Summary: | [CSP] eval() is not blocked for stringified literals | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Daniel Bates <dbates> | ||||||
Component: | WebCore Misc. | Assignee: | Daniel Bates <dbates> | ||||||
Status: | RESOLVED FIXED | ||||||||
Severity: | Normal | CC: | bfulgham, ddkilzer, ggaren, mark.lam, saam | ||||||
Priority: | P2 | Keywords: | InRadar | ||||||
Version: | WebKit Local Build | ||||||||
Hardware: | All | ||||||||
OS: | All | ||||||||
Attachments: |
|
Description
Daniel Bates
2015-12-10 17:31:20 PST
Created attachment 267144 [details] Example For convenience, an HTML document using the markup presented in comment 0. Created attachment 267146 [details]
Patch and layout tests
(In reply to comment #3) > Created attachment 267146 [details] > Patch and layout tests The patch doesn't seem to apply. Do you have a line-ending issue? Comment on attachment 267146 [details]
Patch and layout tests
r=me
(In reply to comment #4) > (In reply to comment #3) > > Created attachment 267146 [details] > > Patch and layout tests > > The patch doesn't seem to apply. Do you have a line-ending issue? I inadvertently didn't merge a local Git commit that made changes to files LayoutTests/http/tests/security/contentSecurityPolicy/eval-blocked.html and LayoutTests/http/tests/security/contentSecurityPolicy/eval-blocked-expected.txt. The patch does not apply because it depends on these changes. [5:57pm] dbates: r? <https://bugs.webkit.org/show_bug.cgi?id=152158> [5:58pm] dbates: Let me rebase the patch [5:59pm] saamyjoon: r=me [6:00pm] saamyjoon: w/ rebased patch [6:03pm] dbates: Actually, the reason the patch didn’t apply is because I inadverntly didn’t squah a local commit that changed the existing files LayoutTests/http/tests/security/contentSecurityPolicy/eval-blocked.html and LayoutTests/http/tests/security/contentSecurityPolicy/eval-blocked-expected.txt. [6:03pm] saamyjoon: ok [6:03pm] dbates: Would you like to see those changes? Otherwise, I will squash that local patch into the one I posted and land [6:04pm] saamyjoon: noope, just land it [6:04pm] dbates: Thank you [6:04pm] saamyjoon: np Committed r193939: <http://trac.webkit.org/changeset/193939> |