Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[CSP] Enhance unsafe-eval test to check both realms #32898

Merged
merged 1 commit into from
Feb 21, 2022

Conversation

chromium-wpt-export-bot
Copy link
Collaborator

@chromium-wpt-export-bot chromium-wpt-export-bot commented Feb 18, 2022

When checking whether eval is allowed, only CSPs of the calleeRealm
should be checked.

Change-Id: I89d3f3f2352dc63538b8479b058f44c12e9ede1a
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/3472768
Reviewed-by: Arthur Sonzogni <arthursonzogni@chromium.org>
Commit-Queue: Antonio Sartori <antoniosartori@chromium.org>
Cr-Commit-Position: refs/heads/main@{#973509}

Copy link
Collaborator

@wpt-pr-bot wpt-pr-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The review process for this patch is being conducted in the Chromium project.

When checking whether eval is allowed, only CSPs of the calleeRealm
should be checked.

Change-Id: I89d3f3f2352dc63538b8479b058f44c12e9ede1a
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/3472768
Reviewed-by: Arthur Sonzogni <arthursonzogni@chromium.org>
Commit-Queue: Antonio Sartori <antoniosartori@chromium.org>
Cr-Commit-Position: refs/heads/main@{#973509}
@chromium-wpt-export-bot chromium-wpt-export-bot merged commit d356e83 into master Feb 21, 2022
@chromium-wpt-export-bot chromium-wpt-export-bot deleted the chromium-export-cl-3472768 branch February 21, 2022 14:18
antosart added a commit to w3c/webappsec-csp that referenced this pull request Feb 23, 2022
According to WPTs web-platform-tests/wpt#32898, Firefox, Safari and Chrome only check policies of the calleeRealm for determining if eval is allowed. Discussions on #438 explain why it is probably hopeless to correctly check the callerRealm. This change adapt the spec to adhere the vendors' implementation, and only check calleeRealm.
ryandel8834 added a commit to ryandel8834/WebAppSec-CSP that referenced this pull request Aug 13, 2022
According to WPTs web-platform-tests/wpt#32898, Firefox, Safari and Chrome only check policies of the calleeRealm for determining if eval is allowed. Discussions on #438 explain why it is probably hopeless to correctly check the callerRealm. This change adapt the spec to adhere the vendors' implementation, and only check calleeRealm.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants