mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-08 08:48:39 +09:00
[DOM] use the sanitizer to restrict href in svg:use to fragment-only URLs
This commit is contained in:
parent
991e2ffb4b
commit
c0429c9a0f
2 changed files with 18 additions and 4 deletions
|
|
@ -1185,7 +1185,8 @@ nsTreeSanitizer::SanitizeAttributes(mozilla::dom::Element* aElement,
|
|||
continue;
|
||||
}
|
||||
if (IsURL(aURLs, attrLocal)) {
|
||||
if (SanitizeURL(aElement, attrNs, attrLocal)) {
|
||||
bool fragmentOnly = aElement->IsSVGElement(nsGkAtoms::use);
|
||||
if (SanitizeURL(aElement, attrNs, attrLocal, fragmentOnly)) {
|
||||
// in case the attribute removal shuffled the attribute order, start
|
||||
// the loop again.
|
||||
--ac;
|
||||
|
|
@ -1239,7 +1240,8 @@ nsTreeSanitizer::SanitizeAttributes(mozilla::dom::Element* aElement,
|
|||
// else not allowed
|
||||
} else if (aAllowXLink && kNameSpaceID_XLink == attrNs) {
|
||||
if (nsGkAtoms::href == attrLocal) {
|
||||
if (SanitizeURL(aElement, attrNs, attrLocal)) {
|
||||
bool fragmentOnly = aElement->IsSVGElement(nsGkAtoms::use);
|
||||
if (SanitizeURL(aElement, attrNs, attrLocal, fragmentOnly)) {
|
||||
// in case the attribute removal shuffled the attribute order, start
|
||||
// the loop again.
|
||||
--ac;
|
||||
|
|
@ -1273,7 +1275,8 @@ nsTreeSanitizer::SanitizeAttributes(mozilla::dom::Element* aElement,
|
|||
bool
|
||||
nsTreeSanitizer::SanitizeURL(mozilla::dom::Element* aElement,
|
||||
int32_t aNamespace,
|
||||
nsIAtom* aLocalName)
|
||||
nsIAtom* aLocalName,
|
||||
bool aFragmentOnly)
|
||||
{
|
||||
nsAutoString value;
|
||||
aElement->GetAttr(aNamespace, aLocalName, value);
|
||||
|
|
@ -1282,6 +1285,15 @@ nsTreeSanitizer::SanitizeURL(mozilla::dom::Element* aElement,
|
|||
static const char* kWhitespace = "\n\r\t\b";
|
||||
const nsAString& v =
|
||||
nsContentUtils::TrimCharsInSet(kWhitespace, value);
|
||||
// Fragment-only url cannot be harmful.
|
||||
if (!v.IsEmpty() && v.First() == u'#') {
|
||||
return false;
|
||||
}
|
||||
// if we allow only same-document fragment URLs, stop and remove here
|
||||
if (aFragmentOnly) {
|
||||
aElement->UnsetAttr(aNamespace, aLocalName, false);
|
||||
return true;
|
||||
}
|
||||
|
||||
nsIScriptSecurityManager* secMan = nsContentUtils::GetSecurityManager();
|
||||
uint32_t flags = nsIScriptSecurityManager::DISALLOW_INHERIT_PRINCIPAL;
|
||||
|
|
|
|||
|
|
@ -143,11 +143,13 @@ class MOZ_STACK_CLASS nsTreeSanitizer {
|
|||
* @param aElement the element whose attribute to possibly modify
|
||||
* @param aNamespace the namespace of the URL attribute
|
||||
* @param aLocalName the local name of the URL attribute
|
||||
* @param aFragmentOnly allows same-document references only
|
||||
* @return true if the attribute was removed and false otherwise
|
||||
*/
|
||||
bool SanitizeURL(mozilla::dom::Element* aElement,
|
||||
int32_t aNamespace,
|
||||
nsIAtom* aLocalName);
|
||||
nsIAtom* aLocalName,
|
||||
bool aFragmentOnly = false);
|
||||
|
||||
/**
|
||||
* Checks a style rule for the presence of the 'binding' CSS property and
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue