[pre-flight] Compare effective ports, and each scheme's own default, for 'self' - #1
Closed
jonathanKingston wants to merge 1 commit into
Closed
jonathanKingston wants to merge 1 commit into
jonathanKingston wants to merge 1 commit into
Conversation
"Does url match expression in origin with redirect count?" lets 'self' match when the origin's and the URL's ports "are either the same or the default ports for their respective schemes", so that a document on http://example.com matches https://example.com and wss://example.com. Neither half of that worked on default ports. rust-url reports `Url::port()` as None whenever the port is the scheme's default, so comparing it against `default_port(..)` - which returns Some(80) for http, Some(443) for https - could not be true; `ports_are_default` was dead code. The same comparison also judged the URL's default port by the protected resource's scheme rather than the URL's own, so an http origin was asking whether the URL's port was 80 while looking at an https URL. Net effect: 'self' matched an upgraded scheme only on explicit non-default ports. A page on https://example.com with connect-src 'self' could not open a WebSocket to wss://example.com/socket, and one on http://example.com did not match https://example.com. Compare `port_or_known_default()` against each scheme's own default instead. The existing WPT for this (connect-src-websocket-self.sub.html) exercises exactly that pair, but over the test server's non-default ports, where the broken comparison happens to give the right answer.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pre-flight only — do not merge. This PR exists to run the fork's own CI
against the branch before it goes to
rust-ammonia/rust-content-security-policy.Merging it would put the commit on this fork's
masterand make future rebasesonto upstream messier.
The base is
ci, which is upstream master plus the fork-only workflow. The diffabove is just the patch: the workflow file is on the base side only, so it never
reaches the branch we send upstream.