
, mUpgradeInsecureRequests(rhs.mUpgradeInsecureRequests) , mUpgradeInsecureRequests(rhs.mUpgradeInsecureRequests)
, mVerifySignedContent(rhs.mVerifySignedContent) , mVerifySignedContent(rhs.mVerifySignedContent)
, mEnforceSRI(rhs.mEnforceSRI) , mEnforceSRI(rhs.mEnforceSRI)
, mForceAllowDataURI(rhs.mForceAllowDataURI)
, mForceInheritPrincipalDropped(rhs.mForceInheritPrincipalDropped) , mForceInheritPrincipalDropped(rhs.mForceInheritPrincipalDropped)
, mInnerWindowID(rhs.mInnerWindowID) , mInnerWindowID(rhs.mInnerWindowID)
, mOuterWindowID(rhs.mOuterWindowID) , mOuterWindowID(rhs.mOuterWindowID)
@ -315,6 +318,7 @@ LoadInfo::LoadInfo(nsIPrincipal* aLoadingPrincipal,
bool aUpgradeInsecureRequests, bool aUpgradeInsecureRequests,
bool aVerifySignedContent, bool aVerifySignedContent,
bool aEnforceSRI, bool aEnforceSRI,
bool aForceAllowDataURI,
bool aForceInheritPrincipalDropped, bool aForceInheritPrincipalDropped,
uint64_t aInnerWindowID, uint64_t aInnerWindowID,
uint64_t aOuterWindowID, uint64_t aOuterWindowID,
@ -341,6 +345,7 @@ LoadInfo::LoadInfo(nsIPrincipal* aLoadingPrincipal,
, mUpgradeInsecureRequests(aUpgradeInsecureRequests) , mUpgradeInsecureRequests(aUpgradeInsecureRequests)
, mVerifySignedContent(aVerifySignedContent) , mVerifySignedContent(aVerifySignedContent)
, mEnforceSRI(aEnforceSRI) , mEnforceSRI(aEnforceSRI)
, mForceAllowDataURI(aForceAllowDataURI)
, mForceInheritPrincipalDropped(aForceInheritPrincipalDropped) , mForceInheritPrincipalDropped(aForceInheritPrincipalDropped)
, mInnerWindowID(aInnerWindowID) , mInnerWindowID(aInnerWindowID)
, mOuterWindowID(aOuterWindowID) , mOuterWindowID(aOuterWindowID)
@ -653,6 +658,23 @@ LoadInfo::GetEnforceSRI(bool* aResult)
return NS_OK; return NS_OK;
} }
NS_IMETHODIMP
LoadInfo::SetForceAllowDataURI(bool aForceAllowDataURI)
{
MOZ_ASSERT(!mForceAllowDataURI ||
mInternalContentPolicyType == nsIContentPolicy::TYPE_DOCUMENT,
"can only allow data URI navigation for TYPE_DOCUMENT");
mForceAllowDataURI = aForceAllowDataURI;
return NS_OK;
}
NS_IMETHODIMP
LoadInfo::GetForceAllowDataURI(bool* aForceAllowDataURI)
{
*aForceAllowDataURI = mForceAllowDataURI;
return NS_OK;
}
NS_IMETHODIMP NS_IMETHODIMP
LoadInfo::GetForceInheritPrincipalDropped(bool* aResult) LoadInfo::GetForceInheritPrincipalDropped(bool* aResult)
{ {

View file

@ -94,6 +94,7 @@ private:
bool aUpgradeInsecureRequests, bool aUpgradeInsecureRequests,
bool aVerifySignedContent, bool aVerifySignedContent,
bool aEnforceSRI, bool aEnforceSRI,
bool aForceAllowDataURI,
bool aForceInheritPrincipalDropped, bool aForceInheritPrincipalDropped,
uint64_t aInnerWindowID, uint64_t aInnerWindowID,
uint64_t aOuterWindowID, uint64_t aOuterWindowID,
@ -139,6 +140,7 @@ private:
bool mUpgradeInsecureRequests; bool mUpgradeInsecureRequests;
bool mVerifySignedContent; bool mVerifySignedContent;
bool mEnforceSRI; bool mEnforceSRI;
bool mForceAllowDataURI;
bool mForceInheritPrincipalDropped; bool mForceInheritPrincipalDropped;
uint64_t mInnerWindowID; uint64_t mInnerWindowID;
uint64_t mOuterWindowID; uint64_t mOuterWindowID;

View file

@ -469,6 +469,11 @@ interface nsILoadInfo : nsISupports
*/ */
[infallible] attribute boolean enforceSRI; [infallible] attribute boolean enforceSRI;
/**
* If true, toplevel data: URI navigation is allowed
*/
[infallible] attribute boolean forceAllowDataURI;
/** /**
* The SEC_FORCE_INHERIT_PRINCIPAL flag may be dropped when a load info * The SEC_FORCE_INHERIT_PRINCIPAL flag may be dropped when a load info
* object is created. Specifically, it will be dropped if the SEC_SANDBOXED * object is created. Specifically, it will be dropped if the SEC_SANDBOXED

View file

@ -39,6 +39,7 @@ struct LoadInfoArgs
bool upgradeInsecureRequests; bool upgradeInsecureRequests;
bool verifySignedContent; bool verifySignedContent;
bool enforceSRI; bool enforceSRI;
bool forceAllowDataURI;
bool forceInheritPrincipalDropped; bool forceInheritPrincipalDropped;
uint64_t innerWindowID; uint64_t innerWindowID;
uint64_t outerWindowID; uint64_t outerWindowID;