Bug 85233 - CSP shouldn't block about:blank for iframes
: CSP shouldn't block about:blank for iframes
Status: RESOLVED FIXED
: WebKit
New Bugs
: 528+ (Nightly build)
: Unspecified Unspecified
: P2 Normal
Assigned To:
:
:
:
: 53572
  Show dependency treegraph
 
Reported: 2012-04-30 14:21 PST by
Modified: 2012-05-04 10:41 PST (History)


Attachments
Patch (4.21 KB, patch)
2012-05-03 15:48 PST, Adam Barth
no flags Review Patch | Details | Formatted Diff | Diff


Note

You need to log in before you can comment on or make changes to this bug.


Description From 2012-04-30 14:21:52 PST
CSP shouldn't block about:blank for iframes
Requested by abarth on #webkit.
------- Comment #1 From 2012-05-03 15:48:57 PST -------
Created an attachment (id=140115) [details]
Patch
------- Comment #2 From 2012-05-03 16:00:16 PST -------
It might be preferable to check that the URL is, in fact, `about:blank`, rather than allowing anything under `about:`. I know Chromium redirects to `chrome://`, and Safari doesn't do anything dangerous, but perhaps some other port exposes something interesting under `about:*`?
------- Comment #3 From 2012-05-03 16:04:21 PST -------
WebKit treats all "about" URLs as about:blank.  The redirect you see in Chrome takes place before the URL gets to WebKit.  :)
------- Comment #4 From 2012-05-03 16:14:21 PST -------
(From update of attachment 140115 [details])
about:banana!
------- Comment #5 From 2012-05-03 16:38:33 PST -------
(From update of attachment 140115 [details])
Rejecting attachment 140115 [details] from commit-queue.

Failed to run "['/mnt/git/webkit-commit-queue/Tools/Scripts/webkit-patch', '--status-host=queues.webkit.org', '-..." exit_code: 2

Last 500 characters of output:
git/webkit-commit-queue/Source/WebKit/chromium/ui --revision 134581 --non-interactive --force --accept theirs-conflict --ignore-externals' in '/mnt/git/webkit-commit-queue/Source/WebKit/chromium'
46>At revision 134581.

________ running '/usr/bin/python tools/clang/scripts/update.py --mac-only' in '/mnt/git/webkit-commit-queue/Source/WebKit/chromium'

________ running '/usr/bin/python gyp_webkit' in '/mnt/git/webkit-commit-queue/Source/WebKit/chromium'
Updating webkit projects from gyp files...

Full output: http://queues.webkit.org/results/12620267
------- Comment #6 From 2012-05-03 17:52:34 PST -------
(From update of attachment 140115 [details])
Clearing flags on attachment: 140115

Committed r116052: <http://trac.webkit.org/changeset/116052>
------- Comment #7 From 2012-05-03 17:52:46 PST -------
All reviewed patches have been landed.  Closing bug.
------- Comment #8 From 2012-05-04 10:26:22 PST -------
It’d be nicer if the “blank URL protocol” was something we got from KURL.h along with blankURL() instead of being a hard-coded string "about".
------- Comment #9 From 2012-05-04 10:41:39 PST -------
I've filed https://bugs.webkit.org/show_bug.cgi?id=85641 about changing the idiom.