Attention is currently required from: Kent Tamura.
1 comment:
File third_party/blink/web_tests/platform/generic/virtual/no-auto-wpt-origin-isolation/external/wpt/html/infrastructure/urls/terminology-0/document-base-url-initiated-grand-parent.https.window-expected.txt:
Patch Set #7, Line 3: "https://www1.web-platform.test:8444/common/dispatcher/executor.html?uuid=child_token#interesting-fragment"
This is the interesting leak. I need to disable "origin"-isolation to get it. Otherwise "about:blank" is returned.
To view, visit change 3723568. To unsubscribe, or for help writing mail filters, visit settings.
Attention is currently required from: Kent Tamura.
Exportable changes to web-platform-tests were detected in this CL and a pull request in the upstream repo has been made: https://github.com/web-platform-tests/wpt/pull/34606.
When this CL lands, the bot will automatically merge the PR on GitHub if the required GitHub checks pass; otherwise, ecosystem-infra@ team will triage the failures and may contact you.
WPT Export docs:
https://chromium.googlesource.com/chromium/src/+/main/docs/testing/web_platform_tests.md#Automatic-export-process
Attention is currently required from: Arthur Sonzogni.
Patch set 9:Code-Review +1
Patch set 9:Commit-Queue +2
1 comment:
Patchset:
Thanks!
To view, visit change 3723568. To unsubscribe, or for help writing mail filters, visit settings.
Chromium LUCI CQ submitted this change.
Add regression test for document.baseURI.
The `document.baseURI` is wrongly implemented in Chrome for about:blank
and about:srcdoc.
It allows leaking cross-origin data. The leak happens only when the two
origin are hosted by the same process.
This patch adds regression tests. I am going to mitigate this bug in a
follow-up.
Bug: 1336904
Change-Id: I027249095fc7ba55dc3f68c772a72f473cfec409
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/3723568
Reviewed-by: Kent Tamura <tk...@chromium.org>
Commit-Queue: Arthur Sonzogni <arthurs...@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1019052}
---
M third_party/blink/renderer/core/dom/document.cc
M third_party/blink/web_tests/FlagExpectations/disable-site-isolation-trials
M third_party/blink/web_tests/VirtualTestSuites
A third_party/blink/web_tests/external/wpt/html/infrastructure/urls/terminology-0/document-base-url-initiated-grand-parent.https.window.js
A third_party/blink/web_tests/platform/generic/external/wpt/html/infrastructure/urls/terminology-0/document-base-url-initiated-grand-parent.https.window-expected.txt
A third_party/blink/web_tests/platform/generic/virtual/no-auto-wpt-origin-isolation/external/wpt/html/infrastructure/urls/terminology-0/document-base-url-initiated-grand-parent.https.window-expected.txt
6 files changed, 129 insertions(+), 10 deletions(-)
The WPT PR for this CL has been merged upstream! https://github.com/web-platform-tests/wpt/pull/34606