<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>53444</bug_id>
          
          <creation_ts>2011-01-31 12:16:59 -0800</creation_ts>
          <short_desc>Propagate parent document security origin to newly create Document XML response</short_desc>
          <delta_ts>2011-02-01 06:35:27 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebCore Misc.</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="anton muhin">antonm</reporter>
          <assigned_to name="anton muhin">antonm</assigned_to>
          <cc>commit-queue</cc>
    
    <cc>sam</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>342735</commentid>
    <comment_count>0</comment_count>
    <who name="anton muhin">antonm</who>
    <bug_when>2011-01-31 12:16:59 -0800</bug_when>
    <thetext>Propagate parent document security origin to newly create Document XML response</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>342737</commentid>
    <comment_count>1</comment_count>
      <attachid>80670</attachid>
    <who name="anton muhin">antonm</who>
    <bug_when>2011-01-31 12:21:15 -0800</bug_when>
    <thetext>Created attachment 80670
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>342799</commentid>
    <comment_count>2</comment_count>
      <attachid>80670</attachid>
    <who name="Adam Barth">abarth</who>
    <bug_when>2011-01-31 14:00:01 -0800</bug_when>
    <thetext>Comment on attachment 80670
Patch

This is tricky.  The problem is that responseXML can be from a cross-origin XMLHttpRequest.  This should be ok, because the DOM nodes created in this way really &quot;belong&quot; to the requester (that&apos;s more or less what CORS says).  I&apos;m not really sure how to test this change.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>342800</commentid>
    <comment_count>3</comment_count>
    <who name="Adam Barth">abarth</who>
    <bug_when>2011-01-31 14:00:11 -0800</bug_when>
    <thetext>+sam</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>342802</commentid>
    <comment_count>4</comment_count>
      <attachid>80670</attachid>
    <who name="Adam Barth">abarth</who>
    <bug_when>2011-01-31 14:01:23 -0800</bug_when>
    <thetext>Comment on attachment 80670
Patch

I think this is reasonable.  We might want to give Sam a chance to give us his opinion.  (Bug 53440 has some more context.)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>342961</commentid>
    <comment_count>5</comment_count>
    <who name="Sam Weinig">sam</who>
    <bug_when>2011-01-31 18:56:05 -0800</bug_when>
    <thetext>This seems reasonable to me.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>343139</commentid>
    <comment_count>6</comment_count>
      <attachid>80670</attachid>
    <who name="anton muhin">antonm</who>
    <bug_when>2011-02-01 04:36:19 -0800</bug_when>
    <thetext>Comment on attachment 80670
Patch

Thanks a lot, Adam and Sam.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>343192</commentid>
    <comment_count>7</comment_count>
      <attachid>80670</attachid>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2011-02-01 06:35:22 -0800</bug_when>
    <thetext>Comment on attachment 80670
Patch

Clearing flags on attachment: 80670

Committed r77246: &lt;http://trac.webkit.org/changeset/77246&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>343193</commentid>
    <comment_count>8</comment_count>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2011-02-01 06:35:27 -0800</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>80670</attachid>
            <date>2011-01-31 12:21:15 -0800</date>
            <delta_ts>2011-02-01 06:35:22 -0800</delta_ts>
            <desc>Patch</desc>
            <filename>bug-53444-20110131232113.patch</filename>
            <type>text/plain</type>
            <size>1402</size>
            <attacher name="anton muhin">antonm</attacher>
            
              <data encoding="base64">ZGlmZiAtLWdpdCBhL1NvdXJjZS9XZWJDb3JlL0NoYW5nZUxvZyBiL1NvdXJjZS9XZWJDb3JlL0No
YW5nZUxvZwppbmRleCA0MzIyYWEyOTI0NzFhMmJjNDZhMzQ5ZDc0ZmY4OTJjOThjMWRhY2FiLi44
YzlkMmFiNGEzODFhMWQ0ODM1MmQ2MjgyNWRlOTJjODMyZDkyZGM0IDEwMDY0NAotLS0gYS9Tb3Vy
Y2UvV2ViQ29yZS9DaGFuZ2VMb2cKKysrIGIvU291cmNlL1dlYkNvcmUvQ2hhbmdlTG9nCkBAIC0x
LDMgKzEsMTUgQEAKKzIwMTEtMDEtMzEgIEFudG9uIE11aGluICA8YW50b25tQGNocm9taXVtLm9y
Zz4KKworICAgICAgICBSZXZpZXdlZCBieSBOT0JPRFkgKE9PUFMhKS4KKworICAgICAgICBQcm9w
YWdhdGUgcGFyZW50IGRvY3VtZW50IHNlY3VyaXR5IG9yaWdpbiB0byBuZXdseSBjcmVhdGUgRG9j
dW1lbnQgWE1MIHJlc3BvbnNlCisgICAgICAgIGh0dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3df
YnVnLmNnaT9pZD01MzQ0NAorCisgICAgICAgIENvdmVyZWQgYnkgdGhlIGV4aXN0aW5nIHRlc3Rz
LgorCisgICAgICAgICogeG1sL1hNTEh0dHBSZXF1ZXN0LmNwcDoKKyAgICAgICAgKFdlYkNvcmU6
OlhNTEh0dHBSZXF1ZXN0OjpyZXNwb25zZVhNTCk6CisKIDIwMTEtMDEtMzEgIEFiaGlzaGVrIEFy
eWEgIDxpbmZlcm5vQGNocm9taXVtLm9yZz4KIAogICAgICAgICBSZXZpZXdlZCBieSBEaW1pdHJp
IEdsYXprb3YuCmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViQ29yZS94bWwvWE1MSHR0cFJlcXVlc3Qu
Y3BwIGIvU291cmNlL1dlYkNvcmUveG1sL1hNTEh0dHBSZXF1ZXN0LmNwcAppbmRleCA0YWQ2YjE3
MzM4NTUxMTZhM2RhYTE2ZjZiM2NiOTk3OWI5ZTY1ZWY5Li4zZTZlMGE5NGFkNzM4MmQ5MjgyZGE2
NTA3Y2YzNzJmMWUzMjJlYzlhIDEwMDY0NAotLS0gYS9Tb3VyY2UvV2ViQ29yZS94bWwvWE1MSHR0
cFJlcXVlc3QuY3BwCisrKyBiL1NvdXJjZS9XZWJDb3JlL3htbC9YTUxIdHRwUmVxdWVzdC5jcHAK
QEAgLTI0OSw2ICsyNDksNyBAQCBEb2N1bWVudCogWE1MSHR0cFJlcXVlc3Q6OnJlc3BvbnNlWE1M
KEV4Y2VwdGlvbkNvZGUmIGVjKQogICAgICAgICAgICAgbV9yZXNwb25zZVhNTCA9IERvY3VtZW50
OjpjcmVhdGUoMCwgbV91cmwpOwogICAgICAgICAgICAgLy8gRklYTUU6IFNldCBMYXN0LU1vZGlm
aWVkLgogICAgICAgICAgICAgbV9yZXNwb25zZVhNTC0+c2V0Q29udGVudChtX3Jlc3BvbnNlQnVp
bGRlci50b1N0cmluZ1ByZXNlcnZlQ2FwYWNpdHkoKSk7CisgICAgICAgICAgICBtX3Jlc3BvbnNl
WE1MLT5zZXRTZWN1cml0eU9yaWdpbihkb2N1bWVudCgpLT5zZWN1cml0eU9yaWdpbigpKTsKICAg
ICAgICAgICAgIGlmICghbV9yZXNwb25zZVhNTC0+d2VsbEZvcm1lZCgpKQogICAgICAgICAgICAg
ICAgIG1fcmVzcG9uc2VYTUwgPSAwOwogICAgICAgICB9Cg==
</data>

          </attachment>
      

    </bug>

</bugzilla>