Bug 228826

Summary: Reject non-IPv4 hostnames that end in numbers
Product: WebKit Reporter: Anne van Kesteren <annevk>
Component: DOMAssignee: Alex Christensen <achristensen>
Status: RESOLVED FIXED    
Severity: Normal CC: achristensen, benjamin, cdumez, clopez, cmarcelo, ews-watchlist, thorton, webkit-bug-importer, youennf
Priority: P2 Keywords: InRadar
Version: WebKit Nightly Build   
Hardware: Unspecified   
OS: Unspecified   
Attachments:
Description Flags
Patch
none
Patch
none
Patch
ews-feeder: commit-queue-
Patch
none
Patch
none
Patch none

Attachments
Patch (60.28 KB, patch)
2021-08-06 17:42 PDT, Alex Christensen
no flags
Patch (61.84 KB, patch)
2021-08-09 09:54 PDT, Alex Christensen
no flags
Patch (65.45 KB, patch)
2021-08-09 10:10 PDT, Alex Christensen
ews-feeder: commit-queue-
Patch (65.57 KB, patch)
2021-08-09 11:41 PDT, Alex Christensen
no flags
Patch (68.28 KB, patch)
2021-08-09 12:46 PDT, Alex Christensen
no flags
Patch (70.06 KB, patch)
2021-08-31 15:51 PDT, Alex Christensen
no flags
Alexey Proskuryakov
Comment 1 2021-08-06 10:47:19 PDT
So it I have a website at http://site0.webkit.org, and configured a DNS search domain webkit.org on my machine, the browser should prevent loading site0?..
Alex Christensen
Comment 2 2021-08-06 12:13:38 PDT
No, I believe this only prevents URLs like http://webkit.org.001/ from parsing, with only digits or hex numbers after the last dot.
Alex Christensen
Comment 3 2021-08-06 17:42:18 PDT
EWS Watchlist
Comment 4 2021-08-06 17:43:23 PDT
This patch modifies the imported WPT tests. Please ensure that any changes on the tests (not coming from a WPT import) are exported to WPT. Please see https://trac.webkit.org/wiki/WPTExportProcess
Alex Christensen
Comment 5 2021-08-06 17:52:40 PDT
Alex Christensen
Comment 6 2021-08-06 17:53:42 PDT
Adding (later) to title to remind myself to revisit this after our next branch.
Alex Christensen
Comment 8 2021-08-09 09:54:53 PDT
Alex Christensen
Comment 9 2021-08-09 10:10:23 PDT
Alex Christensen
Comment 10 2021-08-09 11:41:19 PDT
Alex Christensen
Comment 11 2021-08-09 12:46:09 PDT
Radar WebKit Bug Importer
Comment 12 2021-08-31 15:00:47 PDT
Alex Christensen
Comment 13 2021-08-31 15:51:46 PDT
EWS
Comment 14 2021-09-02 16:10:19 PDT
Committed r281963 (241270@main): <https://commits.webkit.org/241270@main> All reviewed patches have been landed. Closing bug and clearing flags on attachment 436956 [details].
Note You need to log in before you can comment on or make changes to this bug.