Skip to content

Fix per-element allow list handling.#57591

Draft
jonathan-j-lee wants to merge 1 commit intoweb-platform-tests:masterfrom
jonathan-j-lee:chromium-export-cl-7516493
Draft

Fix per-element allow list handling.#57591
jonathan-j-lee wants to merge 1 commit intoweb-platform-tests:masterfrom
jonathan-j-lee:chromium-export-cl-7516493

Conversation

@jonathan-j-lee
Copy link
Contributor

RemoveAttribute doesn't remove per-element allow list attributes (when there's also a global allow list). This is per (old) spec, but the spec has been fixed.

Add CHECKs for Sanitizer's primary security guarantee, to make sure similar issues will not result in an unsafe user experience.

Spec: WICG/sanitizer-api#369
Bug: 477643913, 479513763
Change-Id: I60a103f3fea6ad01f2090a13400e1d51941bea11
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7516493
Reviewed-by: Mike West mkwst@chromium.org
Commit-Queue: Daniel Vogelheim vogelheim@chromium.org
Cr-Commit-Position: refs/heads/main@{#1579985}

RemoveAttribute doesn't remove per-element allow list attributes
(when there's also a global allow list). This is per (old) spec,
but the spec has been fixed.

Add CHECKs for Sanitizer's primary security guarantee, to make sure
similar issues will not result in an unsafe user experience.

Spec: WICG/sanitizer-api#369
Bug: 477643913, 479513763
Change-Id: I60a103f3fea6ad01f2090a13400e1d51941bea11
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7516493
Reviewed-by: Mike West <mkwst@chromium.org>
Commit-Queue: Daniel Vogelheim <vogelheim@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1579985}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants