Bug 1307736 - Ensure History loads pass valid triggeringPrincipal

This commit is contained in:
janekptacijarabaci 2018-04-30 23:02:01 +02:00 committed by Roy Tam
commit 9fca6b7ced
2 changed files with 11 additions and 5 deletions

View file

@ -12660,12 +12660,11 @@ nsDocShell::LoadHistoryEntry(nsISHEntry* aEntry, uint32_t aLoadType)
srcdoc = NullString();
}
// If there is no triggeringPrincipal we can fall back to using the
// SystemPrincipal as the triggeringPrincipal for loading the history
// entry, since the history entry can only end up in history if security
// checks passed in the initial loading phase.
// If there is no valid triggeringPrincipal, we deny the load
MOZ_ASSERT(triggeringPrincipal,
"need a valid triggeringPrincipal to load from history");
if (!triggeringPrincipal) {
triggeringPrincipal = nsContentUtils::GetSystemPrincipal();
return NS_ERROR_FAILURE;
}
// Passing nullptr as aSourceDocShell gives the same behaviour as before

View file

@ -416,6 +416,9 @@ nsSHEntry::Create(nsIURI* aURI, const nsAString& aTitle,
uint64_t aDocShellID,
bool aDynamicCreation)
{
MOZ_ASSERT(aTriggeringPrincipal,
"need a valid triggeringPrincipal to create a session history entry");
mURI = aURI;
mTitle = aTitle;
mPostData = aInputStream;
@ -515,6 +518,10 @@ nsSHEntry::GetTriggeringPrincipal(nsIPrincipal** aTriggeringPrincipal)
NS_IMETHODIMP
nsSHEntry::SetTriggeringPrincipal(nsIPrincipal* aTriggeringPrincipal)
{
MOZ_ASSERT(aTriggeringPrincipal, "need a valid triggeringPrincipal");
if (!aTriggeringPrincipal) {
return NS_ERROR_FAILURE;
}
mShared->mTriggeringPrincipal = aTriggeringPrincipal;
return NS_OK;
}