Skip to content

Commit 02562e3

Browse files
author
cdumez@apple.com
committed
Disallow alert/confirm/prompt in cross-origin-domain subframes
https://bugs.webkit.org/show_bug.cgi?id=221568 Reviewed by Geoff Garen. Source/WebCore: Disallow alert/confirm/prompt in cross-origin-domain subframes as per the latest HTML specification: - whatwg/html#6297 Tests: http/tests/security/cross-origin-js-prompt-forbidden.html http/tests/security/same-origin-different-domain-js-prompt-forbidden.html * page/DOMWindow.cpp: (WebCore::DOMWindow::alert): (WebCore::DOMWindow::confirmForBindings): (WebCore::DOMWindow::prompt): * page/SecurityOrigin.cpp: * page/SecurityOrigin.h: LayoutTests: Add layout test coverage and update existing tests to stop using alert() in cross-origin iframes. * fast/events/popup-blocked-from-unique-frame-via-window-open-named-sibling-frame-expected.txt: * fast/events/popup-blocked-from-unique-frame-via-window-open-named-sibling-frame.html: * fast/events/popup-when-select-change-expected.txt: * fast/events/popup-when-select-change.html: * fast/events/resize-subframe-expected.txt: * fast/events/resize-subframe.html: * fast/forms/autofocus-in-sandbox-with-allow-scripts-expected.txt: * fast/forms/autofocus-in-sandbox-with-allow-scripts.html: * fast/frames/resources/navigate-top-by-name-to-fail.html: * fast/frames/sandboxed-iframe-navigation-top-by-name-denied-expected.txt: * http/tests/cookies/resources/third-party-cookie-relaxing-iframe.html: * http/tests/cookies/third-party-cookie-relaxing-expected.txt: * http/tests/history/cross-origin-replace-history-object-child-expected.txt: * http/tests/history/cross-origin-replace-history-object-expected.txt: * http/tests/history/resources/cross-origin-replaces-history-object-child-iframe.html: * http/tests/history/resources/cross-origin-replaces-history-object-iframe.html: * http/tests/plugins/resources/third-party-cookie-accept-policy-iframe.html: * http/tests/plugins/third-party-cookie-accept-policy-expected.txt: * http/tests/security/contentSecurityPolicy/embed-redirect-allowed-expected.txt: * http/tests/security/contentSecurityPolicy/embed-redirect-allowed2-expected.txt: * http/tests/security/contentSecurityPolicy/frame-src-cross-origin-load-expected.txt: * http/tests/security/contentSecurityPolicy/iframe-allowed-when-loaded-via-javascript-url-expected.txt: * http/tests/security/contentSecurityPolicy/iframe-inside-csp-expected.txt: * http/tests/security/contentSecurityPolicy/iframe-redirect-allowed-by-child-src-expected.txt: * http/tests/security/contentSecurityPolicy/iframe-redirect-allowed-by-child-src2-expected.txt: * http/tests/security/contentSecurityPolicy/iframe-redirect-allowed-by-frame-src-expected.txt: * http/tests/security/contentSecurityPolicy/iframe-redirect-allowed-by-frame-src2-expected.txt: * http/tests/security/contentSecurityPolicy/object-redirect-allowed-expected.txt: * http/tests/security/contentSecurityPolicy/object-redirect-allowed2-expected.txt: * http/tests/security/contentSecurityPolicy/resources/alert-fail.html: * http/tests/security/contentSecurityPolicy/resources/alert-fail.js: (catch): * http/tests/security/contentSecurityPolicy/resources/alert-pass.html: * http/tests/security/contentSecurityPolicy/resources/alert-pass.js: (catch): * http/tests/security/contentSecurityPolicy/resources/sandbox.php: * http/tests/security/contentSecurityPolicy/resources/sandboxed-eval.php: * http/tests/security/contentSecurityPolicy/sandbox-allow-scripts-in-http-header-control-expected.txt: * http/tests/security/contentSecurityPolicy/sandbox-allow-scripts-in-http-header-expected.txt: * http/tests/security/contentSecurityPolicy/sandbox-report-only-expected.txt: * http/tests/security/contentSecurityPolicy/upgrade-insecure-requests/proper-nested-upgrades-expected.txt: * http/tests/security/contentSecurityPolicy/upgrade-insecure-requests/upgrades-mixed-content-expected.txt: * http/tests/security/cross-origin-js-prompt-forbidden-expected.txt: Added. * http/tests/security/cross-origin-js-prompt-forbidden.html: Added. * http/tests/security/dataURL/resources/foreign-domain-data-url-accessor-iframe.html: * http/tests/security/dataURL/resources/foreign-domain-data-url-accessor-opened-frame.html: * http/tests/security/dataURL/xss-DENIED-from-data-url-in-foreign-domain-subframe-expected.txt: * http/tests/security/dataURL/xss-DENIED-from-data-url-in-foreign-domain-window-open-expected.txt: * http/tests/security/mixedContent/resources/frame-with-insecure-websocket.html: * http/tests/security/mixedContent/websocket/insecure-websocket-in-iframe-expected.txt: * http/tests/security/resources/cross-origin-js-prompt-forbidden.html: Added. * http/tests/security/same-origin-different-domain-js-prompt-forbidden-expected.txt: Added. * http/tests/security/same-origin-different-domain-js-prompt-forbidden.html: Added. * http/tests/security/xssAuditor/base-href-control-char-expected.txt: * http/tests/security/xssAuditor/base-href-direct-expected.txt: * http/tests/security/xssAuditor/base-href-expected.txt: * http/tests/security/xssAuditor/base-href-null-char-expected.txt: * http/tests/security/xssAuditor/base-href-safe-expected.txt: * http/tests/security/xssAuditor/base-href-safe2-expected.txt: * http/tests/security/xssAuditor/base-href-safe3-expected.txt: * http/tests/security/xssAuditor/base-href-scheme-relative-expected.txt: * http/tests/security/xssAuditor/cached-frame-expected.txt: * http/tests/security/xssAuditor/cached-frame.html: * http/tests/security/xssAuditor/cookie-injection-expected.txt: * http/tests/security/xssAuditor/data-urls-work-expected.txt: * http/tests/security/xssAuditor/data-urls-work.html: * http/tests/security/xssAuditor/dom-write-innerHTML-expected.txt: * http/tests/security/xssAuditor/dom-write-innerHTML.html: * http/tests/security/xssAuditor/form-action-expected.txt: * http/tests/security/xssAuditor/formaction-on-button-expected.txt: * http/tests/security/xssAuditor/formaction-on-input-expected.txt: * http/tests/security/xssAuditor/javascript-link-safe-expected.txt: * http/tests/security/xssAuditor/javascript-link-safe.html: * http/tests/security/xssAuditor/property-escape-noquotes-expected.txt: * http/tests/security/xssAuditor/property-escape-noquotes-tab-slash-chars-expected.txt: * http/tests/security/xssAuditor/property-escape-noquotes-tab-slash-chars.html: * http/tests/security/xssAuditor/property-escape-noquotes.html: * http/tests/security/xssAuditor/property-inject-expected.txt: * http/tests/security/xssAuditor/property-inject.html: * http/tests/security/xssAuditor/resources/base-href/really-safe-script.js: * http/tests/security/xssAuditor/resources/base-href/safe-script.js: * http/tests/security/xssAuditor/resources/echo-intertag.pl: * http/tests/security/xssAuditor/resources/javascript-link-safe.html: * http/tests/security/xssAuditor/resources/nph-cached.pl: * http/tests/security/xssAuditor/resources/safe-script-noquotes.js: * http/tests/security/xssAuditor/resources/safe-script.js: * http/tests/security/xssAuditor/resources/script-tag-safe2.html: * http/tests/security/xssAuditor/script-tag-near-start-expected.txt: * http/tests/security/xssAuditor/script-tag-near-start.html: * http/tests/security/xssAuditor/script-tag-safe2-expected.txt: * http/tests/security/xssAuditor/script-tag-safe2.html: * http/tests/security/xssAuditor/script-tag-safe3-expected.txt: * http/tests/security/xssAuditor/script-tag-safe3.html: * http/tests/security/xssAuditor/script-tag-src-redirect-safe-expected.txt: * http/tests/security/xssAuditor/script-tag-with-injected-comment-expected.txt: * http/tests/security/xssAuditor/script-tag-with-injected-comment.html: * http/tests/security/xssAuditor/script-tag-with-source-same-host-expected.txt: * platform/wk2/http/tests/security/contentSecurityPolicy/upgrade-insecure-requests/proper-nested-upgrades-expected.txt: git-svn-id: http://svn.webkit.org/repository/webkit/trunk@272607 268f45cc-cd09-0410-ab3c-d52691b4dbfc
1 parent 1ea0e89 commit 02562e3

137 files changed

Lines changed: 658 additions & 410 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

LayoutTests/ChangeLog

Lines changed: 108 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,111 @@
1+
2021-02-09 Chris Dumez <cdumez@apple.com>
2+
3+
Disallow alert/confirm/prompt in cross-origin-domain subframes
4+
https://bugs.webkit.org/show_bug.cgi?id=221568
5+
6+
Reviewed by Geoff Garen.
7+
8+
Add layout test coverage and update existing tests to stop using alert() in cross-origin iframes.
9+
10+
* fast/events/popup-blocked-from-unique-frame-via-window-open-named-sibling-frame-expected.txt:
11+
* fast/events/popup-blocked-from-unique-frame-via-window-open-named-sibling-frame.html:
12+
* fast/events/popup-when-select-change-expected.txt:
13+
* fast/events/popup-when-select-change.html:
14+
* fast/events/resize-subframe-expected.txt:
15+
* fast/events/resize-subframe.html:
16+
* fast/forms/autofocus-in-sandbox-with-allow-scripts-expected.txt:
17+
* fast/forms/autofocus-in-sandbox-with-allow-scripts.html:
18+
* fast/frames/resources/navigate-top-by-name-to-fail.html:
19+
* fast/frames/sandboxed-iframe-navigation-top-by-name-denied-expected.txt:
20+
* http/tests/cookies/resources/third-party-cookie-relaxing-iframe.html:
21+
* http/tests/cookies/third-party-cookie-relaxing-expected.txt:
22+
* http/tests/history/cross-origin-replace-history-object-child-expected.txt:
23+
* http/tests/history/cross-origin-replace-history-object-expected.txt:
24+
* http/tests/history/resources/cross-origin-replaces-history-object-child-iframe.html:
25+
* http/tests/history/resources/cross-origin-replaces-history-object-iframe.html:
26+
* http/tests/plugins/resources/third-party-cookie-accept-policy-iframe.html:
27+
* http/tests/plugins/third-party-cookie-accept-policy-expected.txt:
28+
* http/tests/security/contentSecurityPolicy/embed-redirect-allowed-expected.txt:
29+
* http/tests/security/contentSecurityPolicy/embed-redirect-allowed2-expected.txt:
30+
* http/tests/security/contentSecurityPolicy/frame-src-cross-origin-load-expected.txt:
31+
* http/tests/security/contentSecurityPolicy/iframe-allowed-when-loaded-via-javascript-url-expected.txt:
32+
* http/tests/security/contentSecurityPolicy/iframe-inside-csp-expected.txt:
33+
* http/tests/security/contentSecurityPolicy/iframe-redirect-allowed-by-child-src-expected.txt:
34+
* http/tests/security/contentSecurityPolicy/iframe-redirect-allowed-by-child-src2-expected.txt:
35+
* http/tests/security/contentSecurityPolicy/iframe-redirect-allowed-by-frame-src-expected.txt:
36+
* http/tests/security/contentSecurityPolicy/iframe-redirect-allowed-by-frame-src2-expected.txt:
37+
* http/tests/security/contentSecurityPolicy/object-redirect-allowed-expected.txt:
38+
* http/tests/security/contentSecurityPolicy/object-redirect-allowed2-expected.txt:
39+
* http/tests/security/contentSecurityPolicy/resources/alert-fail.html:
40+
* http/tests/security/contentSecurityPolicy/resources/alert-fail.js:
41+
(catch):
42+
* http/tests/security/contentSecurityPolicy/resources/alert-pass.html:
43+
* http/tests/security/contentSecurityPolicy/resources/alert-pass.js:
44+
(catch):
45+
* http/tests/security/contentSecurityPolicy/resources/sandbox.php:
46+
* http/tests/security/contentSecurityPolicy/resources/sandboxed-eval.php:
47+
* http/tests/security/contentSecurityPolicy/sandbox-allow-scripts-in-http-header-control-expected.txt:
48+
* http/tests/security/contentSecurityPolicy/sandbox-allow-scripts-in-http-header-expected.txt:
49+
* http/tests/security/contentSecurityPolicy/sandbox-report-only-expected.txt:
50+
* http/tests/security/contentSecurityPolicy/upgrade-insecure-requests/proper-nested-upgrades-expected.txt:
51+
* http/tests/security/contentSecurityPolicy/upgrade-insecure-requests/upgrades-mixed-content-expected.txt:
52+
* http/tests/security/cross-origin-js-prompt-forbidden-expected.txt: Added.
53+
* http/tests/security/cross-origin-js-prompt-forbidden.html: Added.
54+
* http/tests/security/dataURL/resources/foreign-domain-data-url-accessor-iframe.html:
55+
* http/tests/security/dataURL/resources/foreign-domain-data-url-accessor-opened-frame.html:
56+
* http/tests/security/dataURL/xss-DENIED-from-data-url-in-foreign-domain-subframe-expected.txt:
57+
* http/tests/security/dataURL/xss-DENIED-from-data-url-in-foreign-domain-window-open-expected.txt:
58+
* http/tests/security/mixedContent/resources/frame-with-insecure-websocket.html:
59+
* http/tests/security/mixedContent/websocket/insecure-websocket-in-iframe-expected.txt:
60+
* http/tests/security/resources/cross-origin-js-prompt-forbidden.html: Added.
61+
* http/tests/security/same-origin-different-domain-js-prompt-forbidden-expected.txt: Added.
62+
* http/tests/security/same-origin-different-domain-js-prompt-forbidden.html: Added.
63+
* http/tests/security/xssAuditor/base-href-control-char-expected.txt:
64+
* http/tests/security/xssAuditor/base-href-direct-expected.txt:
65+
* http/tests/security/xssAuditor/base-href-expected.txt:
66+
* http/tests/security/xssAuditor/base-href-null-char-expected.txt:
67+
* http/tests/security/xssAuditor/base-href-safe-expected.txt:
68+
* http/tests/security/xssAuditor/base-href-safe2-expected.txt:
69+
* http/tests/security/xssAuditor/base-href-safe3-expected.txt:
70+
* http/tests/security/xssAuditor/base-href-scheme-relative-expected.txt:
71+
* http/tests/security/xssAuditor/cached-frame-expected.txt:
72+
* http/tests/security/xssAuditor/cached-frame.html:
73+
* http/tests/security/xssAuditor/cookie-injection-expected.txt:
74+
* http/tests/security/xssAuditor/data-urls-work-expected.txt:
75+
* http/tests/security/xssAuditor/data-urls-work.html:
76+
* http/tests/security/xssAuditor/dom-write-innerHTML-expected.txt:
77+
* http/tests/security/xssAuditor/dom-write-innerHTML.html:
78+
* http/tests/security/xssAuditor/form-action-expected.txt:
79+
* http/tests/security/xssAuditor/formaction-on-button-expected.txt:
80+
* http/tests/security/xssAuditor/formaction-on-input-expected.txt:
81+
* http/tests/security/xssAuditor/javascript-link-safe-expected.txt:
82+
* http/tests/security/xssAuditor/javascript-link-safe.html:
83+
* http/tests/security/xssAuditor/property-escape-noquotes-expected.txt:
84+
* http/tests/security/xssAuditor/property-escape-noquotes-tab-slash-chars-expected.txt:
85+
* http/tests/security/xssAuditor/property-escape-noquotes-tab-slash-chars.html:
86+
* http/tests/security/xssAuditor/property-escape-noquotes.html:
87+
* http/tests/security/xssAuditor/property-inject-expected.txt:
88+
* http/tests/security/xssAuditor/property-inject.html:
89+
* http/tests/security/xssAuditor/resources/base-href/really-safe-script.js:
90+
* http/tests/security/xssAuditor/resources/base-href/safe-script.js:
91+
* http/tests/security/xssAuditor/resources/echo-intertag.pl:
92+
* http/tests/security/xssAuditor/resources/javascript-link-safe.html:
93+
* http/tests/security/xssAuditor/resources/nph-cached.pl:
94+
* http/tests/security/xssAuditor/resources/safe-script-noquotes.js:
95+
* http/tests/security/xssAuditor/resources/safe-script.js:
96+
* http/tests/security/xssAuditor/resources/script-tag-safe2.html:
97+
* http/tests/security/xssAuditor/script-tag-near-start-expected.txt:
98+
* http/tests/security/xssAuditor/script-tag-near-start.html:
99+
* http/tests/security/xssAuditor/script-tag-safe2-expected.txt:
100+
* http/tests/security/xssAuditor/script-tag-safe2.html:
101+
* http/tests/security/xssAuditor/script-tag-safe3-expected.txt:
102+
* http/tests/security/xssAuditor/script-tag-safe3.html:
103+
* http/tests/security/xssAuditor/script-tag-src-redirect-safe-expected.txt:
104+
* http/tests/security/xssAuditor/script-tag-with-injected-comment-expected.txt:
105+
* http/tests/security/xssAuditor/script-tag-with-injected-comment.html:
106+
* http/tests/security/xssAuditor/script-tag-with-source-same-host-expected.txt:
107+
* platform/wk2/http/tests/security/contentSecurityPolicy/upgrade-insecure-requests/proper-nested-upgrades-expected.txt:
108+
1109
2021-02-09 Peng Liu <peng.liu6@apple.com>
2110

3111
[GPUP] Test media/track/audio-track-add-remove.html crashes on debug bots
Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
CONSOLE MESSAGE: Unsafe JavaScript attempt to initiate navigation for frame with URL 'about:blank' from frame with URL 'data:text/html,<script>alert(window.open('about:blank', 'A') ?%20'FAIL'%20:%20'PASS');%3C/script%3E'. The frame attempting navigation is neither same-origin with the target, nor is it the target's parent or opener.
1+
CONSOLE MESSAGE: Unsafe JavaScript attempt to initiate navigation for frame with URL 'about:blank' from frame with URL 'data:text/html,<script>console.log(window.open('about:blank', 'A') ?%20'FAIL'%20:%20'PASS');%3C/script%3E'. The frame attempting navigation is neither same-origin with the target, nor is it the target's parent or opener.
22

3-
ALERT: PASS
3+
CONSOLE MESSAGE: PASS
44

LayoutTests/fast/events/popup-blocked-from-unique-frame-via-window-open-named-sibling-frame.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,6 @@
1111
</head>
1212
<body>
1313
<iframe name="A"></iframe>
14-
<iframe name="B" src="data:text/html,<script>alert(window.open('about:blank', 'A') ? 'FAIL' : 'PASS');</script>"></iframe>
14+
<iframe name="B" src="data:text/html,<script>console.log(window.open('about:blank', 'A') ? 'FAIL' : 'PASS');</script>"></iframe>
1515
</body>
1616
</html>

LayoutTests/fast/events/popup-when-select-change-expected.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
ALERT: PASSED
1+
CONSOLE MESSAGE: PASSED
22
If the pop-up was not blocked then there will be an PASS message. Otherwise, the test fails.
33

44

LayoutTests/fast/events/popup-when-select-change.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@
3838
<body onload="test()">
3939
<select onchange="onpopup()" id="control1"><option value="0">abcd</option><option value="0">efgh</option></select>
4040
If the pop-up was not blocked then there will be an PASS message. Otherwise, the test fails.
41-
<form id="form" action="data:text/html,<script>alert('PASSED')</script>" target="target">
41+
<form id="form" action="data:text/html,<script>console.log('PASSED')</script>" target="target">
4242
<input id="control2" type="submit" value="Submit to new window"/>
4343
</form>
4444
<form id="form2" action="data:text/html,<b>hello!</b><script>window.testRunner && testRunner.notifyDone()</script>" target="panel">
Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,2 +1,2 @@
1-
ALERT: PASS
1+
CONSOLE MESSAGE: PASS
22

LayoutTests/fast/events/resize-subframe.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
{
1919
if (window.testRunner)
2020
{
21-
alert('PASS');
21+
console.log('PASS');
2222
testRunner.notifyDone();
2323
}
2424
else
Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,2 +1,2 @@
1-
ALERT: INPUT
1+
CONSOLE MESSAGE: INPUT
22
This test passes if the activeElement is the input element rather than the body (which it would be if the sandbox didn't allow autofocus although allow-scripts flag is set).

LayoutTests/fast/forms/autofocus-in-sandbox-with-allow-scripts.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,4 +5,4 @@
55
This test passes if the activeElement is the input element rather than the body
66
(which it would be if the sandbox didn't allow autofocus although allow-scripts flag is set).
77
<iframe sandbox="allow-scripts allow-modals"
8-
src="data:text/html,<input autofocus onfocus><script>window.onload = function() { alert(document.activeElement.tagName) }</script>"></iframe>
8+
src="data:text/html,<input autofocus onfocus><script>window.onload = function() { console.log(document.activeElement.tagName) }</script>"></iframe>
Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
11
<script>
22
if (window.open("fail-and-notify-done.html", "target"))
3-
alert("FAIL");
3+
console.log("FAIL");
44
if (window.open("fail-and-notify-done.html", "_top"))
5-
alert("FAIL");
5+
console.log("FAIL");
66
if (window.open("fail-and-notify-done.html", "_parent"))
7-
alert("FAIL");
7+
console.log("FAIL");
88
if (window.open("fail-and-notify-done.html", "_blank"))
9-
alert("FAIL");
10-
alert("PASS");
9+
console.log("FAIL");
10+
console.log("PASS");
1111
</script>

0 commit comments

Comments
 (0)