From: uazo Date: Sat, 9 Jul 2022 06:59:18 +0000 Subject: Remove window name on cross origin navigation See also: https://trac.webkit.org/changeset/209076/webkit Original License: GPL-2.0-or-later - https://spdx.org/licenses/GPL-2.0-or-later.html License: GPL-3.0-only - https://spdx.org/licenses/GPL-3.0-only.html --- content/browser/renderer_host/browsing_context_state.cc | 2 +- .../Remove-window-name-on-cross-origin-navigation.inc | 1 + third_party/blink/renderer/core/loader/document_loader.cc | 4 +++- 3 files changed, 5 insertions(+), 2 deletions(-) create mode 100644 cromite_flags/content/public/common/content_features_cc/Remove-window-name-on-cross-origin-navigation.inc diff --git a/content/browser/renderer_host/browsing_context_state.cc b/content/browser/renderer_host/browsing_context_state.cc --- a/content/browser/renderer_host/browsing_context_state.cc +++ b/content/browser/renderer_host/browsing_context_state.cc @@ -15,7 +15,7 @@ #include "services/network/public/mojom/web_sandbox_flags.mojom.h" namespace features { -BASE_FEATURE(kNewBrowsingContextStateOnBrowsingContextGroupSwap, +BASE_FEATURE_DISABLED(kNewBrowsingContextStateOnBrowsingContextGroupSwap, base::FEATURE_DISABLED_BY_DEFAULT); BrowsingContextStateImplementationType GetBrowsingContextMode() { diff --git a/cromite_flags/content/public/common/content_features_cc/Remove-window-name-on-cross-origin-navigation.inc b/cromite_flags/content/public/common/content_features_cc/Remove-window-name-on-cross-origin-navigation.inc new file mode 100644 --- /dev/null +++ b/cromite_flags/content/public/common/content_features_cc/Remove-window-name-on-cross-origin-navigation.inc @@ -0,0 +1 @@ +SET_CROMITE_FEATURE_ENABLED(kClearCrossSiteCrossBrowsingContextGroupWindowName); diff --git a/third_party/blink/renderer/core/loader/document_loader.cc b/third_party/blink/renderer/core/loader/document_loader.cc --- a/third_party/blink/renderer/core/loader/document_loader.cc +++ b/third_party/blink/renderer/core/loader/document_loader.cc @@ -3057,7 +3057,8 @@ void DocumentLoader::CommitNavigation() { // that the name would be nulled and if the name is accessed after we will // fire a UseCounter. If we decide to move forward with this change, we'd // actually clean the name here. - // frame_->tree().setName(g_null_atom); + if (!previous_window->GetSecurityOrigin()->IsOpaque()) + frame_->Tree().SetName(g_null_atom); frame_->Tree().ExperimentalSetNulledName(); } @@ -3068,6 +3069,7 @@ void DocumentLoader::CommitNavigation() { // TODO(shuuran): CrossSiteCrossBrowsingContextGroupSetNulledName will just // record the fact that the name would be nulled and if the name is accessed // after we will fire a UseCounter. + frame_->Tree().SetName(g_null_atom); frame_->Tree().CrossSiteCrossBrowsingContextGroupSetNulledName(); } --