Files
Simon Farre 90fdec60cd Bug 2034329 - Anchor DOMStringList to a specified realm. r=smaug,dom-core
DOMStringList::GetParentObject() returned nullptr, so FindAssociatedGlobal in
BindingUtils.h:1845 fell back to JS::CurrentGlobalOrNull(cx), stamping the JS
wrapper into the first caller's compartment. If an extension content script got
there first, subsequent page access required a content→extension CCW, which
security policy blocks, breaking sites like Gmail.

Fix by passing the Document (or inner window) as the DOMStringList parent, so
FindAssociatedGlobal always anchors the wrapper to the content realm — the same
mechanism that makes things like nsContentList immune to this problem.

Differential Revision: https://phabricator.services.mozilla.com/D296198
2026-04-27 08:23:58 +00:00

29 lines
921 B
C++

/* This Source Code Form is subject to the terms of the Mozilla Public
* License, v. 2.0. If a copy of the MPL was not distributed with this
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */
#include "mozilla/dom/DOMStringList.h"
#include "mozilla/dom/DOMStringListBinding.h"
#include "nsContentUtils.h"
namespace mozilla::dom {
NS_IMPL_CYCLE_COLLECTION_WRAPPERCACHE(DOMStringList, mParent)
NS_IMPL_CYCLE_COLLECTING_ADDREF(DOMStringList)
NS_IMPL_CYCLE_COLLECTING_RELEASE(DOMStringList)
NS_INTERFACE_MAP_BEGIN_CYCLE_COLLECTION(DOMStringList)
NS_WRAPPERCACHE_INTERFACE_MAP_ENTRY
NS_INTERFACE_MAP_ENTRY(nsISupports)
NS_INTERFACE_MAP_END
DOMStringList::~DOMStringList() = default;
JSObject* DOMStringList::WrapObject(JSContext* aCx,
JS::Handle<JSObject*> aGivenProto) {
return DOMStringList_Binding::Wrap(aCx, this, aGivenProto);
}
} // namespace mozilla::dom