mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-29 20:07:30 +09:00
Merge remote-tracking branch 'origin/tracking' into custom
This commit is contained in:
commit
be6796bb20
9 changed files with 401 additions and 65 deletions
|
|
@ -2316,28 +2316,32 @@ nsObjectLoadingContent::LoadObject(bool aNotify,
|
|||
}
|
||||
}
|
||||
|
||||
// Don't allow view-source scheme.
|
||||
// view-source is the only scheme to which this applies at the moment due to
|
||||
// potential timing attacks to read data from cross-origin documents. If this
|
||||
// widens we should add a protocol flag for whether the scheme is only allowed
|
||||
// in top and use something like nsNetUtil::NS_URIChainHasFlags.
|
||||
// https://html.spec.whatwg.org/multipage/iframe-embed-object.html#the-object-element
|
||||
// requires that `embed` and `object` go through `Fetch` with mode=navigate,
|
||||
// see 1.3.5. This will in https://fetch.spec.whatwg.org/#fetching plumb us
|
||||
// through to https://fetch.spec.whatwg.org/#concept-main-fetch where in step
|
||||
// 12 a switch is performed. Since `object` and `embed` have mode=navigate the
|
||||
// result of https://fetch.spec.whatwg.org/#concept-scheme-fetch will decide
|
||||
// if main fetch proceeds. We short-circuit that scheme-fetch here, inspecting
|
||||
// if the scheme of `mURI` is one that would return a network error. The
|
||||
// following schemes are allowed through in scheme fetch:
|
||||
// "about", "blob", "data", "file", "http", "https".
|
||||
// XXXMC: Should we include "ftp" as well?
|
||||
//
|
||||
// Some accessibility tests use our internal "chrome" scheme.
|
||||
if (mType != eType_Null) {
|
||||
nsCOMPtr<nsIURI> tempURI = mURI;
|
||||
nsCOMPtr<nsINestedURI> nestedURI = do_QueryInterface(tempURI);
|
||||
while (nestedURI) {
|
||||
// view-source should always be an nsINestedURI, loop and check the
|
||||
// scheme on this and all inner URIs that are also nested URIs.
|
||||
bool isViewSource = false;
|
||||
rv = tempURI->SchemeIs("view-source", &isViewSource);
|
||||
if (NS_FAILED(rv) || isViewSource) {
|
||||
LOG(("OBJLC [%p]: Blocking as effective URI has view-source scheme",
|
||||
this));
|
||||
mType = eType_Null;
|
||||
bool isCandidate = false;
|
||||
for (const auto& candidate :
|
||||
{"about", "blob", "chrome", "data", "file", "http", "https"}) {
|
||||
rv = mURI->SchemeIs(candidate, &isCandidate);
|
||||
if (NS_SUCCEEDED(rv) && isCandidate) {
|
||||
break;
|
||||
}
|
||||
|
||||
nestedURI->GetInnerURI(getter_AddRefs(tempURI));
|
||||
nestedURI = do_QueryInterface(tempURI);
|
||||
}
|
||||
if (!isCandidate) {
|
||||
LOG(("OBJLC [%p]: Blocking as effective URI does not have an allowed scheme",
|
||||
this));
|
||||
mType = eType_Null;
|
||||
}
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -808,33 +808,51 @@ StripURIForReporting(nsIURI* aURI,
|
|||
nsIURI* aSelfURI,
|
||||
nsACString& outStrippedURI)
|
||||
{
|
||||
// 1) If the origin of uri is a globally unique identifier (for example,
|
||||
// aURI has a scheme of data, blob, or filesystem), then return the
|
||||
// ASCII serialization of uri’s scheme.
|
||||
bool isHttpOrFtp =
|
||||
(NS_SUCCEEDED(aURI->SchemeIs("http", &isHttpOrFtp)) && isHttpOrFtp) ||
|
||||
(NS_SUCCEEDED(aURI->SchemeIs("https", &isHttpOrFtp)) && isHttpOrFtp) ||
|
||||
(NS_SUCCEEDED(aURI->SchemeIs("ftp", &isHttpOrFtp)) && isHttpOrFtp);
|
||||
bool isAllowedScheme =
|
||||
(NS_SUCCEEDED(aURI->SchemeIs("http", &isAllowedScheme)) && isAllowedScheme) ||
|
||||
(NS_SUCCEEDED(aURI->SchemeIs("https", &isAllowedScheme)) && isAllowedScheme) ||
|
||||
(NS_SUCCEEDED(aURI->SchemeIs("ftp", &isAllowedScheme)) && isAllowedScheme) ||
|
||||
(NS_SUCCEEDED(aURI->SchemeIs("ws", &isAllowedScheme)) && isAllowedScheme) ||
|
||||
(NS_SUCCEEDED(aURI->SchemeIs("wss", &isAllowedScheme)) && isAllowedScheme);
|
||||
|
||||
if (!isHttpOrFtp) {
|
||||
// not strictly spec compliant, but what we really care about is
|
||||
// http/https and also ftp. If it's not http/https or ftp, then treat aURI
|
||||
// as if it's a globally unique identifier and just return the scheme.
|
||||
if (!isAllowedScheme) {
|
||||
// Step 1. If url's scheme is not an allowed scheme, then just return url's scheme,
|
||||
// i.e. treat aURI as a globally unique identifier.
|
||||
// What we really care about reporting is http/https/ftp.
|
||||
// https://github.com/w3c/webappsec-csp/issues/735: We also allow WS(S) schemes.
|
||||
aURI->GetScheme(outStrippedURI);
|
||||
return;
|
||||
}
|
||||
|
||||
// 2) If the origin of uri is not the same as the origin of the protected
|
||||
// resource, then return the ASCII serialization of uri’s origin.
|
||||
if (!NS_SecurityCompareURIs(aSelfURI, aURI, false)) {
|
||||
// cross origin redirects also fall into this category, see:
|
||||
// http://www.w3.org/TR/CSP/#violation-reports
|
||||
aURI->GetPrePath(outStrippedURI);
|
||||
// Step 2. Set url's fragment to the empty string.
|
||||
// Implicit in GetSpecIgnoringRef() below.
|
||||
|
||||
// Step 3. Set url's username/password to the empty string.
|
||||
nsCOMPtr<nsIURI> stripped;
|
||||
nsresult rv = aURI->Clone(getter_AddRefs(stripped));
|
||||
if (NS_FAILED(rv)) {
|
||||
// Cloning the URI failed for some reason, just return the scheme.
|
||||
aURI->GetScheme(outStrippedURI);
|
||||
return;
|
||||
}
|
||||
rv = stripped->SetUserPass(EmptyCString());
|
||||
if (NS_FAILED(rv)) {
|
||||
// Mutating the URI failed for some reason, just return the scheme.
|
||||
aURI->GetScheme(outStrippedURI);
|
||||
return;
|
||||
}
|
||||
|
||||
// 3) Return uri, with any fragment component removed.
|
||||
aURI->GetSpecIgnoringRef(outStrippedURI);
|
||||
// Non-standard: https://github.com/w3c/webappsec-csp/issues/735
|
||||
// We match other browsers here: To avoid leaking the whole URL when blocking
|
||||
// (or reporting!) cross-origin navigations inside a frame, we restrict the URLs
|
||||
// to just the (ASCII serialization of) uri's origin.
|
||||
if (!NS_SecurityCompareURIs(aSelfURI, stripped, false)) {
|
||||
stripped->GetPrePath(outStrippedURI);
|
||||
return;
|
||||
}
|
||||
|
||||
// Step 4. Return uri, with any unwanted component removed.
|
||||
stripped->GetSpecIgnoringRef(outStrippedURI);
|
||||
}
|
||||
|
||||
nsresult
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue