fix: meta referrer updating to follow spec (#36390)

Previously the referrer policy used tree order but the spec only cares
about the most-recently-updated or most-recently-added meta referrer.

Testing: change has existing WPT tests

---------

Signed-off-by: Sebastian C <sebsebmc@gmail.com>
This commit is contained in:
Sebastian C 2025-04-07 17:29:12 -05:00 committed by GitHub
parent bfbe464eba
commit 9bdc46d66b
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
5 changed files with 28 additions and 46 deletions

View file

@ -10,7 +10,7 @@ use js::rust::HandleObject;
use crate::dom::bindings::codegen::Bindings::DocumentBinding::DocumentMethods; use crate::dom::bindings::codegen::Bindings::DocumentBinding::DocumentMethods;
use crate::dom::bindings::inheritance::Castable; use crate::dom::bindings::inheritance::Castable;
use crate::dom::bindings::root::DomRoot; use crate::dom::bindings::root::DomRoot;
use crate::dom::document::{Document, determine_policy_for_token}; use crate::dom::document::Document;
use crate::dom::element::Element; use crate::dom::element::Element;
use crate::dom::htmlelement::HTMLElement; use crate::dom::htmlelement::HTMLElement;
use crate::dom::htmlmetaelement::HTMLMetaElement; use crate::dom::htmlmetaelement::HTMLMetaElement;
@ -54,37 +54,6 @@ impl HTMLHeadElement {
n n
} }
/// <https://html.spec.whatwg.org/multipage/#meta-referrer>
pub(crate) fn set_document_referrer(&self) {
let doc = self.owner_document();
if doc.GetHead().as_deref() != Some(self) {
return;
}
let node = self.upcast::<Node>();
let candidates = node
.traverse_preorder(ShadowIncluding::No)
.filter_map(DomRoot::downcast::<Element>)
.filter(|elem| elem.is::<HTMLMetaElement>())
.filter(|elem| elem.get_name() == Some(atom!("referrer")))
.filter(|elem| {
elem.get_attribute(&ns!(), &local_name!("content"))
.is_some()
});
for meta in candidates {
if let Some(ref content) = meta.get_attribute(&ns!(), &local_name!("content")) {
let content = content.value();
let content_val = content.trim();
if !content_val.is_empty() {
doc.set_referrer_policy(determine_policy_for_token(content_val));
return;
}
}
}
}
/// <https://html.spec.whatwg.org/multipage/#attr-meta-http-equiv-content-security-policy> /// <https://html.spec.whatwg.org/multipage/#attr-meta-http-equiv-content-security-policy>
pub(crate) fn set_content_security_policy(&self) { pub(crate) fn set_content_security_policy(&self) {
let doc = self.owner_document(); let doc = self.owner_document();

View file

@ -8,7 +8,7 @@ use std::time::Duration;
use constellation_traits::NavigationHistoryBehavior; use constellation_traits::NavigationHistoryBehavior;
use dom_struct::dom_struct; use dom_struct::dom_struct;
use html5ever::{LocalName, Prefix}; use html5ever::{LocalName, Prefix, local_name, namespace_url, ns};
use js::rust::HandleObject; use js::rust::HandleObject;
use regex::bytes::Regex; use regex::bytes::Regex;
use servo_url::ServoUrl; use servo_url::ServoUrl;
@ -21,7 +21,7 @@ use crate::dom::bindings::codegen::Bindings::WindowBinding::WindowMethods;
use crate::dom::bindings::inheritance::Castable; use crate::dom::bindings::inheritance::Castable;
use crate::dom::bindings::root::DomRoot; use crate::dom::bindings::root::DomRoot;
use crate::dom::bindings::str::DOMString; use crate::dom::bindings::str::DOMString;
use crate::dom::document::{DeclarativeRefresh, Document}; use crate::dom::document::{DeclarativeRefresh, Document, determine_policy_for_token};
use crate::dom::element::{AttributeMutation, Element}; use crate::dom::element::{AttributeMutation, Element};
use crate::dom::htmlelement::HTMLElement; use crate::dom::htmlelement::HTMLElement;
use crate::dom::htmlheadelement::HTMLHeadElement; use crate::dom::htmlheadelement::HTMLHeadElement;
@ -115,9 +115,31 @@ impl HTMLMetaElement {
/// <https://html.spec.whatwg.org/multipage/#meta-referrer> /// <https://html.spec.whatwg.org/multipage/#meta-referrer>
fn apply_referrer(&self) { fn apply_referrer(&self) {
if let Some(parent) = self.upcast::<Node>().GetParentElement() { let doc = self.owner_document();
if let Some(head) = parent.downcast::<HTMLHeadElement>() { // From spec: For historical reasons, unlike other standard metadata names, the processing model for referrer
head.set_document_referrer(); // is not responsive to element removals, and does not use tree order. Only the most-recently-inserted or
// most-recently-modified meta element in this state has an effect.
// 1. If element is not in a document tree, then return.
let meta_node = self.upcast::<Node>();
if !meta_node.is_in_a_document_tree() {
return;
}
// 2. If element does not have a name attribute whose value is an ASCII case-insensitive match for "referrer",
// then return.
if self.upcast::<Element>().get_name() != Some(atom!("referrer")) {
return;
}
// 3. If element does not have a content attribute, or that attribute's value is the empty string, then return.
let content = self
.upcast::<Element>()
.get_attribute(&ns!(), &local_name!("content"));
if let Some(attr) = content {
let attr = attr.value();
let attr_val = attr.trim();
if !attr_val.is_empty() {
doc.set_referrer_policy(determine_policy_for_token(attr_val));
} }
} }
} }

View file

@ -1,3 +0,0 @@
[first-meta-changed-after-second-added.http.html]
[document referrer policy is the value of the most recently modified <meta name="referrer"]
expected: FAIL

View file

@ -1,3 +0,0 @@
[meta-referrer-outofhead-fetch.http.html]
[Referer header was not send]
expected: FAIL

View file

@ -1,3 +0,0 @@
[meta-referrer-removed-2.http.html]
[referrer policy does not change when second <meta name="referrer"> is removed]
expected: FAIL