mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-08 08:48:39 +09:00
[DOM security] Be more explicit about CSP checks and reports.
This commit is contained in:
parent
ef3685dc5d
commit
95120acbb2
5 changed files with 70 additions and 10 deletions
|
|
@ -1721,7 +1721,8 @@ HTMLFormElement::GetActionURL(nsIURI** aActionURL,
|
|||
// policy - do *not* consult default-src, see:
|
||||
// http://www.w3.org/TR/CSP2/#directive-default-src
|
||||
rv = csp->Permits(actionURL, nsIContentSecurityPolicy::FORM_ACTION_DIRECTIVE,
|
||||
true, &permitsFormAction);
|
||||
true /*aSpecific */, true /* aSendViolationReports */,
|
||||
&permitsFormAction);
|
||||
NS_ENSURE_SUCCESS(rv, rv);
|
||||
if (!permitsFormAction) {
|
||||
return NS_ERROR_CSP_FORM_ACTION_VIOLATION;
|
||||
|
|
|
|||
|
|
@ -191,7 +191,8 @@ SetBaseURIUsingFirstBaseWithHref(nsIDocument* aDocument, nsIContent* aMustMatch)
|
|||
// http://www.w3.org/TR/CSP2/#directive-default-src
|
||||
bool cspPermitsBaseURI = true;
|
||||
rv = csp->Permits(newBaseURI, nsIContentSecurityPolicy::BASE_URI_DIRECTIVE,
|
||||
true, &cspPermitsBaseURI);
|
||||
true /* aSpecific */, true /* aSendViolationReports */,
|
||||
&cspPermitsBaseURI);
|
||||
if (NS_FAILED(rv) || !cspPermitsBaseURI) {
|
||||
newBaseURI = nullptr;
|
||||
}
|
||||
|
|
|
|||
|
|
@ -252,9 +252,6 @@ interface nsIContentSecurityPolicy : nsISerializable
|
|||
/**
|
||||
* Checks if a specific directive permits loading of a URI.
|
||||
*
|
||||
* NOTE: Calls to this may trigger violation reports when queried, so the
|
||||
* return value should not be cached.
|
||||
*
|
||||
* @param aURI
|
||||
* The URI about to be loaded or used.
|
||||
* @param aDir
|
||||
|
|
@ -266,11 +263,17 @@ interface nsIContentSecurityPolicy : nsISerializable
|
|||
* "false" allows CSP to fall back to default-src. This function
|
||||
* behaves the same for both values of canUseDefault when querying
|
||||
* directives that don't fall-back.
|
||||
* @param aSendViolationReports
|
||||
* If `true` and the uri is not allowed then trigger violation reports.
|
||||
* This should be `false` for caching or preloads.
|
||||
* @return
|
||||
* Whether or not the provided URI is allowed by CSP under the given
|
||||
* directive. (block the pending operation if false).
|
||||
*/
|
||||
boolean permits(in nsIURI aURI, in CSPDirective aDir, in boolean aSpecific);
|
||||
boolean permits(in nsIURI aURI,
|
||||
in CSPDirective aDir,
|
||||
in boolean aSpecific,
|
||||
in boolean aSendViolationReports);
|
||||
|
||||
/**
|
||||
* Delegate method called by the service when sub-elements of the protected
|
||||
|
|
|
|||
|
|
@ -1309,6 +1309,7 @@ NS_IMETHODIMP
|
|||
nsCSPContext::Permits(nsIURI* aURI,
|
||||
CSPDirective aDir,
|
||||
bool aSpecific,
|
||||
bool aSendViolationReports,
|
||||
bool* outPermits)
|
||||
{
|
||||
// Can't perform check without aURI
|
||||
|
|
@ -1323,13 +1324,13 @@ nsCSPContext::Permits(nsIURI* aURI,
|
|||
false, // not redirected.
|
||||
false, // not a preload.
|
||||
aSpecific,
|
||||
true, // send violation reports
|
||||
aSendViolationReports,
|
||||
true, // send blocked URI in violation reports
|
||||
false); // not parser created
|
||||
|
||||
if (CSPCONTEXTLOGENABLED()) {
|
||||
CSPCONTEXTLOG(("nsCSPContext::Permits, aUri: %s, aDir: %d, isAllowed: %s",
|
||||
aURI->GetSpecOrDefault().get(), aDir,
|
||||
CSPCONTEXTLOG(("nsCSPContext::Permits, aUri: %s, aDir: %s, isAllowed: %s",
|
||||
aURI->GetSpecOrDefault().get(), CSP_CSPDirectiveToString(aDir),
|
||||
*outPermits ? "allow" : "deny"));
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -1018,9 +1018,63 @@ nsHtml5TreeOpExecutor::SetSpeculationBase(const nsAString& aURL)
|
|||
return;
|
||||
}
|
||||
const nsCString& charset = mDocument->GetDocumentCharacterSet();
|
||||
DebugOnly<nsresult> rv = NS_NewURI(getter_AddRefs(mSpeculationBaseURI), aURL,
|
||||
nsCOMPtr<nsIURI> newBaseURI;
|
||||
nsresult rv = NS_NewURI(getter_AddRefs(newBaseURI), aURL,
|
||||
charset.get(), mDocument->GetDocumentURI());
|
||||
NS_WARNING_ASSERTION(NS_SUCCEEDED(rv), "Failed to create a URI");
|
||||
if (!newBaseURI) {
|
||||
return;
|
||||
}
|
||||
|
||||
if (!CSPService::sCSPEnabled) {
|
||||
// If CSP is not enabled, just pass back the URI
|
||||
mSpeculationBaseURI = newBaseURI;
|
||||
return;
|
||||
}
|
||||
|
||||
NS_ASSERTION(NS_IsMainThread(), "Wrong thread!");
|
||||
|
||||
nsCOMPtr<nsIPrincipal> principal = mDocument->NodePrincipal();
|
||||
nsCOMPtr<nsIDOMDocument> domDoc = do_QueryInterface(mDocument);
|
||||
|
||||
// Check the document's CSP usually delivered via the CSP header.
|
||||
nsCOMPtr<nsIContentSecurityPolicy> documentCsp;
|
||||
rv = principal->EnsureCSP(domDoc, getter_AddRefs(documentCsp));
|
||||
NS_ENSURE_SUCCESS_VOID(rv);
|
||||
if (documentCsp) {
|
||||
// base-uri should not fallback to the default-src and preloads should not
|
||||
// trigger violation reports.
|
||||
bool cspPermitsBaseURI = true;
|
||||
rv = documentCsp->Permits(
|
||||
newBaseURI,
|
||||
nsIContentSecurityPolicy::BASE_URI_DIRECTIVE,
|
||||
true /* aSpecific */,
|
||||
false /* aSendViolationReports */,
|
||||
&cspPermitsBaseURI);
|
||||
if (NS_FAILED(rv) || !cspPermitsBaseURI) {
|
||||
return;
|
||||
}
|
||||
}
|
||||
|
||||
// Also check the CSP discovered from the <meta> tag during speculative
|
||||
// parsing.
|
||||
nsCOMPtr<nsIContentSecurityPolicy> preloadCsp;
|
||||
rv = principal->EnsurePreloadCSP(domDoc, getter_AddRefs(preloadCsp));
|
||||
NS_ENSURE_SUCCESS_VOID(rv);
|
||||
if (preloadCsp) {
|
||||
bool cspPermitsBaseURI = true;
|
||||
rv = preloadCsp->Permits(
|
||||
newBaseURI,
|
||||
nsIContentSecurityPolicy::BASE_URI_DIRECTIVE,
|
||||
true /* aSpecific */,
|
||||
false /* aSendViolationReports */,
|
||||
&cspPermitsBaseURI);
|
||||
if (NS_FAILED(rv) || !cspPermitsBaseURI) {
|
||||
return;
|
||||
}
|
||||
}
|
||||
|
||||
mSpeculationBaseURI = newBaseURI;
|
||||
}
|
||||
|
||||
void
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue