Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: c62d29d7aae2b9b7070da6441b3a54fb0a46ad3e
      
https://github.com/WebKit/WebKit/commit/c62d29d7aae2b9b7070da6441b3a54fb0a46ad3e
  Author: Ian Gower <[email protected]>
  Date:   2026-10-01 (Thu, 01 Oct 2026)

  Changed paths:
    A 
LayoutTests/http/wpt/fetch/local-network-access/navigating-a-frame-is-checked-against-the-initiator-expected.txt
    A 
LayoutTests/http/wpt/fetch/local-network-access/navigating-a-frame-is-checked-against-the-initiator.html
    A 
LayoutTests/http/wpt/fetch/local-network-access/resources/lna-frame-navigator.html
    A 
LayoutTests/http/wpt/fetch/local-network-access/resources/lna-navigation-target.html
    M LayoutTests/platform/glib/TestExpectations
    M LayoutTests/platform/win/TestExpectations
    M Source/WebCore/loader/NavigationRequester.cpp
    M Source/WebCore/loader/NavigationRequester.h
    M Source/WebKit/NetworkProcess/NetworkResourceLoader.cpp
   
M
Source/WebKit/Shared/WebCoreArgumentCoders.serialization.in

  Log Message:
  -----------
  Check iframe navigations for Local Network Access against their initiator
https://bugs.webkit.org/show_bug.cgi?id=325552
rdar://188636682

Reviewed by Alex Christensen.

This is Local Network Access feature work: 
https://flagged.apple.com:443/proxy?t2=Dh0A0k7rb0&o=aHR0cHM6Ly93aWNnLmdpdGh1Yi5pby9sb2NhbC1uZXR3b3JrLWFjY2Vzcw==&emid=d81dcd87-ec9a-449b-b945-484f0a2bda0f&c=11/

The specification applies the check to navigations as well as subresource 
loads. Chromium applies it
only to iframe navigations so far, and top-level navigations stay exempt here 
too. But
NetworkResourceLoader skipped every main-resource load, so a public page could
navigate an iframe to a local or loopback address with no check at all, 
including from a document that
is not a secure context.

A navigation's client is the document that started it, not the one being 
navigated away
from.
Therefore
NavigationRequester now also carries the initiator's secure-context flag and its
local-network and loopback-network permissions-policy state, alongside the 
address space its policy
container already had, and the check uses those and the initiator's origins for 
an iframe navigation.
A navigation that arrives without an initiator is judged as a non-secure public 
client rather than
skipped, so leaving the initiator out does not avoid the check. The new 
NavigationRequester fields
default to false.

History traversal and reload of a frame are started by that frame's own 
document, so they are judged
against it. Whether a load is top-level still comes from the web process, as do 
the initiator's
fields. Deriving both in the network process is a separate change.

The new test is skipped on the glib and Windows ports, which cannot classify 
address spaces yet.

*
LayoutTests/http/wpt/fetch/local-network-access/navigating-a-frame-is-checked-against-the-initiator-expected.txt:
Added.
* 
LayoutTests/http/wpt/fetch/local-network-access/navigating-a-frame-is-checked-against-the-initiator.html:
 Added.
* 
LayoutTests/http/wpt/fetch/local-network-access/resources/lna-frame-navigator.html:
 Added.
* 
LayoutTests/http/wpt/fetch/local-network-access/resources/lna-navigation-target.html:
 Added.
* LayoutTests/platform/glib/TestExpectations:
* LayoutTests/platform/win/TestExpectations:
* Source/WebCore/loader/NavigationRequester.cpp:
(WebCore::NavigationRequester::from):
* Source/WebCore/loader/NavigationRequester.h:
* Source/WebKit/NetworkProcess/NetworkResourceLoader.cpp:
(WebKit::NetworkResourceLoader::checkLocalNetworkAccess):
* Source/WebKit/Shared/WebCoreArgumentCoders.serialization.in:

Canonical link:
https://flagged.apple.com:443/proxy?t2=DI5V6P1vv1&o=aHR0cHM6Ly9jb21taXRzLndlYmtpdC5vcmcvMzIyMzc5QG1haW4=&emid=d81dcd87-ec9a-449b-b945-484f0a2bda0f&c=11



To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to