Add a security note for GetURLLoaderFactoryForBrowserProcess method.
The new security note explains security-related caveats related to using the GetURLLoaderFactoryForBrowserProcess method. The note suggests using RenderFrameHost::CreateNetworkServiceDefaultFactory instead (the latter factory should enforce setting a non-base::nullopt network::ResourceRequest::request_initiator - see the InitiatorLockCompatibility::kNoInitiator case in CorsURLLoaderFactory::IsValidRequest). Bug: 1128008 Change-Id: I3d30736f5804b97a45e246106463ee6a40e747a2 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/2410820 Auto-Submit: Łukasz Anforowicz <lukasza@chromium.org> Reviewed-by:Nasko Oskov <nasko@chromium.org> Reviewed-by:
Matt Menke <mmenke@chromium.org> Commit-Queue: Matt Menke <mmenke@chromium.org> Cr-Commit-Position: refs/heads/master@{#807781}
Showing
Please register or sign in to comment