
RenderFrameHostImpl::UpdateSubresourceLoaderFactories method is called after NetworkService process crashes and recreates/resends URLLoaderFactory objects to the renderer process. Before this CL, the recreated factory was always based on the |last_committed_origin_| (and |last_committed_client_security_state_|, etc.). This resulted in creating a factory with a wrong |request_initiator_origin_lock| to a frame that was in the process of committing a navigation. A similar problem (using |last_committed_origin_| rather than the target origin of an in-flight/in-commit NavigationRequest) has already been known (had to be addressed in https://crbug.com/1047436) but the known scenario and the fix (e.g. RFHI::GetExpectedMainWorldOriginForUrlLoaderFactory) focused on isolated world factories. In this CL, the previous fix is made more generic by splitting GetExpectedMainWorldOriginForUrlLoaderFactory across FindLatestNavigationRequestThatIsStillCommitting and ExtractFactoryParamsFromNavigationRequestOrLastCommittedNavigation methods. While working on the CL, all callers of RFHI::CreateURLLoaderFactoryParamsForMainWorld and RFHI::CreateURLLoaderFactoriesForIsolatedWorlds have been inspected and most of these callers have been switched to basing factory parameters based on the in-flight NavigationRequest if one exists. (all except RFHI::CreateNetworkServiceDefaultFactory that is exposed via //content/browser/public and we assume has an expectation of working with the last committed origin). Bug: 1056949 Change-Id: I3cadd28ec71d8a203117a314d084314e60babc03 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/2399184 Auto-Submit: Łukasz Anforowicz <lukasza@chromium.org> Commit-Queue: Łukasz Anforowicz <lukasza@chromium.org> Reviewed-by: Alex Moshchuk <alexmos@chromium.org> Cr-Commit-Position: refs/heads/master@{#807668}
93 lines
3.4 KiB
C++
93 lines
3.4 KiB
C++
// Copyright 2019 The Chromium Authors. All rights reserved.
|
|
// Use of this source code is governed by a BSD-style license that can be
|
|
// found in the LICENSE file.
|
|
|
|
#ifndef CONTENT_TEST_DID_COMMIT_NAVIGATION_INTERCEPTOR_H_
|
|
#define CONTENT_TEST_DID_COMMIT_NAVIGATION_INTERCEPTOR_H_
|
|
|
|
#include <map>
|
|
#include <memory>
|
|
|
|
#include "base/callback.h"
|
|
#include "base/macros.h"
|
|
#include "base/run_loop.h"
|
|
#include "content/common/frame.mojom.h"
|
|
#include "content/public/browser/web_contents_observer.h"
|
|
#include "url/gurl.h"
|
|
|
|
namespace content {
|
|
|
|
class RenderFrameHost;
|
|
class NavigationRequest;
|
|
|
|
// Allows intercepting calls to RenderFrameHostImpl::DidCommitNavigation just
|
|
// before they are processed by the implementation. This enables unit/browser
|
|
// tests to scrutinize/alter the parameters, or simulate race conditions by
|
|
// triggering other calls just before processing DidCommitProvisionalLoad.
|
|
class DidCommitNavigationInterceptor : public WebContentsObserver {
|
|
public:
|
|
// Constructs an instance that will intercept DidCommitProvisionalLoad calls
|
|
// in any frame of the |web_contents| while the instance is in scope.
|
|
explicit DidCommitNavigationInterceptor(WebContents* web_contents);
|
|
~DidCommitNavigationInterceptor() override;
|
|
|
|
// Called just before DidCommitNavigation with |navigation_request|, |params|
|
|
// and |interface_provider_request| would be processed by
|
|
// |render_frame_host|.
|
|
// Return false to cancel the processing of this call by |render_frame_host|.
|
|
virtual bool WillProcessDidCommitNavigation(
|
|
RenderFrameHost* render_frame_host,
|
|
NavigationRequest* navigation_request,
|
|
::FrameHostMsg_DidCommitProvisionalLoad_Params* params,
|
|
mojom::DidCommitProvisionalLoadInterfaceParamsPtr* interface_params) = 0;
|
|
|
|
private:
|
|
class FrameAgent;
|
|
|
|
// WebContentsObserver:
|
|
void RenderFrameCreated(RenderFrameHost* render_frame_host) override;
|
|
void RenderFrameDeleted(RenderFrameHost* render_frame_host) override;
|
|
|
|
std::map<RenderFrameHost*, std::unique_ptr<FrameAgent>> frame_agents_;
|
|
|
|
DISALLOW_COPY_AND_ASSIGN(DidCommitNavigationInterceptor);
|
|
};
|
|
|
|
// A helper class to run a predefined callback just before processing the
|
|
// DidCommitProvisionalLoad IPC for |deferred_url|.
|
|
class CommitMessageDelayer : public DidCommitNavigationInterceptor {
|
|
public:
|
|
using DidCommitCallback = base::OnceCallback<void(RenderFrameHost*)>;
|
|
|
|
// Starts monitoring |web_contents| for DidCommit IPC and executes
|
|
// |deferred_action| for each DidCommit IPC that matches |deferred_url|.
|
|
explicit CommitMessageDelayer(WebContents* web_contents,
|
|
const GURL& deferred_url,
|
|
DidCommitCallback deferred_action);
|
|
~CommitMessageDelayer() override;
|
|
|
|
// Waits until DidCommit IPC arrives for |deferred_url|, then calls
|
|
// |deferred_action|, then handles the IPC, then returns.
|
|
void Wait();
|
|
|
|
private:
|
|
// DidCommitNavigationInterceptor:
|
|
bool WillProcessDidCommitNavigation(
|
|
RenderFrameHost* render_frame_host,
|
|
NavigationRequest* navigation_request,
|
|
::FrameHostMsg_DidCommitProvisionalLoad_Params* params,
|
|
mojom::DidCommitProvisionalLoadInterfaceParamsPtr* interface_params)
|
|
override;
|
|
|
|
std::unique_ptr<base::RunLoop> run_loop_;
|
|
|
|
const GURL deferred_url_;
|
|
DidCommitCallback deferred_action_;
|
|
|
|
DISALLOW_COPY_AND_ASSIGN(CommitMessageDelayer);
|
|
};
|
|
|
|
} // namespace content
|
|
|
|
#endif // CONTENT_TEST_DID_COMMIT_NAVIGATION_INTERCEPTOR_H_
|