Use relative filenames instead of URLs when specifying extension resources (panels, sidebars, icons)/ Also, we used to allow extension requests for any iframes injected into WebInspecor front-end. This patch changes it to only allow extension requests coming from the same origin as the extension we explicitly loaded.
Created attachment 99969 [details] patch
Comment on attachment 99969 [details] patch View in context: https://bugs.webkit.org/attachment.cgi?id=99969&action=review > LayoutTests/platform/gtk/Skipped:-1554 > -inspector/ Thanks for making inspector tests pass on gtk. > Source/WebCore/inspector/front-end/ExtensionServer.js:495 > + } while (resourcePath !== old_path); split("/"), followed by a push on normal / pull on ..
A variation of patch landed as r90581: http://trac.webkit.org/changeset/90581
(In reply to comment #3) > A variation of patch landed as r90581: http://trac.webkit.org/changeset/90581 After this change inspector/extensions/extensions.html times out at least on the Qt Linux Release, SnowLeopard Intel Release, Windows 7 Release bots and inspector/profiler/cpu-profiler-profiling.html on the Qt Linux Release bot.
(In reply to comment #4) > (In reply to comment #3) > > A variation of patch landed as r90581: http://trac.webkit.org/changeset/90581 > > After this change inspector/extensions/extensions.html times out at least on the Qt Linux Release, SnowLeopard Intel Release, Windows 7 Release bots and inspector/profiler/cpu-profiler-profiling.html on the Qt Linux Release bot. Yup, I just noticed this as well, the fix is coming in a few minutes.
(In reply to comment #5) > (In reply to comment #4) > > (In reply to comment #3) > > > A variation of patch landed as r90581: http://trac.webkit.org/changeset/90581 > > > > After this change inspector/extensions/extensions.html times out at least on the Qt Linux Release, SnowLeopard Intel Release, Windows 7 Release bots and inspector/profiler/cpu-profiler-profiling.html on the Qt Linux Release bot. > > Yup, I just noticed this as well, the fix is coming in a few minutes. Actually, not. I'll rather rollback for the time being.