New issue
Advanced search Search tips

Issue 743311 link

Starred by 1 user

Issue metadata

Status: Available
Owner: ----
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug

Blocking:
issue 674329



Sign in to add a comment

XMLHttpRequest should use MIME parser with ABNF validation

Project Member Reported by tyoshino@chromium.org, Jul 15 2017

Issue description

One in HTTPParsers is too loosely implemented.

Need to measure the impact to ensure compatibility.

 
Project Member

Comment 1 by bugdroid1@chromium.org, Jul 15 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/ef9c803b58398f3b2f531103e024035210fb367d

commit ef9c803b58398f3b2f531103e024035210fb367d
Author: Takeshi Yoshino <tyoshino@chromium.org>
Date: Sat Jul 15 06:43:17 2017

Mark the charset parsing methods in HTTPParser as deprecated

FindCharsetInMediaType() looks for a substring that is likely to be
indicating the charset parameter loosely without performing ABNF
validation. New code should use the strict version in HttpUtil.

Bug: 674329, 743311
Change-Id: I9faa60dcb63e983a62aff74601ac16257da28e80
Reviewed-on: https://chromium-review.googlesource.com/564749
Commit-Queue: Takeshi Yoshino <tyoshino@chromium.org>
Reviewed-by: Mike West <mkwst@chromium.org>
Reviewed-by: Yutaka Hirano <yhirano@chromium.org>
Cr-Commit-Position: refs/heads/master@{#486983}
[modify] https://crrev.com/ef9c803b58398f3b2f531103e024035210fb367d/third_party/WebKit/Source/core/xmlhttprequest/XMLHttpRequest.cpp
[modify] https://crrev.com/ef9c803b58398f3b2f531103e024035210fb367d/third_party/WebKit/Source/platform/network/HTTPParsers.cpp
[modify] https://crrev.com/ef9c803b58398f3b2f531103e024035210fb367d/third_party/WebKit/Source/platform/network/HTTPParsers.h

Project Member

Comment 2 by sheriffbot@chromium.org, Jul 16

Labels: Hotlist-Recharge-Cold
Status: Untriaged (was: Available)
This issue has been Available for over a year. If it's no longer important or seems unlikely to be fixed, please consider closing it out. If it is important, please re-triage the issue.

Sorry for the inconvenience if the bug really should have been left as Available.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: -Hotlist-Recharge-Cold
Status: Available (was: Untriaged)

Sign in to add a comment