Branch: refs/heads/main
Home: https://github.com/WebKit/WebKit
Commit: c62d29d7aae2b9b7070da6441b3a54fb0a46ad3e
https://github.com/WebKit/WebKit/commit/c62d29d7aae2b9b7070da6441b3a54fb0a46ad3e
Author: Ian Gower <[email protected]>
Date: 2026-10-01 (Thu, 01 Oct 2026)
Changed paths:
A
LayoutTests/http/wpt/fetch/local-network-access/navigating-a-frame-is-checked-against-the-initiator-expected.txt
A
LayoutTests/http/wpt/fetch/local-network-access/navigating-a-frame-is-checked-against-the-initiator.html
A
LayoutTests/http/wpt/fetch/local-network-access/resources/lna-frame-navigator.html
A
LayoutTests/http/wpt/fetch/local-network-access/resources/lna-navigation-target.html
M LayoutTests/platform/glib/TestExpectations
M LayoutTests/platform/win/TestExpectations
M Source/WebCore/loader/NavigationRequester.cpp
M Source/WebCore/loader/NavigationRequester.h
M Source/WebKit/NetworkProcess/NetworkResourceLoader.cpp
M
Source/WebKit/Shared/WebCoreArgumentCoders.serialization.in
Log Message:
-----------
Check iframe navigations for Local Network Access against their initiator
https://bugs.webkit.org/show_bug.cgi?id=325552
rdar://188636682
Reviewed by Alex Christensen.
This is Local Network Access feature work:
https://flagged.apple.com:443/proxy?t2=Dh0A0k7rb0&o=aHR0cHM6Ly93aWNnLmdpdGh1Yi5pby9sb2NhbC1uZXR3b3JrLWFjY2Vzcw==&emid=d81dcd87-ec9a-449b-b945-484f0a2bda0f&c=11/
The specification applies the check to navigations as well as subresource
loads. Chromium applies it
only to iframe navigations so far, and top-level navigations stay exempt here
too. But
NetworkResourceLoader skipped every main-resource load, so a public page could
navigate an iframe to a local or loopback address with no check at all,
including from a document that
is not a secure context.
A navigation's client is the document that started it, not the one being
navigated away
from.
Therefore
NavigationRequester now also carries the initiator's secure-context flag and its
local-network and loopback-network permissions-policy state, alongside the
address space its policy
container already had, and the check uses those and the initiator's origins for
an iframe navigation.
A navigation that arrives without an initiator is judged as a non-secure public
client rather than
skipped, so leaving the initiator out does not avoid the check. The new
NavigationRequester fields
default to false.
History traversal and reload of a frame are started by that frame's own
document, so they are judged
against it. Whether a load is top-level still comes from the web process, as do
the initiator's
fields. Deriving both in the network process is a separate change.
The new test is skipped on the glib and Windows ports, which cannot classify
address spaces yet.
*
LayoutTests/http/wpt/fetch/local-network-access/navigating-a-frame-is-checked-against-the-initiator-expected.txt:
Added.
*
LayoutTests/http/wpt/fetch/local-network-access/navigating-a-frame-is-checked-against-the-initiator.html:
Added.
*
LayoutTests/http/wpt/fetch/local-network-access/resources/lna-frame-navigator.html:
Added.
*
LayoutTests/http/wpt/fetch/local-network-access/resources/lna-navigation-target.html:
Added.
* LayoutTests/platform/glib/TestExpectations:
* LayoutTests/platform/win/TestExpectations:
* Source/WebCore/loader/NavigationRequester.cpp:
(WebCore::NavigationRequester::from):
* Source/WebCore/loader/NavigationRequester.h:
* Source/WebKit/NetworkProcess/NetworkResourceLoader.cpp:
(WebKit::NetworkResourceLoader::checkLocalNetworkAccess):
* Source/WebKit/Shared/WebCoreArgumentCoders.serialization.in:
Canonical link:
https://flagged.apple.com:443/proxy?t2=DI5V6P1vv1&o=aHR0cHM6Ly9jb21taXRzLndlYmtpdC5vcmcvMzIyMzc5QG1haW4=&emid=d81dcd87-ec9a-449b-b945-484f0a2bda0f&c=11
To unsubscribe from these emails, change your notification settings at
https://github.com/WebKit/WebKit/settings/notifications