[Webkit-unassigned] [Bug 183028] pushState and replaceState no longer works in local file

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Tue Feb 27 08:46:26 PST 2018


https://bugs.webkit.org/show_bug.cgi?id=183028

--- Comment #5 from Brent Fulgham <bfulgham at webkit.org> ---
(In reply to Danyao Wang from comment #4)
> Thanks Fred!
> 
> SecurityOrigin::passesFileCheck() is also used in
> SecurityOrigin::canAccess(). I'm not sure if reverting Brent's patch will
> have other undesired effect. So I'm also OK if we just patch
> History::stateObjectAdded() like Blink did.
> 
> bfulgham@, dbates@: Do you have any preference?

Please do not roll this change out without coordinating with me first. We made the original change as part of a security fix and need to make sure this request doesn't reintroduce a possible exploit.

-- 
You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.webkit.org/pipermail/webkit-unassigned/attachments/20180227/e3265f3a/attachment.html>


More information about the webkit-unassigned mailing list