Branch: refs/heads/main
Home: https://github.com/WebKit/WebKit
Commit: cd3abe0e663eff9880a5d076737d6ed797754488
https://github.com/WebKit/WebKit/commit/cd3abe0e663eff9880a5d076737d6ed797754488
Author: Anne van Kesteren <[email protected]>
Date: 2026-09-30 (Wed, 30 Sep 2026)
Changed paths:
A
LayoutTests/imported/w3c/web-platform-tests/html/browsers/origin/origin-keyed-agent-clusters/1-iframe/parent-no-child-yes-cross-site.sub.https-expected.txt
A
LayoutTests/imported/w3c/web-platform-tests/html/browsers/origin/origin-keyed-agent-clusters/1-iframe/parent-no-child-yes-cross-site.sub.https.html
M
LayoutTests/imported/w3c/web-platform-tests/html/browsers/origin/origin-keyed-agent-clusters/1-iframe/w3c-import.log
A
LayoutTests/imported/w3c/web-platform-tests/html/browsers/origin/origin-keyed-agent-clusters/insecure-http-opener-https-openee.sub-expected.txt
A
LayoutTests/imported/w3c/web-platform-tests/html/browsers/origin/origin-keyed-agent-clusters/insecure-http-opener-https-openee.sub.html
A
LayoutTests/imported/w3c/web-platform-tests/html/browsers/origin/origin-keyed-agent-clusters/insecure-http-parent-https-children.sub-expected.txt
A
LayoutTests/imported/w3c/web-platform-tests/html/browsers/origin/origin-keyed-agent-clusters/insecure-http-parent-https-children.sub.html
M
LayoutTests/imported/w3c/web-platform-tests/html/browsers/origin/origin-keyed-agent-clusters/w3c-import.log
M Source/WebCore/loader/OriginAgentClusterPolicy.cpp
M Source/WebCore/loader/OriginAgentClusterPolicy.h
M Source/WebKit/UIProcess/WebPageProxy.cpp
M Source/WebKit/WebProcess/WebPage/WebFrame.cpp
Log Message:
-----------
Origin-Agent-Cluster should be ignored in non-secure contexts
https://bugs.webkit.org/show_bug.cgi?id=325799
rdar://188806357
Reviewed by Alex Christensen.
A document can only request an origin-keyed agent cluster when the reserved
environment of its navigation is a secure context, which depends on the
environment's top-level creation URL. We only checked the response URL, so an
HTTPS document in an HTTP page was origin-keyed when it asked for it:
window.originAgentCluster returned true while window.isSecureContext returned
false, and document.domain did nothing.
With site isolation, a document that loads in another process is created in
the WebFrame's provisional frame, which WebFrame::didReceivePolicyDecision()
skipped, so it was never origin-keyed.
Tests:
imported/w3c/web-platform-tests/html/browsers/origin/origin-keyed-agent-clusters/1-iframe/parent-no-child-yes-cross-site.sub.https.html
imported/w3c/web-platform-tests/html/browsers/origin/origin-keyed-agent-clusters/insecure-http-opener-https-openee.sub.html
imported/w3c/web-platform-tests/html/browsers/origin/origin-keyed-agent-clusters/insecure-http-parent-https-children.sub.html
Canonical link: https://commits.webkit.org/322350@main
To unsubscribe from these emails, change your notification settings at
https://github.com/WebKit/WebKit/settings/notifications