webui: make `default-src 'self';` the default CSP for chrome-untrusted:// URLDataSource
This CL makes `default-src 'self';` the default Content Security Policy for chrome-untrusted:// URLDataSource. This stops chrome-untrusted:// from using resources from a different origin, unless CSP explicitly allows them. To prevent breakage of existing chrome-untrusted:// WebUIs, we override their default-src to an empty value, and create bug tracker issues for relevant teams to update their CSP. This is a preparation for enabling Fetch API for chrome-untrusted:// scheme. Bug: 1023741 Change-Id: I2e5cfe3877c1e996a678e04aacd378f044332bb5 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/2208588 Commit-Queue: Jiewei Qian <qjw@chromium.org> Reviewed-by:Oleh Lamzin <lamzin@google.com> Reviewed-by:
Tibor Goldschwendt <tiborg@chromium.org> Reviewed-by:
dpapad <dpapad@chromium.org> Reviewed-by:
Rachel Carpenter <carpenterr@chromium.org> Reviewed-by:
Nasko Oskov <nasko@chromium.org> Reviewed-by:
Giovanni Ortuño Urquidi <ortuno@chromium.org> Cr-Commit-Position: refs/heads/master@{#772076}
Showing
Please register or sign in to comment