Commit 00d57a5
Javascript Binding - Finalize JavascriptBindingApiAllowOrigins: Per-browser isolation and origin normalization (#5218)
* Javascript Binding - Add Ability to limit origins
* Move JS binding settings to CefBrowserWrapper and optimize origin validation
* Initialize origins to null
* Normalize allowed origins
* Optimize origin validation
* Add null check for origin compare
* Fix JavaScript Binding API settings for popups
Move the JS binding API configuration block out of the !browser->IsPopup() scope
in OnBrowserCreated. This ensures that IsJavascriptBindingApiAllowed() enforces
configured restrictions for popups as well.
* Fix possible null deref for JavascriptBindingApiAllowOrigins
In IsJavascriptBindingApiAllowed, added a null check for JavascriptBindingApiAllowOrigins
to prevent a potential null dereference if JavascriptBindingApiHasAllowOrigins is true
but the allowOrigins list itself was null.
* Simplify origin normalization and add null check
* Add more test cases
* Refactor IsJavascriptBindingApiAllowed signature
Refactored IsJavascriptBindingApiAllowed to accept a CefBrowserWrapper^ parameter directly, eliminating redundant lookups and improving clarity. Updated all call sites to pass the browser wrapper explicitly.
* Clarify summary for HasJavascriptBindingApiAllowOrigins
Clarify documentation for HasJavascriptBindingApiAllowOrigins method to specify zero or more origins
* Simplify origin comparison logic in CefAppUnmanagedWrapper
Refactored code to directly compare wide string origins using
_wcsicmp, removing unnecessary pointer casts and null checks.
This streamlines the logic and improves readability.
* Add tests for JavaScript binding API behavior across cross-origin navigation
---------
Co-authored-by: amaitland <307872+amaitland@users.noreply.github.com>
Co-authored-by: Luca Sonntag <luca.sonntag@cgm.com>1 parent 6de821c commit 00d57a5
File tree
6 files changed
+328
-11
lines changed- CefSharp.BrowserSubprocess.Core
- CefSharp.Core.Runtime
- CefSharp.Test/JavascriptBinding
- CefSharp/JavascriptBinding
6 files changed
+328
-11
lines changedLines changed: 72 additions & 8 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
23 | 23 | | |
24 | 24 | | |
25 | 25 | | |
| 26 | + | |
26 | 27 | | |
27 | 28 | | |
28 | 29 | | |
| |||
87 | 88 | | |
88 | 89 | | |
89 | 90 | | |
90 | | - | |
| 91 | + | |
91 | 92 | | |
92 | 93 | | |
93 | 94 | | |
| |||
98 | 99 | | |
99 | 100 | | |
100 | 101 | | |
| 102 | + | |
101 | 103 | | |
102 | | - | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
103 | 112 | | |
104 | | - | |
| 113 | + | |
105 | 114 | | |
106 | | - | |
107 | | - | |
108 | | - | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
109 | 120 | | |
110 | 121 | | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
111 | 129 | | |
112 | 130 | | |
113 | 131 | | |
| |||
147 | 165 | | |
148 | 166 | | |
149 | 167 | | |
150 | | - | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
151 | 171 | | |
152 | 172 | | |
153 | 173 | | |
154 | | - | |
155 | 174 | | |
156 | 175 | | |
157 | 176 | | |
| |||
328 | 347 | | |
329 | 348 | | |
330 | 349 | | |
| 350 | + | |
| 351 | + | |
| 352 | + | |
| 353 | + | |
| 354 | + | |
| 355 | + | |
| 356 | + | |
| 357 | + | |
| 358 | + | |
| 359 | + | |
| 360 | + | |
| 361 | + | |
| 362 | + | |
| 363 | + | |
| 364 | + | |
| 365 | + | |
| 366 | + | |
| 367 | + | |
| 368 | + | |
| 369 | + | |
| 370 | + | |
| 371 | + | |
| 372 | + | |
| 373 | + | |
| 374 | + | |
| 375 | + | |
| 376 | + | |
| 377 | + | |
| 378 | + | |
| 379 | + | |
| 380 | + | |
| 381 | + | |
| 382 | + | |
| 383 | + | |
| 384 | + | |
| 385 | + | |
| 386 | + | |
| 387 | + | |
| 388 | + | |
| 389 | + | |
| 390 | + | |
| 391 | + | |
| 392 | + | |
| 393 | + | |
| 394 | + | |
331 | 395 | | |
332 | 396 | | |
333 | 397 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
32 | | - | |
33 | 32 | | |
34 | 33 | | |
35 | 34 | | |
| |||
39 | 38 | | |
40 | 39 | | |
41 | 40 | | |
| 41 | + | |
42 | 42 | | |
43 | 43 | | |
44 | 44 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
25 | | - | |
| 25 | + | |
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
29 | 29 | | |
30 | 30 | | |
| 31 | + | |
31 | 32 | | |
32 | 33 | | |
33 | 34 | | |
34 | 35 | | |
35 | 36 | | |
36 | 37 | | |
37 | 38 | | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
38 | 43 | | |
39 | 44 | | |
40 | 45 | | |
41 | 46 | | |
42 | 47 | | |
| 48 | + | |
| 49 | + | |
43 | 50 | | |
44 | 51 | | |
45 | 52 | | |
| |||
49 | 56 | | |
50 | 57 | | |
51 | 58 | | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
52 | 66 | | |
53 | 67 | | |
54 | 68 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
84 | 84 | | |
85 | 85 | | |
86 | 86 | | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
87 | 103 | | |
88 | 104 | | |
89 | 105 | | |
| |||
0 commit comments