2017-06-19 07:59:44 +03:00
|
|
|
/* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */
|
|
|
|
/* vim: set ts=8 sts=2 et sw=2 tw=80: */
|
|
|
|
/* This Source Code Form is subject to the terms of the Mozilla Public
|
|
|
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
|
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */
|
|
|
|
|
|
|
|
#include "FramingChecker.h"
|
|
|
|
#include "nsCharSeparatedTokenizer.h"
|
|
|
|
#include "nsCSPUtils.h"
|
|
|
|
#include "nsDocShell.h"
|
|
|
|
#include "nsIChannel.h"
|
|
|
|
#include "nsIConsoleService.h"
|
|
|
|
#include "nsIContentSecurityPolicy.h"
|
|
|
|
#include "nsIScriptError.h"
|
|
|
|
#include "nsNetUtil.h"
|
|
|
|
#include "nsQueryObject.h"
|
|
|
|
#include "mozilla/dom/nsCSPUtils.h"
|
2019-01-11 14:43:39 +03:00
|
|
|
#include "mozilla/dom/LoadURIOptionsBinding.h"
|
2018-09-18 17:57:04 +03:00
|
|
|
#include "mozilla/NullPrincipal.h"
|
2019-07-24 15:23:32 +03:00
|
|
|
#include "nsIStringBundle.h"
|
2017-06-19 07:59:44 +03:00
|
|
|
|
|
|
|
using namespace mozilla;
|
|
|
|
|
2019-10-31 00:26:01 +03:00
|
|
|
void FramingChecker::ReportError(const char* aMessageTag,
|
|
|
|
nsIDocShellTreeItem* aParentDocShellItem,
|
|
|
|
nsIURI* aChildURI, const nsAString& aPolicy) {
|
|
|
|
MOZ_ASSERT(aParentDocShellItem, "Need a parent docshell");
|
|
|
|
if (!aChildURI || !aParentDocShellItem) {
|
2019-07-24 15:23:32 +03:00
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
2019-10-31 00:26:01 +03:00
|
|
|
Document* parentDocument = aParentDocShellItem->GetDocument();
|
|
|
|
MOZ_ASSERT(!parentDocument->NodePrincipal()->IsSystemPrincipal(),
|
|
|
|
"Should not get system principal here.");
|
|
|
|
|
2019-07-24 15:23:32 +03:00
|
|
|
// Get the parent URL spec
|
|
|
|
nsAutoCString parentSpec;
|
|
|
|
nsresult rv;
|
2019-10-31 00:26:01 +03:00
|
|
|
rv = parentDocument->NodePrincipal()->GetAsciiSpec(parentSpec);
|
2019-07-24 15:23:32 +03:00
|
|
|
if (NS_FAILED(rv)) {
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
// Get the child URL spec
|
|
|
|
nsAutoCString childSpec;
|
|
|
|
rv = aChildURI->GetAsciiSpec(childSpec);
|
|
|
|
if (NS_FAILED(rv)) {
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
nsCOMPtr<nsIStringBundleService> bundleService =
|
|
|
|
mozilla::services::GetStringBundleService();
|
|
|
|
nsCOMPtr<nsIStringBundle> bundle;
|
|
|
|
rv = bundleService->CreateBundle(
|
|
|
|
"chrome://global/locale/security/security.properties",
|
|
|
|
getter_AddRefs(bundle));
|
|
|
|
if (NS_FAILED(rv)) {
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (NS_WARN_IF(!bundle)) {
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
nsCOMPtr<nsIConsoleService> console(
|
|
|
|
do_GetService(NS_CONSOLESERVICE_CONTRACTID));
|
|
|
|
nsCOMPtr<nsIScriptError> error(do_CreateInstance(NS_SCRIPTERROR_CONTRACTID));
|
|
|
|
if (!console || !error) {
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
// Localize the error message
|
|
|
|
nsAutoString message;
|
|
|
|
AutoTArray<nsString, 3> formatStrings;
|
|
|
|
formatStrings.AppendElement(aPolicy);
|
|
|
|
CopyASCIItoUTF16(childSpec, *formatStrings.AppendElement());
|
|
|
|
CopyASCIItoUTF16(parentSpec, *formatStrings.AppendElement());
|
|
|
|
rv = bundle->FormatStringFromName(aMessageTag, formatStrings, message);
|
|
|
|
if (NS_FAILED(rv)) {
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
rv = error->InitWithWindowID(message, EmptyString(), EmptyString(), 0, 0,
|
|
|
|
nsIScriptError::errorFlag, "X-Frame-Options",
|
2019-10-31 00:26:01 +03:00
|
|
|
parentDocument->InnerWindowID());
|
2019-07-24 15:23:32 +03:00
|
|
|
if (NS_FAILED(rv)) {
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
console->LogMessage(error);
|
|
|
|
}
|
|
|
|
|
2019-02-26 01:05:29 +03:00
|
|
|
/* static */
|
2019-10-31 00:26:01 +03:00
|
|
|
bool FramingChecker::CheckOneFrameOptionsPolicy(nsIHttpChannel* aHttpChannel,
|
|
|
|
const nsAString& aPolicy,
|
|
|
|
nsIDocShell* aDocShell) {
|
|
|
|
nsresult rv;
|
|
|
|
// Find the top docshell in our parent chain that doesn't have the system
|
|
|
|
// principal and use it for the principal comparison. Finding the top
|
|
|
|
// content-type docshell doesn't work because some chrome documents are
|
|
|
|
// loaded in content docshells (see bug 593387).
|
|
|
|
nsCOMPtr<nsIDocShellTreeItem> thisDocShellItem(aDocShell);
|
|
|
|
nsCOMPtr<nsIDocShellTreeItem> parentDocShellItem;
|
|
|
|
nsCOMPtr<nsIDocShellTreeItem> curDocShellItem = thisDocShellItem;
|
|
|
|
nsCOMPtr<Document> topDoc;
|
|
|
|
nsCOMPtr<nsIScriptSecurityManager> ssm =
|
|
|
|
do_GetService(NS_SCRIPTSECURITYMANAGER_CONTRACTID, &rv);
|
|
|
|
|
|
|
|
if (!ssm) {
|
|
|
|
MOZ_CRASH();
|
2017-06-19 07:59:44 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
nsCOMPtr<nsIURI> uri;
|
|
|
|
aHttpChannel->GetURI(getter_AddRefs(uri));
|
|
|
|
|
2019-07-24 15:23:32 +03:00
|
|
|
// return early if header does not have one of the values with meaning
|
|
|
|
if (!aPolicy.LowerCaseEqualsLiteral("deny") &&
|
|
|
|
!aPolicy.LowerCaseEqualsLiteral("sameorigin")) {
|
2019-10-31 00:26:01 +03:00
|
|
|
nsCOMPtr<nsIDocShellTreeItem> root;
|
|
|
|
curDocShellItem->GetInProcessSameTypeRootTreeItem(getter_AddRefs(root));
|
|
|
|
ReportError("XFOInvalid", root, uri, aPolicy);
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
// XXXkhuey when does this happen? Is returning true safe here?
|
|
|
|
if (!aDocShell) {
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
// We need to check the location of this window and the location of the top
|
|
|
|
// window, if we're not the top. X-F-O: SAMEORIGIN requires that the
|
|
|
|
// document must be same-origin with top window. X-F-O: DENY requires that
|
|
|
|
// the document must never be framed.
|
|
|
|
nsCOMPtr<nsPIDOMWindowOuter> thisWindow = aDocShell->GetWindow();
|
|
|
|
// If we don't have DOMWindow there is no risk of clickjacking
|
|
|
|
if (!thisWindow) {
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
// GetInProcessScriptableTop, not GetTop, because we want this to respect
|
|
|
|
// <iframe mozbrowser> boundaries.
|
|
|
|
nsCOMPtr<nsPIDOMWindowOuter> topWindow =
|
|
|
|
thisWindow->GetInProcessScriptableTop();
|
|
|
|
|
|
|
|
// if the document is in the top window, it's not in a frame.
|
|
|
|
if (thisWindow == topWindow) {
|
2017-06-19 07:59:44 +03:00
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2017-11-03 18:37:10 +03:00
|
|
|
// If the X-Frame-Options value is SAMEORIGIN, then the top frame in the
|
|
|
|
// parent chain must be from the same origin as this document.
|
|
|
|
bool checkSameOrigin = aPolicy.LowerCaseEqualsLiteral("sameorigin");
|
|
|
|
nsCOMPtr<nsIURI> topUri;
|
|
|
|
|
2019-10-31 00:26:01 +03:00
|
|
|
// Traverse up the parent chain and stop when we see a docshell whose
|
|
|
|
// parent has a system principal, or a docshell corresponding to
|
|
|
|
// <iframe mozbrowser>.
|
|
|
|
while (NS_SUCCEEDED(curDocShellItem->GetInProcessParent(
|
|
|
|
getter_AddRefs(parentDocShellItem))) &&
|
|
|
|
parentDocShellItem) {
|
|
|
|
nsCOMPtr<nsIDocShell> curDocShell = do_QueryInterface(curDocShellItem);
|
|
|
|
if (curDocShell && curDocShell->GetIsMozBrowser()) {
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
topDoc = parentDocShellItem->GetDocument();
|
|
|
|
if (topDoc) {
|
|
|
|
if (topDoc->NodePrincipal()->IsSystemPrincipal()) {
|
|
|
|
// Found a system-principled doc: last docshell was top.
|
|
|
|
break;
|
2017-06-19 07:59:44 +03:00
|
|
|
}
|
2017-11-03 18:37:10 +03:00
|
|
|
|
|
|
|
if (checkSameOrigin) {
|
2019-10-31 00:26:01 +03:00
|
|
|
topDoc->NodePrincipal()->GetURI(getter_AddRefs(topUri));
|
2018-09-25 08:25:05 +03:00
|
|
|
bool isPrivateWin =
|
2019-10-31 00:26:01 +03:00
|
|
|
topDoc->NodePrincipal()->OriginAttributesRef().mPrivateBrowsingId >
|
|
|
|
0;
|
|
|
|
rv = ssm->CheckSameOriginURI(uri, topUri, true, isPrivateWin);
|
|
|
|
|
2017-11-03 18:37:10 +03:00
|
|
|
// one of the ancestors is not same origin as this document
|
|
|
|
if (NS_FAILED(rv)) {
|
2019-10-31 00:26:01 +03:00
|
|
|
ReportError("XFOSameOrigin", curDocShellItem, uri, aPolicy);
|
2017-11-03 18:37:10 +03:00
|
|
|
return false;
|
|
|
|
}
|
|
|
|
}
|
2019-10-31 00:26:01 +03:00
|
|
|
} else {
|
|
|
|
return false;
|
2017-06-19 07:59:44 +03:00
|
|
|
}
|
2019-10-31 00:26:01 +03:00
|
|
|
curDocShellItem = parentDocShellItem;
|
|
|
|
}
|
|
|
|
|
|
|
|
// If this document has the top non-SystemPrincipal docshell it is not being
|
|
|
|
// framed or it is being framed by a chrome document, which we allow.
|
|
|
|
if (curDocShellItem == thisDocShellItem) {
|
|
|
|
return true;
|
2017-06-19 07:59:44 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
// If the value of the header is DENY, and the previous condition is
|
|
|
|
// not met (current docshell is not the top docshell), prohibit the
|
|
|
|
// load.
|
|
|
|
if (aPolicy.LowerCaseEqualsLiteral("deny")) {
|
2019-10-31 00:26:01 +03:00
|
|
|
ReportError("XFODeny", curDocShellItem, uri, aPolicy);
|
2017-06-19 07:59:44 +03:00
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
// Ignore x-frame-options if CSP with frame-ancestors exists
|
|
|
|
static bool ShouldIgnoreFrameOptions(nsIChannel* aChannel,
|
2019-05-22 02:14:27 +03:00
|
|
|
nsIContentSecurityPolicy* aCSP) {
|
2017-06-19 07:59:44 +03:00
|
|
|
NS_ENSURE_TRUE(aChannel, false);
|
2019-05-22 02:14:27 +03:00
|
|
|
NS_ENSURE_TRUE(aCSP, false);
|
2017-06-19 07:59:44 +03:00
|
|
|
|
|
|
|
bool enforcesFrameAncestors = false;
|
2019-05-22 02:14:27 +03:00
|
|
|
aCSP->GetEnforcesFrameAncestors(&enforcesFrameAncestors);
|
2017-06-19 07:59:44 +03:00
|
|
|
if (!enforcesFrameAncestors) {
|
|
|
|
// if CSP does not contain frame-ancestors, then there
|
|
|
|
// is nothing to do here.
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
// log warning to console that xfo is ignored because of CSP
|
2019-02-20 15:27:25 +03:00
|
|
|
nsCOMPtr<nsILoadInfo> loadInfo = aChannel->LoadInfo();
|
|
|
|
uint64_t innerWindowID = loadInfo->GetInnerWindowID();
|
|
|
|
bool privateWindow = !!loadInfo->GetOriginAttributes().mPrivateBrowsingId;
|
2019-06-11 18:51:51 +03:00
|
|
|
AutoTArray<nsString, 2> params = {NS_LITERAL_STRING("x-frame-options"),
|
|
|
|
NS_LITERAL_STRING("frame-ancestors")};
|
2017-07-12 08:13:37 +03:00
|
|
|
CSP_LogLocalizedStr("IgnoringSrcBecauseOfDirective", params,
|
2017-06-19 07:59:44 +03:00
|
|
|
EmptyString(), // no sourcefile
|
|
|
|
EmptyString(), // no scriptsample
|
|
|
|
0, // no linenumber
|
|
|
|
0, // no columnnumber
|
|
|
|
nsIScriptError::warningFlag,
|
2018-07-20 20:57:21 +03:00
|
|
|
NS_LITERAL_CSTRING("IgnoringSrcBecauseOfDirective"),
|
2018-03-13 08:40:38 +03:00
|
|
|
innerWindowID, privateWindow);
|
2017-06-19 07:59:44 +03:00
|
|
|
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
// Check if X-Frame-Options permits this document to be loaded as a subdocument.
|
|
|
|
// This will iterate through and check any number of X-Frame-Options policies
|
|
|
|
// in the request (comma-separated in a header, multiple headers, etc).
|
2019-02-26 01:05:29 +03:00
|
|
|
/* static */
|
|
|
|
bool FramingChecker::CheckFrameOptions(nsIChannel* aChannel,
|
2019-10-31 00:26:01 +03:00
|
|
|
nsIDocShell* aDocShell,
|
2019-05-22 02:14:27 +03:00
|
|
|
nsIContentSecurityPolicy* aCsp) {
|
2019-10-31 00:26:01 +03:00
|
|
|
if (!aChannel || !aDocShell) {
|
2017-06-19 07:59:44 +03:00
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2019-05-22 02:14:27 +03:00
|
|
|
if (ShouldIgnoreFrameOptions(aChannel, aCsp)) {
|
2017-06-19 07:59:44 +03:00
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2019-10-31 00:26:01 +03:00
|
|
|
nsresult rv;
|
|
|
|
nsCOMPtr<nsIHttpChannel> httpChannel = do_QueryInterface(aChannel);
|
|
|
|
if (!httpChannel) {
|
|
|
|
// check if it is hiding in a multipart channel
|
|
|
|
rv = nsDocShell::Cast(aDocShell)->GetHttpChannel(
|
|
|
|
aChannel, getter_AddRefs(httpChannel));
|
|
|
|
if (NS_FAILED(rv)) {
|
|
|
|
return false;
|
|
|
|
}
|
2017-06-19 07:59:44 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
if (!httpChannel) {
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
nsAutoCString xfoHeaderCValue;
|
|
|
|
Unused << httpChannel->GetResponseHeader(
|
|
|
|
NS_LITERAL_CSTRING("X-Frame-Options"), xfoHeaderCValue);
|
|
|
|
NS_ConvertUTF8toUTF16 xfoHeaderValue(xfoHeaderCValue);
|
|
|
|
|
|
|
|
// if no header value, there's nothing to do.
|
|
|
|
if (xfoHeaderValue.IsEmpty()) {
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
// iterate through all the header values (usually there's only one, but can
|
|
|
|
// be many. If any want to deny the load, deny the load.
|
|
|
|
nsCharSeparatedTokenizer tokenizer(xfoHeaderValue, ',');
|
|
|
|
while (tokenizer.hasMoreTokens()) {
|
2017-06-20 12:19:52 +03:00
|
|
|
const nsAString& tok = tokenizer.nextToken();
|
2019-10-31 00:26:01 +03:00
|
|
|
if (!CheckOneFrameOptionsPolicy(httpChannel, tok, aDocShell)) {
|
|
|
|
// cancel the load and display about:blank
|
|
|
|
httpChannel->Cancel(NS_BINDING_ABORTED);
|
|
|
|
if (aDocShell) {
|
|
|
|
nsCOMPtr<nsIWebNavigation> webNav(do_QueryObject(aDocShell));
|
|
|
|
if (webNav) {
|
|
|
|
nsCOMPtr<nsILoadInfo> loadInfo = httpChannel->LoadInfo();
|
|
|
|
RefPtr<NullPrincipal> principal =
|
|
|
|
NullPrincipal::CreateWithInheritedAttributes(
|
|
|
|
loadInfo->TriggeringPrincipal());
|
|
|
|
|
|
|
|
LoadURIOptions loadURIOptions;
|
|
|
|
loadURIOptions.mTriggeringPrincipal = principal;
|
|
|
|
webNav->LoadURI(NS_LITERAL_STRING("about:blank"), loadURIOptions);
|
|
|
|
}
|
|
|
|
}
|
2017-06-19 07:59:44 +03:00
|
|
|
return false;
|
|
|
|
}
|
|
|
|
}
|
2019-10-31 00:26:01 +03:00
|
|
|
|
2017-06-19 07:59:44 +03:00
|
|
|
return true;
|
|
|
|
}
|