<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>157355</bug_id>
          
          <creation_ts>2016-05-04 13:40:35 -0700</creation_ts>
          <short_desc>Content Security Policy form-action directive is ignored</short_desc>
          <delta_ts>2016-11-17 11:50:52 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebCore Misc.</component>
          <version>Safari 9</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>DUPLICATE</resolution>
          <dup_id>154520</dup_id>
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Ilya Nesterov">webkit.bugzilla</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          <cc>bfulgham</cc>
    
    <cc>dbates</cc>
    
    <cc>webkit-bug-importer</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1190203</commentid>
    <comment_count>0</comment_count>
      <attachid>278123</attachid>
    <who name="Ilya Nesterov">webkit.bugzilla</who>
    <bug_when>2016-05-04 13:40:35 -0700</bug_when>
    <thetext>Created attachment 278123
form-action blocked test file

Steps to reproduce:

Create a test page with a form which submits data somewhere. 
Add to a page &lt;meta http-equiv=&quot;Content-Security-Policy&quot; content=&quot;form-action &apos;none&apos;&quot;&gt; into &lt;head&gt;.
Load page and submit the form. Form action should be blocked, but it is not.

Alternatively use attached test file.

Load attached &quot;form-action-src-blocked.html&quot; in a browser and click &quot;Submit&quot; button.

You can also reproduce the issue if Content Security Policy delivered via content-security-policy http header. (You need to remove &quot;&lt;meta http-equiv=&quot;Content-Security-Policy&quot; content=&quot;form-action &apos;none&apos;&quot;&gt; from attached file, and adjust your http server settings to add &quot;Content-Security-Policy: form-action &apos;none&apos;&quot; header to response)


Actual results:

Form successfully submitted


Expected results:

Form submit should be blocked. (Open the same file in Chrome)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1210515</commentid>
    <comment_count>1</comment_count>
    <who name="Radar WebKit Bug Importer">webkit-bug-importer</who>
    <bug_when>2016-07-13 10:27:44 -0700</bug_when>
    <thetext>&lt;rdar://problem/27326202&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1252380</commentid>
    <comment_count>2</comment_count>
    <who name="Daniel Bates">dbates</who>
    <bug_when>2016-11-17 11:48:58 -0800</bug_when>
    <thetext>

*** This bug has been marked as a duplicate of bug 154520 ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1252382</commentid>
    <comment_count>3</comment_count>
    <who name="Daniel Bates">dbates</who>
    <bug_when>2016-11-17 11:50:52 -0800</bug_when>
    <thetext>The directive form-action was enabled by default in Safari 10. That is, Safari 9 did not respect this directive.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>278123</attachid>
            <date>2016-05-04 13:40:35 -0700</date>
            <delta_ts>2016-05-04 13:40:35 -0700</delta_ts>
            <desc>form-action blocked test file</desc>
            <filename>form-action-src-blocked.html</filename>
            <type>text/html</type>
            <size>482</size>
            <attacher name="Ilya Nesterov">webkit.bugzilla</attacher>
            
              <data encoding="base64">PCFET0NUWVBFIGh0bWw+CjxodG1sPgo8aGVhZD4KPG1ldGEgaHR0cC1lcXVpdj0iQ29udGVudC1T
ZWN1cml0eS1Qb2xpY3kiIGNvbnRlbnQ9ImZvcm0tYWN0aW9uICdub25lJyI+CjwvaGVhZD4KPGJv
ZHk+CiAgICA8Zm9ybSBhY3Rpb249Jy4vJyBpZD0ndGhlZm9ybScgbWV0aG9kPSdwb3N0Jz4KICAg
ICAgICA8aW5wdXQgdHlwZT0ndGV4dCcgbmFtZT0nZmllbGRuYW1lJyB2YWx1ZT0nZmllbGR2YWx1
ZSc+CiAgICAgICAgPGlucHV0IHR5cGU9J3N1Ym1pdCcgaWQ9J3N1Ym1pdCcgdmFsdWU9J3N1Ym1p
dCc+CiAgICA8L2Zvcm0+CiAgICA8cD5UZXN0cyB0aGF0IGJsb2NraW5nIGZvcm0gYWN0aW9ucyB3
b3JrcyBjb3JyZWN0bHkuIElmIHRoaXMgdGVzdCBwYXNzZXMsIHlvdSB3aWxsIHNlZSBhIGNvbnNv
bGUgZXJyb3IsIGFuZCB3aWxsIG5vdCBzZWUgYSBwYWdlIGluZGljYXRpbmcgYSBmb3JtIHdhcyBQ
T1NUZWQuPC9wPgo8L2JvZHk+CjwvaHRtbD4=
</data>

          </attachment>
      

    </bug>

</bugzilla>