New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 910841 link

Starred by 1 user

Issue metadata

Status: Started
Owner:
Last visit > 30 days ago
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug



Sign in to add a comment

Inherited CSP should also inherit the self source

Project Member Reported by andypaicu@chromium.org, Dec 1

Issue description

According to the newest version of CSP3 we should inherit the self source whenever we inherit the policy.
 
Project Member

Comment 1 by bugdroid1@chromium.org, Dec 4

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/538b02699f11c2ffa124d673b749b46eb60bd6b9

commit 538b02699f11c2ffa124d673b749b46eb60bd6b9
Author: Andy Paicu <andypaicu@chromium.org>
Date: Tue Dec 04 10:53:00 2018

Inherit the self source when we inherit the policy

Spec: https://w3c.github.io/webappsec-csp/#initialize-document-csp

Bug: 910841
Change-Id: Ic06cf87577c46cfc3a8a2581160c32e22f3956e8
Reviewed-on: https://chromium-review.googlesource.com/c/1357084
Commit-Queue: Andy Paicu <andypaicu@chromium.org>
Reviewed-by: Mike West <mkwst@chromium.org>
Cr-Commit-Position: refs/heads/master@{#613501}
[modify] https://crrev.com/538b02699f11c2ffa124d673b749b46eb60bd6b9/third_party/blink/renderer/core/frame/csp/content_security_policy.cc
[modify] https://crrev.com/538b02699f11c2ffa124d673b749b46eb60bd6b9/third_party/blink/renderer/core/frame/csp/content_security_policy.h
[modify] https://crrev.com/538b02699f11c2ffa124d673b749b46eb60bd6b9/third_party/blink/renderer/core/frame/csp/csp_source.cc
[modify] https://crrev.com/538b02699f11c2ffa124d673b749b46eb60bd6b9/third_party/blink/renderer/core/frame/csp/csp_source.h
[copy] https://crrev.com/538b02699f11c2ffa124d673b749b46eb60bd6b9/third_party/blink/web_tests/external/wpt/content-security-policy/inheritance/iframe-all-local-schemes-inherit-self.sub.html
[rename] https://crrev.com/538b02699f11c2ffa124d673b749b46eb60bd6b9/third_party/blink/web_tests/external/wpt/content-security-policy/inheritance/iframe-all-local-schemes.sub.html

Sign in to add a comment