Summary: | Web Inspector: do not evaluate watch expressions on load. | ||||||
---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Pavel Feldman <pfeldman> | ||||
Component: | Web Inspector (Deprecated) | Assignee: | Pavel Feldman <pfeldman> | ||||
Status: | RESOLVED FIXED | ||||||
Severity: | Normal | CC: | apavlov, bweinstein, joepeck, keishi, loislo, pfeldman, pmuellr, rik, timothy, webkit.review.bot, yurys | ||||
Priority: | P2 | ||||||
Version: | 528+ (Nightly build) | ||||||
Hardware: | All | ||||||
OS: | All | ||||||
Attachments: |
|
Description
Pavel Feldman
2011-08-10 12:09:30 PDT
Created attachment 103516 [details]
Patch
Comment on attachment 103516 [details]
Patch
Is there a chance we have it tested?
Comment on attachment 103516 [details]
Patch
By the time we get control on the front-end, malicious watch update is already performed, not sure how to test this very case :(
(In reply to comment #3) > (From update of attachment 103516 [details]) > By the time we get control on the front-end, malicious watch update is already performed, not sure how to test this very case :( Well, the watch expression can have a side effect on the inspected page, say increment a counter in it and we can check that after frontend opening it has not been incremented yet. We would need to issue a request on the very early stage of the frontend loading though. Comment on attachment 103516 [details] Patch Clearing flags on attachment: 103516 Committed r92827: <http://trac.webkit.org/changeset/92827> All reviewed patches have been landed. Closing bug. |