<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>40404</bug_id>
          
          <creation_ts>2010-06-09 23:48:52 -0700</creation_ts>
          <short_desc>Use allowRequestIfNoIllegalURICharacters instead of context for XSSAuditor::canLoadExternalScriptFromSrc</short_desc>
          <delta_ts>2010-06-10 10:40:12 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>New Bugs</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Other</rep_platform>
          <op_sys>OS X 10.5</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          <blocked>39259</blocked>
          <everconfirmed>1</everconfirmed>
          <reporter name="Adam Barth">abarth</reporter>
          <assigned_to name="Adam Barth">abarth</assigned_to>
          <cc>dbates</cc>
    
    <cc>eric</cc>
    
    <cc>Ms2ger</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>236182</commentid>
    <comment_count>0</comment_count>
    <who name="Adam Barth">abarth</who>
    <bug_when>2010-06-09 23:48:52 -0700</bug_when>
    <thetext>Use allowRequestIfNoIllegalURICharacters instead of context for XSSAuditor::canLoadExternalScriptFromSrc</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>236187</commentid>
    <comment_count>1</comment_count>
      <attachid>58336</attachid>
    <who name="Adam Barth">abarth</who>
    <bug_when>2010-06-09 23:55:41 -0700</bug_when>
    <thetext>Created attachment 58336
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>236188</commentid>
    <comment_count>2</comment_count>
      <attachid>58336</attachid>
    <who name="Eric Seidel (no email)">eric</who>
    <bug_when>2010-06-09 23:58:20 -0700</bug_when>
    <thetext>Comment on attachment 58336
Patch

OK.  dbates should at least see this go by.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>236255</commentid>
    <comment_count>3</comment_count>
    <who name="Ms2ger (he/him; ⌚ UTC+1/+2)">Ms2ger</who>
    <bug_when>2010-06-10 02:28:39 -0700</bug_when>
    <thetext>&gt;     // FIXME: We have no easy way to provide the XSSAuditor with the original
&gt;     // un-processed attribute source, so for now we pass nullAtom.
&gt;-    return m_XSSAuditor-&gt;canLoadExternalScriptFromSrc(nullAtom, srcValue);
&gt;+    return m_XSSAuditor-&gt;canLoadExternalScriptFromSrc(srcValue);

Update the comment?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>236413</commentid>
    <comment_count>4</comment_count>
    <who name="Adam Barth">abarth</who>
    <bug_when>2010-06-10 10:21:52 -0700</bug_when>
    <thetext>Good catch.  One sec.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>236428</commentid>
    <comment_count>5</comment_count>
    <who name="Adam Barth">abarth</who>
    <bug_when>2010-06-10 10:40:12 -0700</bug_when>
    <thetext>Committed r60964: &lt;http://trac.webkit.org/changeset/60964&gt;</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>58336</attachid>
            <date>2010-06-09 23:55:41 -0700</date>
            <delta_ts>2010-06-09 23:58:19 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-40404-20100609235539.patch</filename>
            <type>text/plain</type>
            <size>5920</size>
            <attacher name="Adam Barth">abarth</attacher>
            
              <data encoding="base64">SW5kZXg6IFdlYkNvcmUvQ2hhbmdlTG9nCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIFdlYkNvcmUvQ2hhbmdlTG9n
CShyZXZpc2lvbiA2MDk0MCkKKysrIFdlYkNvcmUvQ2hhbmdlTG9nCSh3b3JraW5nIGNvcHkpCkBA
IC0xLDMgKzEsNDEgQEAKKzIwMTAtMDYtMDkgIEFkYW0gQmFydGggIDxhYmFydGhAd2Via2l0Lm9y
Zz4KKworICAgICAgICBSZXZpZXdlZCBieSBOT0JPRFkgKE9PUFMhKS4KKworICAgICAgICBVc2Ug
YWxsb3dSZXF1ZXN0SWZOb0lsbGVnYWxVUklDaGFyYWN0ZXJzIGluc3RlYWQgb2YgY29udGV4dCBm
b3IgWFNTQXVkaXRvcjo6Y2FuTG9hZEV4dGVybmFsU2NyaXB0RnJvbVNyYworICAgICAgICBodHRw
czovL2J1Z3Mud2Via2l0Lm9yZy9zaG93X2J1Zy5jZ2k/aWQ9NDA0MDQKKworICAgICAgICBXZSBv
cmlnaW5hbGx5IGFkZGVkIHRoZSBjb250ZXh0IHBhcmFtZXRlciB0bworICAgICAgICBjYW5Mb2Fk
RXh0ZXJuYWxTY3JpcHRGcm9tU3JjIHRvIHdvcmsgYXJvdW5kIHNvbWUgZmFsc2UgcG9zaXRpdmVz
IGNhdXNlZAorICAgICAgICBieSBmb2xrcyBjaGVja2luZyBleHRlcm5hbCBzY3JpcHQgVVJMcyBv
biB0aGUgc2VydmVyLiAgT3VyIHRob3VnaHQgd2FzCisgICAgICAgIHRoYXQgd2UgY291bGQgdGVs
bCB0aGVzZSB3ZXJlIG5vdCByZWFsIFhTUyBhdHRhY2tzIGJlY2F1c2UgdGhlCisgICAgICAgIHN1
cnJvdW5kaW5nIGNvbnRleHQgd291bGRuJ3QgbWF0Y2ggaW4gdGhlIFVSTCBhbmQgdGhlIGRvY3Vt
ZW50LgorCisgICAgICAgIEltcGxlbWVudGluZyB0aGlzIGZlYXR1cmUgaW4gdGhlIEhUTUw1IHBh
cnNlciBpcyBoYXJkIGJlY2F1c2UgaXQKKyAgICAgICAgcGllcmNlcyBhIGxheWVyIG9mIGFic3Ry
YWN0aW9uICh0aGUgdG9rZW4gYWJzdHJhY3Rpb24gb2YgdGhlIGlucHV0CisgICAgICAgIHN0cmVh
bSkuICBXZSBjb3VsZCBoYWNrIHRoaXMgaW50byB0aGUgbmV3IHBhcnNlciwgYnV0IGluc3RlYWQg
SSB0aGluaworICAgICAgICBpdCdzIGJldHRlciB0byBzd2l0Y2ggdG8gdXNpbmcgdGhlIGFsbG93
UmVxdWVzdElmTm9JbGxlZ2FsVVJJQ2hhcmFjdGVycworICAgICAgICBoZXVyaXN0aWMuCisKKyAg
ICAgICAgV2UgZGVzaWduZWQgdGhlIGFsbG93UmVxdWVzdElmTm9JbGxlZ2FsVVJJQ2hhcmFjdGVy
cyBhZnRlciB0aGUgY29udGV4dAorICAgICAgICBoZXVyaXN0aWMgdG8gZGVhbCB3aXRoIG90aGVy
IGNhc2VzIHdoZXJlIHRoZSBzZXJ2ZXIgd2FzIHZhbGlkYXRpbmcKKyAgICAgICAgaW5wdXQgYmVm
b3JlIGVjaG9pbmcgaXQuICBIb3dldmVyLCB3ZSBuZXZlciB0cmllZCBhcHBseWluZyBpdCB0bwor
ICAgICAgICBjYW5Mb2FkRXh0ZXJuYWxTY3JpcHRGcm9tU3JjLgorCisgICAgICAgIEl0J3MgcG9z
c2libGUgdGhhdCB0aGlzIHdpbGwgY2F1c2UgZmFsc2UgcG9zaXRpdmVzIGFuZCB3aWxsIG5lZWQg
dG8gYmUKKyAgICAgICAgcmV2ZXJ0ZWQsIHdoaWNoIGlzIHdoeSBJJ3ZlIGxlZnQgaW4gc29tZSBv
ZiB0aGUgaW5mcnVzdHJ1Y3R1cmUgZm9yCisgICAgICAgIGNvbXB1dGluZyBjb250ZXh0LiAgV2Ug
ZG9uJ3QgaGF2ZSBhIGdvb2Qgd2F5IHRvIGtub3cgaWYgdGhhdCB3aWxsCisgICAgICAgIGhhcHBl
biBleGNlcHQgdG8gdHJ5LiAgV2UgZG8ga25vdywgaG93ZXZlciwgdGhhdCB0aGlzIGhldXJpc3Rp
YyB3aWxsCisgICAgICAgIHdvcmsgZm9yIHRoZSBvcmlnaW5hbCBmYWxzZSBwb3NpdGl2ZXMgd2Ug
c2F3LgorCisgICAgICAgICogaHRtbC9IVE1MNVRva2VuaXplci5jcHA6CisgICAgICAgIChXZWJD
b3JlOjpIVE1MNVRva2VuaXplcjo6c2hvdWxkTG9hZEV4dGVybmFsU2NyaXB0RnJvbVNyYyk6Cisg
ICAgICAgICogaHRtbC9IVE1MVG9rZW5pemVyLmNwcDoKKyAgICAgICAgKFdlYkNvcmU6OkhUTUxU
b2tlbml6ZXI6OnBhcnNlVGFnKToKKyAgICAgICAgKiBwYWdlL1hTU0F1ZGl0b3IuY3BwOgorICAg
ICAgICAoV2ViQ29yZTo6WFNTQXVkaXRvcjo6Y2FuTG9hZEV4dGVybmFsU2NyaXB0RnJvbVNyYyk6
CisgICAgICAgICogcGFnZS9YU1NBdWRpdG9yLmg6CisKIDIwMTAtMDYtMDkgIFRvbnkgR2VudGls
Y29yZSAgPHRvbnlnQGNocm9taXVtLm9yZz4KIAogICAgICAgICBSZXZpZXdlZCBieSBBZGFtIEJh
cnRoLgpJbmRleDogV2ViQ29yZS9odG1sL0hUTUw1VG9rZW5pemVyLmNwcAo9PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0t
LSBXZWJDb3JlL2h0bWwvSFRNTDVUb2tlbml6ZXIuY3BwCShyZXZpc2lvbiA2MDk0MCkKKysrIFdl
YkNvcmUvaHRtbC9IVE1MNVRva2VuaXplci5jcHAJKHdvcmtpbmcgY29weSkKQEAgLTIyNyw3ICsy
MjcsNyBAQCBib29sIEhUTUw1VG9rZW5pemVyOjpzaG91bGRMb2FkRXh0ZXJuYWxTCiAgICAgICAg
IHJldHVybiB0cnVlOwogICAgIC8vIEZJWE1FOiBXZSBoYXZlIG5vIGVhc3kgd2F5IHRvIHByb3Zp
ZGUgdGhlIFhTU0F1ZGl0b3Igd2l0aCB0aGUgb3JpZ2luYWwKICAgICAvLyB1bi1wcm9jZXNzZWQg
YXR0cmlidXRlIHNvdXJjZSwgc28gZm9yIG5vdyB3ZSBwYXNzIG51bGxBdG9tLgotICAgIHJldHVy
biBtX1hTU0F1ZGl0b3ItPmNhbkxvYWRFeHRlcm5hbFNjcmlwdEZyb21TcmMobnVsbEF0b20sIHNy
Y1ZhbHVlKTsKKyAgICByZXR1cm4gbV9YU1NBdWRpdG9yLT5jYW5Mb2FkRXh0ZXJuYWxTY3JpcHRG
cm9tU3JjKHNyY1ZhbHVlKTsKIH0KIAogdm9pZCBIVE1MNVRva2VuaXplcjo6ZXhlY3V0ZVNjcmlw
dChjb25zdCBTY3JpcHRTb3VyY2VDb2RlJiBzb3VyY2VDb2RlKQpJbmRleDogV2ViQ29yZS9odG1s
L0hUTUxUb2tlbml6ZXIuY3BwCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIFdlYkNvcmUvaHRtbC9IVE1MVG9rZW5p
emVyLmNwcAkocmV2aXNpb24gNjA5MzgpCisrKyBXZWJDb3JlL2h0bWwvSFRNTFRva2VuaXplci5j
cHAJKHdvcmtpbmcgY29weSkKQEAgLTEzOTUsNyArMTM5NSw3IEBAIEhUTUxUb2tlbml6ZXI6OlN0
YXRlIEhUTUxUb2tlbml6ZXI6OnBhcnMKIAogICAgICAgICAgICAgICAgICAgICAgICAgaWYgKG1f
Y3VycmVudFRva2VuLmJlZ2luVGFnICYmIG1fY3VycmVudFRva2VuLnRhZ05hbWUgPT0gc2NyaXB0
VGFnICYmICFpblZpZXdTb3VyY2VNb2RlKCkgJiYgIW1fcGFyc2VyLT5za2lwTW9kZSgpICYmIG1f
YXR0ck5hbWUgPT0gc3JjQXR0cikgewogICAgICAgICAgICAgICAgICAgICAgICAgICAgIFN0cmlu
ZyBjb250ZXh0KG1fcmF3QXR0cmlidXRlQmVmb3JlVmFsdWUuZGF0YSgpLCBtX3Jhd0F0dHJpYnV0
ZUJlZm9yZVZhbHVlLnNpemUoKSk7Ci0gICAgICAgICAgICAgICAgICAgICAgICAgICAgaWYgKG1f
WFNTQXVkaXRvciAmJiAhbV9YU1NBdWRpdG9yLT5jYW5Mb2FkRXh0ZXJuYWxTY3JpcHRGcm9tU3Jj
KGNvbnRleHQsIGF0dHJpYnV0ZVZhbHVlKSkKKyAgICAgICAgICAgICAgICAgICAgICAgICAgICBp
ZiAobV9YU1NBdWRpdG9yICYmICFtX1hTU0F1ZGl0b3ItPmNhbkxvYWRFeHRlcm5hbFNjcmlwdEZy
b21TcmMoYXR0cmlidXRlVmFsdWUpKQogICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBh
dHRyaWJ1dGVWYWx1ZSA9IGJsYW5rVVJMKCkuc3RyaW5nKCk7CiAgICAgICAgICAgICAgICAgICAg
ICAgICB9CiAKQEAgLTE0MzIsNyArMTQzMiw3IEBAIEhUTUxUb2tlbml6ZXI6OlN0YXRlIEhUTUxU
b2tlbml6ZXI6OnBhcnMKIAogICAgICAgICAgICAgICAgICAgICAgICAgaWYgKG1fY3VycmVudFRv
a2VuLmJlZ2luVGFnICYmIG1fY3VycmVudFRva2VuLnRhZ05hbWUgPT0gc2NyaXB0VGFnICYmICFp
blZpZXdTb3VyY2VNb2RlKCkgJiYgIW1fcGFyc2VyLT5za2lwTW9kZSgpICYmIG1fYXR0ck5hbWUg
PT0gc3JjQXR0cikgewogICAgICAgICAgICAgICAgICAgICAgICAgICAgIFN0cmluZyBjb250ZXh0
KG1fcmF3QXR0cmlidXRlQmVmb3JlVmFsdWUuZGF0YSgpLCBtX3Jhd0F0dHJpYnV0ZUJlZm9yZVZh
bHVlLnNpemUoKSk7Ci0gICAgICAgICAgICAgICAgICAgICAgICAgICAgaWYgKG1fWFNTQXVkaXRv
ciAmJiAhbV9YU1NBdWRpdG9yLT5jYW5Mb2FkRXh0ZXJuYWxTY3JpcHRGcm9tU3JjKGNvbnRleHQs
IGF0dHJpYnV0ZVZhbHVlKSkKKyAgICAgICAgICAgICAgICAgICAgICAgICAgICBpZiAobV9YU1NB
dWRpdG9yICYmICFtX1hTU0F1ZGl0b3ItPmNhbkxvYWRFeHRlcm5hbFNjcmlwdEZyb21TcmMoYXR0
cmlidXRlVmFsdWUpKQogICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBhdHRyaWJ1dGVW
YWx1ZSA9IGJsYW5rVVJMKCkuc3RyaW5nKCk7CiAgICAgICAgICAgICAgICAgICAgICAgICB9CiAK
SW5kZXg6IFdlYkNvcmUvcGFnZS9YU1NBdWRpdG9yLmNwcAo9PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBXZWJDb3Jl
L3BhZ2UvWFNTQXVkaXRvci5jcHAJKHJldmlzaW9uIDYwOTM4KQorKysgV2ViQ29yZS9wYWdlL1hT
U0F1ZGl0b3IuY3BwCSh3b3JraW5nIGNvcHkpCkBAIC0xNzAsNyArMTcwLDcgQEAgYm9vbCBYU1NB
dWRpdG9yOjpjYW5DcmVhdGVJbmxpbmVFdmVudExpcwogICAgIHJldHVybiB0cnVlOwogfQogCi1i
b29sIFhTU0F1ZGl0b3I6OmNhbkxvYWRFeHRlcm5hbFNjcmlwdEZyb21TcmMoY29uc3QgU3RyaW5n
JiBjb250ZXh0LCBjb25zdCBTdHJpbmcmIHVybCkgY29uc3QKK2Jvb2wgWFNTQXVkaXRvcjo6Y2Fu
TG9hZEV4dGVybmFsU2NyaXB0RnJvbVNyYyhjb25zdCBTdHJpbmcmIHVybCkgY29uc3QKIHsKICAg
ICBpZiAoIWlzRW5hYmxlZCgpKQogICAgICAgICByZXR1cm4gdHJ1ZTsKQEAgLTE3OSw4ICsxNzks
OCBAQCBib29sIFhTU0F1ZGl0b3I6OmNhbkxvYWRFeHRlcm5hbFNjcmlwdEZyCiAgICAgICAgIHJl
dHVybiB0cnVlOwogCiAgICAgRmluZFRhc2sgdGFzazsKLSAgICB0YXNrLmNvbnRleHQgPSBjb250
ZXh0OwogICAgIHRhc2suc3RyaW5nID0gdXJsOworICAgIHRhc2suYWxsb3dSZXF1ZXN0SWZOb0ls
bGVnYWxVUklDaGFyYWN0ZXJzID0gdHJ1ZTsKIAogICAgIGlmIChmaW5kSW5SZXF1ZXN0KHRhc2sp
KSB7CiAgICAgICAgIERFRklORV9TVEFUSUNfTE9DQUwoU3RyaW5nLCBjb25zb2xlTWVzc2FnZSwg
KCJSZWZ1c2VkIHRvIGV4ZWN1dGUgYSBKYXZhU2NyaXB0IHNjcmlwdC4gU291cmNlIGNvZGUgb2Yg
c2NyaXB0IGZvdW5kIHdpdGhpbiByZXF1ZXN0LlxuIikpOwpJbmRleDogV2ViQ29yZS9wYWdlL1hT
U0F1ZGl0b3IuaAo9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09Ci0tLSBXZWJDb3JlL3BhZ2UvWFNTQXVkaXRvci5oCShyZXZp
c2lvbiA2MDkzOCkKKysrIFdlYkNvcmUvcGFnZS9YU1NBdWRpdG9yLmgJKHdvcmtpbmcgY29weSkK
QEAgLTkwLDcgKzkwLDcgQEAgbmFtZXNwYWNlIFdlYkNvcmUgewogCiAgICAgICAgIC8vIERldGVy
bWluZXMgd2hldGhlciB0aGUgZXh0ZXJuYWwgc2NyaXB0IHNob3VsZCBiZSBsb2FkZWQgYmFzZWQg
b24gdGhlCiAgICAgICAgIC8vIGNvbnRlbnQgb2YgYW55IHVzZXItc3VibWl0dGVkIGRhdGEuCi0g
ICAgICAgIGJvb2wgY2FuTG9hZEV4dGVybmFsU2NyaXB0RnJvbVNyYyhjb25zdCBTdHJpbmcmIGNv
bnRleHQsIGNvbnN0IFN0cmluZyYgdXJsKSBjb25zdDsKKyAgICAgICAgYm9vbCBjYW5Mb2FkRXh0
ZXJuYWxTY3JpcHRGcm9tU3JjKGNvbnN0IFN0cmluZyYgdXJsKSBjb25zdDsKIAogICAgICAgICAv
LyBEZXRlcm1pbmVzIHdoZXRoZXIgb2JqZWN0IHNob3VsZCBiZSBsb2FkZWQgYmFzZWQgb24gdGhl
IGNvbnRlbnQgb2YKICAgICAgICAgLy8gYW55IHVzZXItc3VibWl0dGVkIGRhdGEuCg==
</data>
<flag name="review"
          id="43379"
          type_id="1"
          status="+"
          setter="eric"
    />
          </attachment>
      

    </bug>

</bugzilla>