Skip to content

[CSP] Enhance unsafe-eval test to check both realms#32898

Merged
chromium-wpt-export-bot merged 1 commit intomasterfrom
chromium-export-cl-3472768
Feb 21, 2022
Merged

[CSP] Enhance unsafe-eval test to check both realms#32898
chromium-wpt-export-bot merged 1 commit intomasterfrom
chromium-export-cl-3472768

Conversation

@chromium-wpt-export-bot
Copy link
Copy Markdown
Collaborator

@chromium-wpt-export-bot chromium-wpt-export-bot commented Feb 18, 2022

When checking whether eval is allowed, only CSPs of the calleeRealm
should be checked.

Change-Id: I89d3f3f2352dc63538b8479b058f44c12e9ede1a
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/3472768
Reviewed-by: Arthur Sonzogni <[email protected]>
Commit-Queue: Antonio Sartori <[email protected]>
Cr-Commit-Position: refs/heads/main@{#973509}

Copy link
Copy Markdown
Collaborator

@wpt-pr-bot wpt-pr-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The review process for this patch is being conducted in the Chromium project.

When checking whether eval is allowed, only CSPs of the calleeRealm
should be checked.

Change-Id: I89d3f3f2352dc63538b8479b058f44c12e9ede1a
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/3472768
Reviewed-by: Arthur Sonzogni <[email protected]>
Commit-Queue: Antonio Sartori <[email protected]>
Cr-Commit-Position: refs/heads/main@{#973509}
@chromium-wpt-export-bot chromium-wpt-export-bot merged commit d356e83 into master Feb 21, 2022
@chromium-wpt-export-bot chromium-wpt-export-bot deleted the chromium-export-cl-3472768 branch February 21, 2022 14:18
antosart added a commit to w3c/webappsec-csp that referenced this pull request Feb 23, 2022
According to WPTs web-platform-tests/wpt#32898, Firefox, Safari and Chrome only check policies of the calleeRealm for determining if eval is allowed. Discussions on #438 explain why it is probably hopeless to correctly check the callerRealm. This change adapt the spec to adhere the vendors' implementation, and only check calleeRealm.
ryandel8834 added a commit to ryandel8834/WebAppSec-CSP that referenced this pull request Aug 13, 2022
According to WPTs web-platform-tests/wpt#32898, Firefox, Safari and Chrome only check policies of the calleeRealm for determining if eval is allowed. Discussions on #438 explain why it is probably hopeless to correctly check the callerRealm. This change adapt the spec to adhere the vendors' implementation, and only check calleeRealm.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants