1/* 2 * Copyright (C) 2010 Google Inc. All rights reserved. 3 * 4 * Redistribution and use in source and binary forms, with or without 5 * modification, are permitted provided that the following conditions are 6 * met: 7 * 8 * * Redistributions of source code must retain the above copyright 9 * notice, this list of conditions and the following disclaimer. 10 * * Redistributions in binary form must reproduce the above 11 * copyright notice, this list of conditions and the following disclaimer 12 * in the documentation and/or other materials provided with the 13 * distribution. 14 * * Neither the name of Google Inc. nor the names of its 15 * contributors may be used to endorse or promote products derived from 16 * this software without specific prior written permission. 17 * 18 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS 19 * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT 20 * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR 21 * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT 22 * OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, 23 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT 24 * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, 25 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY 26 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 27 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE 28 * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 29 */ 30 31#include "config.h" 32 33#include "AbstractWorker.h" 34 35#include "ContentSecurityPolicy.h" 36#include "ErrorEvent.h" 37#include "Event.h" 38#include "EventException.h" 39#include "EventNames.h" 40#include "ExceptionCode.h" 41#include "InspectorInstrumentation.h" 42#include "ScriptExecutionContext.h" 43#include "SecurityOrigin.h" 44 45namespace WebCore { 46 47AbstractWorker::AbstractWorker(ScriptExecutionContext& context) 48 : ActiveDOMObject(&context) 49{ 50} 51 52AbstractWorker::~AbstractWorker() 53{ 54} 55 56URL AbstractWorker::resolveURL(const String& url, ExceptionCode& ec) 57{ 58 if (url.isEmpty()) { 59 ec = SYNTAX_ERR; 60 return URL(); 61 } 62 63 // FIXME: This should use the dynamic global scope (bug #27887) 64 URL scriptURL = scriptExecutionContext()->completeURL(url); 65 if (!scriptURL.isValid()) { 66 ec = SYNTAX_ERR; 67 return URL(); 68 } 69 70 if (!scriptExecutionContext()->securityOrigin()->canRequest(scriptURL)) { 71 ec = SECURITY_ERR; 72 return URL(); 73 } 74 75 if (scriptExecutionContext()->contentSecurityPolicy() && !scriptExecutionContext()->contentSecurityPolicy()->allowScriptFromSource(scriptURL)) { 76 ec = SECURITY_ERR; 77 return URL(); 78 } 79 80 return scriptURL; 81} 82 83} // namespace WebCore 84