diff options
author | Jüri Valdmann <juri.valdmann@qt.io> | 2018-07-19 10:54:33 +0200 |
---|---|---|
committer | Jüri Valdmann <juri.valdmann@qt.io> | 2018-07-20 09:39:51 +0000 |
commit | 8f914155c4d32fd8befa01c6cc09957d082ca7fe (patch) | |
tree | 15b9d5cb0ba53e9ecceefd73c5dc7833b62167e0 /src/webenginewidgets/api/qwebenginepage.cpp | |
parent | 2d3afea3c0a1d56b62fbd28d0a49a64c06857eb1 (diff) | |
download | qtwebengine-8f914155c4d32fd8befa01c6cc09957d082ca7fe.tar.gz |
QWebEngineUrlRequestJob: QUrl("null") for unique initiator origins
The empty URL is used both for representing a missing origin (browser-initiated
navigation request) and a unique/opaque origin. This is problematic since the
security implications are very different in these two cases: browser-initiated
requests usually should have high security clearance, while requests from unique
origins should be restricted.
Task-number: QTBUG-69372
Change-Id: Iff73fd1c9a29f1c5c281a8945536333081ff2d6b
Reviewed-by: Allan Sandfeld Jensen <allan.jensen@qt.io>
Diffstat (limited to 'src/webenginewidgets/api/qwebenginepage.cpp')
0 files changed, 0 insertions, 0 deletions