Branch: refs/heads/main
Home: https://github.com/WebKit/WebKit
Commit: 2cedf37da2fa3bed50dfef6f0e3dee6a31c30832
https://github.com/WebKit/WebKit/commit/2cedf37da2fa3bed50dfef6f0e3dee6a31c30832
Author: Charlie Wolfe <[email protected]>
Date: 2026-09-28 (Mon, 28 Sep 2026)
Changed paths:
M
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/connect-src/worker-from-guid.sub-expected.txt
M
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-worker-src-expected.txt
M Source/WebCore/page/csp/ContentSecurityPolicy.cpp
M Source/WebCore/page/csp/ContentSecurityPolicyClient.h
M Source/WebCore/workers/WorkerGlobalScope.cpp
M Source/WebCore/workers/WorkerGlobalScope.h
Log Message:
-----------
Fire securitypolicyviolation events in workers
https://bugs.webkit.org/show_bug.cgi?id=325254
rdar://188368580
Reviewed by Anne van Kesteren.
ContentSecurityPolicy::reportViolation() returned early unless its script
execution context was a
Document, so CSP violations in workers never fired securitypolicyviolation
events or notified
ReportingObservers.
Allow WorkerGlobalScope contexts too. Use the context URL for documentURI, and
dispatch the
violation event on the worker global scope through a new
enqueueSecurityPolicyViolationEvent().
*
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/connect-src/worker-from-guid.sub-expected.txt:
*
LayoutTests/imported/w3c/web-platform-tests/content-security-policy/inside-worker/dedicatedworker-worker-src-expected.txt:
* Source/WebCore/page/csp/ContentSecurityPolicy.cpp:
(WebCore::ContentSecurityPolicy::reportViolation const):
* Source/WebCore/page/csp/ContentSecurityPolicyClient.h:
* Source/WebCore/workers/WorkerGlobalScope.cpp:
(WebCore::WorkerGlobalScope::enqueueSecurityPolicyViolationEvent):
* Source/WebCore/workers/WorkerGlobalScope.h:
Canonical link: https://commits.webkit.org/322099@main
To unsubscribe from these emails, change your notification settings at
https://github.com/WebKit/WebKit/settings/notifications