Files
sousa-gecko/testing/web-platform/tests/service-workers
Timothy Nikkel a2f3c0934b Bug 2052841. Don't taint a same-origin response that a service worker substitutes for a cross-origin request. r=necko-reviewers,kershaw
When a service worker answers a cross-origin request with a same-origin
resource (respondWith(fetch(<same-origin URL>))), the response is delivered as
an internal redirect from the cross-origin request URL to the same-origin
response URL. nsITimedChannel's allRedirectsSameOrigin counts that internal
redirect as a cross-origin hop, so consumers that use it to decide tainting
(image loads, stylesheets, media) treat the resource as cross-origin and taint
it -- even though the bytes are same-origin and should be readable.

Add nsITimedChannel::allRedirectsSameOriginIgnoringInternal, computed like
allRedirectsSameOrigin but ignoring internal (e.g. service-worker response-URL)
redirects, and switch the tainting consumers (imgRequestProxy, the CSS Loader,
and the media resources) to it. Real cross-origin redirects still flip it, so
genuine cross-origin loads (including bounce-backs) still taint. Other users of
allRedirectsSameOrigin (resource timing, Fetch body-access) intentionally keep
the original flag.

Add a service-worker regression test for the same-origin substitution case
(CSS).

Differential Revision: https://phabricator.services.mozilla.com/D310626
2026-07-08 12:16:06 +00:00
..
…