<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>54590</bug_id>
          
          <creation_ts>2011-02-16 14:47:36 -0800</creation_ts>
          <short_desc>Fix xssAuditor/form-action.html</short_desc>
          <delta_ts>2011-02-17 12:28:36 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>New Bugs</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Other</rep_platform>
          <op_sys>OS X 10.5</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Adam Barth">abarth</reporter>
          <assigned_to name="Adam Barth">abarth</assigned_to>
          <cc>ap</cc>
    
    <cc>commit-queue</cc>
    
    <cc>dbates</cc>
    
    <cc>eric</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>352374</commentid>
    <comment_count>0</comment_count>
    <who name="Adam Barth">abarth</who>
    <bug_when>2011-02-16 14:47:36 -0800</bug_when>
    <thetext>Fix xssAuditor/form-action.html</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>352376</commentid>
    <comment_count>1</comment_count>
      <attachid>82703</attachid>
    <who name="Adam Barth">abarth</who>
    <bug_when>2011-02-16 14:49:06 -0800</bug_when>
    <thetext>Created attachment 82703
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>352381</commentid>
    <comment_count>2</comment_count>
      <attachid>82703</attachid>
    <who name="Eric Seidel (no email)">eric</who>
    <bug_when>2011-02-16 14:51:53 -0800</bug_when>
    <thetext>Comment on attachment 82703
Patch

That diff looks strange due to the file previously being empty.  But looks good.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>352558</commentid>
    <comment_count>3</comment_count>
      <attachid>82703</attachid>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2011-02-16 20:01:14 -0800</bug_when>
    <thetext>Comment on attachment 82703
Patch

Clearing flags on attachment: 82703

Committed r78780: &lt;http://trac.webkit.org/changeset/78780&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>352559</commentid>
    <comment_count>4</comment_count>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2011-02-16 20:01:19 -0800</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>353024</commentid>
    <comment_count>5</comment_count>
    <who name="Alexey Proskuryakov">ap</who>
    <bug_when>2011-02-17 10:54:55 -0800</bug_when>
    <thetext>+        We should block form actions.  Although this technically can&apos;t be used
+        to run script, it&apos;s a pretty easy vector for stealing passwords.

Doesn&apos;t the error message get too confusing then?

+CONSOLE MESSAGE: line 1: Refused to execute a JavaScript script. Source code of script found within request.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>353084</commentid>
    <comment_count>6</comment_count>
    <who name="Adam Barth">abarth</who>
    <bug_when>2011-02-17 12:28:36 -0800</bug_when>
    <thetext>Yep.  We should tailor the error message to what was blocked.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>82703</attachid>
            <date>2011-02-16 14:49:06 -0800</date>
            <delta_ts>2011-02-16 20:01:14 -0800</delta_ts>
            <desc>Patch</desc>
            <filename>bug-54590-20110216144905.patch</filename>
            <type>text/plain</type>
            <size>3857</size>
            <attacher name="Adam Barth">abarth</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogNzg3MjUKZGlmZiAtLWdpdCBhL0xheW91dFRlc3RzL0NoYW5n
ZUxvZyBiL0xheW91dFRlc3RzL0NoYW5nZUxvZwppbmRleCAzODg1NGNiYmZkNmQ5OWI1MzUzZDc0
ZWM1ZGY1ZTQ2MjE4Y2I0MjM3Li5hOTVmODM3ZDQ5N2U5YWU4NzNlMWQ0NGJkYzhjZmZmOThhNjRj
NjY5IDEwMDY0NAotLS0gYS9MYXlvdXRUZXN0cy9DaGFuZ2VMb2cKKysrIGIvTGF5b3V0VGVzdHMv
Q2hhbmdlTG9nCkBAIC0yLDYgKzIsMTcgQEAKIAogICAgICAgICBSZXZpZXdlZCBieSBOT0JPRFkg
KE9PUFMhKS4KIAorICAgICAgICBGaXggeHNzQXVkaXRvci9mb3JtLWFjdGlvbi5odG1sCisgICAg
ICAgIGh0dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD01NDU5MAorCisgICAg
ICAgIFVwZGF0ZSBleHBlY3RlZCByZXN1bHRzIHRvIHNob3cgdGhhdCB3ZSBwYXNzLgorCisgICAg
ICAgICogaHR0cC90ZXN0cy9zZWN1cml0eS94c3NBdWRpdG9yL2Zvcm0tYWN0aW9uLWV4cGVjdGVk
LnR4dDoKKworMjAxMS0wMi0xNiAgQWRhbSBCYXJ0aCAgPGFiYXJ0aEB3ZWJraXQub3JnPgorCisg
ICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorCiAgICAgICAgIEltcG9ydCBYU1NB
dWRpdG9yIHRlc3RzIGZyb20gRGF2aWQgUm9zcwogICAgICAgICBodHRwczovL2J1Z3Mud2Via2l0
Lm9yZy9zaG93X2J1Zy5jZ2k/aWQ9NTQ1NzYKIApkaWZmIC0tZ2l0IGEvTGF5b3V0VGVzdHMvaHR0
cC90ZXN0cy9zZWN1cml0eS94c3NBdWRpdG9yL2Zvcm0tYWN0aW9uLWV4cGVjdGVkLnR4dCBiL0xh
eW91dFRlc3RzL2h0dHAvdGVzdHMvc2VjdXJpdHkveHNzQXVkaXRvci9mb3JtLWFjdGlvbi1leHBl
Y3RlZC50eHQKaW5kZXggOGIxMzc4OTE3OTFmZTk2OTI3YWQ3OGU2NGIwYWFkN2JkZWQwOGJkYy4u
NTEzZTJmOGQwM2Y3NDIwM2EzNWUwYmVlZDFmZDQzYjQzMjkyZGMyZiAxMDA2NDQKLS0tIGEvTGF5
b3V0VGVzdHMvaHR0cC90ZXN0cy9zZWN1cml0eS94c3NBdWRpdG9yL2Zvcm0tYWN0aW9uLWV4cGVj
dGVkLnR4dAorKysgYi9MYXlvdXRUZXN0cy9odHRwL3Rlc3RzL3NlY3VyaXR5L3hzc0F1ZGl0b3Iv
Zm9ybS1hY3Rpb24tZXhwZWN0ZWQudHh0CkBAIC0xICsxLDMgQEAKK0NPTlNPTEUgTUVTU0FHRTog
bGluZSAxOiBSZWZ1c2VkIHRvIGV4ZWN1dGUgYSBKYXZhU2NyaXB0IHNjcmlwdC4gU291cmNlIGNv
ZGUgb2Ygc2NyaXB0IGZvdW5kIHdpdGhpbiByZXF1ZXN0LgorCiAKZGlmZiAtLWdpdCBhL1NvdXJj
ZS9XZWJDb3JlL0NoYW5nZUxvZyBiL1NvdXJjZS9XZWJDb3JlL0NoYW5nZUxvZwppbmRleCAyZjRl
Yjk1YmFjMTNmYzc1ZGEyNjg3YjdkMjc1ZmZhMjhhNTRiYjdiLi44NWQ0NDUyYzU2NTQwZWQzNGYw
Y2FiMWIyY2MzNmVlNTY3MGQyM2E4IDEwMDY0NAotLS0gYS9Tb3VyY2UvV2ViQ29yZS9DaGFuZ2VM
b2cKKysrIGIvU291cmNlL1dlYkNvcmUvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTggQEAKKzIwMTEt
MDItMTYgIEFkYW0gQmFydGggIDxhYmFydGhAd2Via2l0Lm9yZz4KKworICAgICAgICBSZXZpZXdl
ZCBieSBOT0JPRFkgKE9PUFMhKS4KKworICAgICAgICBGaXggeHNzQXVkaXRvci9mb3JtLWFjdGlv
bi5odG1sCisgICAgICAgIGh0dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD01
NDU5MAorCisgICAgICAgIFdlIHNob3VsZCBibG9jayBmb3JtIGFjdGlvbnMuICBBbHRob3VnaCB0
aGlzIHRlY2huaWNhbGx5IGNhbid0IGJlIHVzZWQKKyAgICAgICAgdG8gcnVuIHNjcmlwdCwgaXQn
cyBhIHByZXR0eSBlYXN5IHZlY3RvciBmb3Igc3RlYWxpbmcgcGFzc3dvcmRzLgorCisgICAgICAg
ICogaHRtbC9wYXJzZXIvWFNTRmlsdGVyLmNwcDoKKyAgICAgICAgKFdlYkNvcmU6OlhTU0ZpbHRl
cjo6ZmlsdGVyVG9rZW5Jbml0aWFsKToKKyAgICAgICAgKFdlYkNvcmU6OlhTU0ZpbHRlcjo6Zmls
dGVyRm9ybVRva2VuKToKKyAgICAgICAgKiBodG1sL3BhcnNlci9YU1NGaWx0ZXIuaDoKKwogMjAx
MS0wMi0xNiAgSGFucyBXZW5uYm9yZyAgPGhhbnNAY2hyb21pdW0ub3JnPgogCiAgICAgICAgIFJl
dmlld2VkIGJ5IEplcmVteSBPcmxvdy4KZGlmZiAtLWdpdCBhL1NvdXJjZS9XZWJDb3JlL2h0bWwv
cGFyc2VyL1hTU0ZpbHRlci5jcHAgYi9Tb3VyY2UvV2ViQ29yZS9odG1sL3BhcnNlci9YU1NGaWx0
ZXIuY3BwCmluZGV4IGRlMzFmNzYzMzRjYTBiM2E0NzlmZjEzNjgxZmM1Mzc4YzNlN2VlN2YuLmQ3
ODYxNWNkNTMwMGViZGU0Nzg0OTY1NTc4YTlkMjU0Yjc4NTJlOTEgMTAwNjQ0Ci0tLSBhL1NvdXJj
ZS9XZWJDb3JlL2h0bWwvcGFyc2VyL1hTU0ZpbHRlci5jcHAKKysrIGIvU291cmNlL1dlYkNvcmUv
aHRtbC9wYXJzZXIvWFNTRmlsdGVyLmNwcApAQCAtMjQ5LDYgKzI0OSw4IEBAIGJvb2wgWFNTRmls
dGVyOjpmaWx0ZXJUb2tlbkluaXRpYWwoSFRNTFRva2VuJiB0b2tlbikKICAgICAgICAgZGlkQmxv
Y2tTY3JpcHQgfD0gZmlsdGVyTWV0YVRva2VuKHRva2VuKTsKICAgICBlbHNlIGlmIChoYXNOYW1l
KHRva2VuLCBiYXNlVGFnKSkKICAgICAgICAgZGlkQmxvY2tTY3JpcHQgfD0gZmlsdGVyQmFzZVRv
a2VuKHRva2VuKTsKKyAgICBlbHNlIGlmIChoYXNOYW1lKHRva2VuLCBmb3JtVGFnKSkKKyAgICAg
ICAgZGlkQmxvY2tTY3JpcHQgfD0gZmlsdGVyRm9ybVRva2VuKHRva2VuKTsKIAogICAgIHJldHVy
biBkaWRCbG9ja1NjcmlwdDsKIH0KQEAgLTM2OSw2ICszNzEsMTUgQEAgYm9vbCBYU1NGaWx0ZXI6
OmZpbHRlckJhc2VUb2tlbihIVE1MVG9rZW4mIHRva2VuKQogICAgIHJldHVybiBlcmFzZUF0dHJp
YnV0ZUlmSW5qZWN0ZWQodG9rZW4sIGhyZWZBdHRyKTsKIH0KIAorYm9vbCBYU1NGaWx0ZXI6OmZp
bHRlckZvcm1Ub2tlbihIVE1MVG9rZW4mIHRva2VuKQoreworICAgIEFTU0VSVChtX3N0YXRlID09
IEluaXRpYWwpOworICAgIEFTU0VSVCh0b2tlbi50eXBlKCkgPT0gSFRNTFRva2VuOjpTdGFydFRh
Zyk7CisgICAgQVNTRVJUKGhhc05hbWUodG9rZW4sIGZvcm1UYWcpKTsKKworICAgIHJldHVybiBl
cmFzZUF0dHJpYnV0ZUlmSW5qZWN0ZWQodG9rZW4sIGFjdGlvbkF0dHIpOworfQorCiBib29sIFhT
U0ZpbHRlcjo6ZXJhc2VEYW5nZXJvdXNBdHRyaWJ1dGVzSWZJbmplY3RlZChIVE1MVG9rZW4mIHRv
a2VuKQogewogICAgIERFRklORV9TVEFUSUNfTE9DQUwoU3RyaW5nLCBzYWZlSmF2YVNjcmlwdFVS
TCwgKCJqYXZhc2NyaXB0OnZvaWQoMCkiKSk7CmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViQ29yZS9o
dG1sL3BhcnNlci9YU1NGaWx0ZXIuaCBiL1NvdXJjZS9XZWJDb3JlL2h0bWwvcGFyc2VyL1hTU0Zp
bHRlci5oCmluZGV4IDJjN2Q0Mjg4NWQ5NjM2NzA5Zjc4ODdiMjk0NGRhMTRmYzZiYWFjY2UuLjUx
OWE3MTQ5NDY4NTVhMjA4NjMxOTRkZGZkOGI1ZmYxMzc1YTVlMTIgMTAwNjQ0Ci0tLSBhL1NvdXJj
ZS9XZWJDb3JlL2h0bWwvcGFyc2VyL1hTU0ZpbHRlci5oCisrKyBiL1NvdXJjZS9XZWJDb3JlL2h0
bWwvcGFyc2VyL1hTU0ZpbHRlci5oCkBAIC02MCw2ICs2MCw3IEBAIHByaXZhdGU6CiAgICAgYm9v
bCBmaWx0ZXJBcHBsZXRUb2tlbihIVE1MVG9rZW4mKTsKICAgICBib29sIGZpbHRlck1ldGFUb2tl
bihIVE1MVG9rZW4mKTsKICAgICBib29sIGZpbHRlckJhc2VUb2tlbihIVE1MVG9rZW4mKTsKKyAg
ICBib29sIGZpbHRlckZvcm1Ub2tlbihIVE1MVG9rZW4mKTsKIAogICAgIGJvb2wgZXJhc2VEYW5n
ZXJvdXNBdHRyaWJ1dGVzSWZJbmplY3RlZChIVE1MVG9rZW4mKTsKICAgICBib29sIGVyYXNlQXR0
cmlidXRlSWZJbmplY3RlZChIVE1MVG9rZW4mLCBjb25zdCBRdWFsaWZpZWROYW1lJiwgY29uc3Qg
U3RyaW5nJiByZXBsYWNlbWVudFZhbHVlID0gU3RyaW5nKCkpOwo=
</data>

          </attachment>
      

    </bug>

</bugzilla>