mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-30 12:27:29 +09:00
Bug 1329288: Allow content policy consumers to identify contentPolicy checks from docshell
This commit is contained in:
parent
79fb0b8506
commit
9e52126f1a
3 changed files with 26 additions and 3 deletions
|
|
@ -139,6 +139,7 @@
|
||||||
#include "nsISiteSecurityService.h"
|
#include "nsISiteSecurityService.h"
|
||||||
#include "nsStructuredCloneContainer.h"
|
#include "nsStructuredCloneContainer.h"
|
||||||
#include "nsIStructuredCloneContainer.h"
|
#include "nsIStructuredCloneContainer.h"
|
||||||
|
#include "nsISupportsPrimitives.h"
|
||||||
#ifdef MOZ_PLACES
|
#ifdef MOZ_PLACES
|
||||||
#include "nsIFaviconService.h"
|
#include "nsIFaviconService.h"
|
||||||
#include "mozIPlacesPendingOperation.h"
|
#include "mozIPlacesPendingOperation.h"
|
||||||
|
|
@ -9931,13 +9932,24 @@ nsDocShell::InternalLoad(nsIURI* aURI,
|
||||||
#endif
|
#endif
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Since Content Policy checks are performed within docShell as well as
|
||||||
|
// the ContentSecurityManager we need a reliable way to let certain
|
||||||
|
// nsIContentPolicy consumers ignore duplicate calls. Let's use the 'extra'
|
||||||
|
// argument to pass a specific identifier.
|
||||||
|
nsCOMPtr<nsISupportsString> extraStr =
|
||||||
|
do_CreateInstance(NS_SUPPORTS_STRING_CONTRACTID, &rv);
|
||||||
|
NS_ENSURE_SUCCESS(rv, rv);
|
||||||
|
NS_NAMED_LITERAL_STRING(msg, "conPolCheckFromDocShell");
|
||||||
|
rv = extraStr->SetData(msg);
|
||||||
|
NS_ENSURE_SUCCESS(rv, rv);
|
||||||
|
|
||||||
int16_t shouldLoad = nsIContentPolicy::ACCEPT;
|
int16_t shouldLoad = nsIContentPolicy::ACCEPT;
|
||||||
rv = NS_CheckContentLoadPolicy(contentType,
|
rv = NS_CheckContentLoadPolicy(contentType,
|
||||||
aURI,
|
aURI,
|
||||||
aTriggeringPrincipal,
|
aTriggeringPrincipal,
|
||||||
requestingContext,
|
requestingContext,
|
||||||
EmptyCString(), // mime guess
|
EmptyCString(), // mime guess
|
||||||
nullptr, // extra
|
extraStr, // extra
|
||||||
&shouldLoad);
|
&shouldLoad);
|
||||||
|
|
||||||
if (NS_FAILED(rv) || NS_CP_REJECTED(shouldLoad)) {
|
if (NS_FAILED(rv) || NS_CP_REJECTED(shouldLoad)) {
|
||||||
|
|
|
||||||
|
|
@ -171,9 +171,10 @@ nsCSPContext::ShouldLoad(nsContentPolicyType aContentType,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// aExtra is only non-null if the channel got redirected.
|
// aExtra holds the original URI of the channel if the
|
||||||
bool wasRedirected = (aExtra != nullptr);
|
// channel got redirected (until we fix Bug 1332422).
|
||||||
nsCOMPtr<nsIURI> originalURI = do_QueryInterface(aExtra);
|
nsCOMPtr<nsIURI> originalURI = do_QueryInterface(aExtra);
|
||||||
|
bool wasRedirected = originalURI;
|
||||||
|
|
||||||
bool permitted = permitsInternal(dir,
|
bool permitted = permitsInternal(dir,
|
||||||
aContentLocation,
|
aContentLocation,
|
||||||
|
|
|
||||||
|
|
@ -80,6 +80,16 @@ var ContentPolicy = {
|
||||||
|
|
||||||
shouldLoad(policyType, contentLocation, requestOrigin,
|
shouldLoad(policyType, contentLocation, requestOrigin,
|
||||||
node, mimeTypeGuess, extra, requestPrincipal) {
|
node, mimeTypeGuess, extra, requestPrincipal) {
|
||||||
|
|
||||||
|
// Loads of TYPE_DOCUMENT and TYPE_SUBDOCUMENT perform a ConPol check
|
||||||
|
// within docshell as well as within the ContentSecurityManager. To avoid
|
||||||
|
// duplicate evaluations we ignore ConPol checks performed within docShell.
|
||||||
|
if (extra instanceof Ci.nsISupportsString) {
|
||||||
|
if (extra.data === "conPolCheckFromDocShell") {
|
||||||
|
return Ci.nsIContentPolicy.ACCEPT;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
if (requestPrincipal &&
|
if (requestPrincipal &&
|
||||||
Services.scriptSecurityManager.isSystemPrincipal(requestPrincipal)) {
|
Services.scriptSecurityManager.isSystemPrincipal(requestPrincipal)) {
|
||||||
return Ci.nsIContentPolicy.ACCEPT;
|
return Ci.nsIContentPolicy.ACCEPT;
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue