mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-05 23:38:38 +09:00
Issue #2736 - Part 4: Re-work img <src> attribute.
Use subject principal as triggering principal in <img> "src" attribute. Also get rid of the `BeforeMaybeChangeAttr`/`AfterMaybeChangeAttr` dance: It makes more logical sense for these effects to happen _after_ the attribute has actually been changed.
This commit is contained in:
parent
166b25a42c
commit
c8db9efb3c
9 changed files with 168 additions and 71 deletions
|
|
@ -199,6 +199,7 @@
|
|||
#include "nsThreadUtils.h"
|
||||
#include "nsUnicharUtilCIID.h"
|
||||
#include "nsUnicodeProperties.h"
|
||||
#include "nsURLHelper.h"
|
||||
#include "nsViewManager.h"
|
||||
#include "nsViewportInfo.h"
|
||||
#include "nsWidgetsCID.h"
|
||||
|
|
@ -2118,6 +2119,54 @@ nsContentUtils::CanCallerAccess(nsPIDOMWindowInner* aWindow)
|
|||
return CanCallerAccess(SubjectPrincipal(), scriptObject->GetPrincipal());
|
||||
}
|
||||
|
||||
// static
|
||||
nsIPrincipal*
|
||||
nsContentUtils::GetAttrTriggeringPrincipal(nsIContent* aContent, const nsAString& aAttrValue,
|
||||
nsIPrincipal* aSubjectPrincipal)
|
||||
{
|
||||
nsIPrincipal* contentPrin = aContent ? aContent->NodePrincipal() : nullptr;
|
||||
|
||||
// If the subject principal is the same as the content principal, or no
|
||||
// explicit subject principal was provided, we don't need to do any further
|
||||
// checks. Just return the content principal.
|
||||
if (contentPrin == aSubjectPrincipal || !aSubjectPrincipal) {
|
||||
return contentPrin;
|
||||
}
|
||||
|
||||
// If the attribute value is empty, it's not an absolute URL, so don't bother
|
||||
// with more expensive checks.
|
||||
if (!aAttrValue.IsEmpty() &&
|
||||
IsAbsoluteURL(NS_ConvertUTF16toUTF8(aAttrValue))) {
|
||||
return aSubjectPrincipal;
|
||||
}
|
||||
|
||||
return contentPrin;
|
||||
}
|
||||
|
||||
// static
|
||||
bool
|
||||
nsContentUtils::IsAbsoluteURL(const nsACString& aURL)
|
||||
{
|
||||
nsAutoCString scheme;
|
||||
if (NS_FAILED(net_ExtractURLScheme(aURL, scheme))) {
|
||||
// If we can't extract a scheme, it's not an absolute URL.
|
||||
return false;
|
||||
}
|
||||
|
||||
// If it parses as an absolute StandardURL, it's definitely an absolute URL,
|
||||
// so no need to check with the IO service.
|
||||
if (net_IsAbsoluteURL(aURL)) {
|
||||
return true;
|
||||
}
|
||||
|
||||
uint32_t flags;
|
||||
if (NS_SUCCEEDED(sIOService->GetProtocolFlags(scheme.get(), &flags))) {
|
||||
return flags & nsIProtocolHandler::URI_NORELATIVE;
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
//static
|
||||
bool
|
||||
nsContentUtils::InProlog(nsINode *aNode)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue