| Summary: | A Headers object with "request-no-cors" guard will accept non-safelisted headers with empty values | ||
|---|---|---|---|
| Product: | WebKit | Reporter: | Andreu Botella <abotella> |
| Component: | WebCore Misc. | Assignee: | Nobody <webkit-unassigned> |
| Status: | RESOLVED FIXED | ||
| Severity: | Normal | CC: | achristensen, annevk, karlcow, webkit-bug-importer, wilander, youennf |
| Priority: | P2 | Keywords: | BrowserCompat, InRadar |
| Version: | Other | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| See Also: | https://github.com/web-platform-tests/wpt/pull/38431 | ||
|
Description
Andreu Botella
2023-02-08 10:23:39 PST
Pull request: https://github.com/WebKit/WebKit/pull/9825 https://searchfox.org/wubkat/rev/8657349b48cece83215d92556db34a0a6ed55040/Source/WebCore/platform/network/HTTPParsers.cpp#841-857 and https://searchfox.org/wubkat/rev/8657349b48cece83215d92556db34a0a6ed55040/Source/WebCore/platform/network/HTTPParsers.cpp#841-857 Second link should have been https://searchfox.org/wubkat/rev/8657349b48cece83215d92556db34a0a6ed55040/Source/WebCore/Modules/fetch/FetchHeaders.cpp#157-178 Committed 260066@main (2fbadf6b9f23): <https://commits.webkit.org/260066@main> Reviewed commits have been landed. Closing PR #9825 and removing active labels. |