diff options
author | Timothy Flynn <trflynn89@pm.me> | 2021-04-13 17:30:41 -0400 |
---|---|---|
committer | Andreas Kling <kling@serenityos.org> | 2021-04-14 16:07:46 +0200 |
commit | c00760c5f9ca72b89b39feb7042978da2f15eef3 (patch) | |
tree | fcec9f5b592b3472593c4f136c90e2f5595eac67 /Userland/Libraries/LibWeb/Loader | |
parent | 7193e518d1190e54ba3a94cc42c4905a7be786a1 (diff) | |
download | serenity-c00760c5f9ca72b89b39feb7042978da2f15eef3.zip |
Browser+LibWeb+WebContent: Track the source of document.cookie requests
To implement the HttpOnly attribute, the CookieJar needs to know where a
request originated from. Namely, it needs to distinguish between HTTP /
non-HTTP (i.e. JavaScript) requests. When the HttpOnly attribute is set,
requests from JavaScript are to be blocked.
Diffstat (limited to 'Userland/Libraries/LibWeb/Loader')
-rw-r--r-- | Userland/Libraries/LibWeb/Loader/FrameLoader.cpp | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/Userland/Libraries/LibWeb/Loader/FrameLoader.cpp b/Userland/Libraries/LibWeb/Loader/FrameLoader.cpp index 19f1f0b369..496cb38d8d 100644 --- a/Userland/Libraries/LibWeb/Loader/FrameLoader.cpp +++ b/Userland/Libraries/LibWeb/Loader/FrameLoader.cpp @@ -277,7 +277,7 @@ void FrameLoader::resource_did_load() // FIXME: Support multiple instances of the Set-Cookie response header. auto set_cookie = resource()->response_headers().get("Set-Cookie"); if (set_cookie.has_value()) - document->set_cookie(set_cookie.value()); + document->set_cookie(set_cookie.value(), Cookie::Source::Http); if (!url.fragment().is_empty()) frame().scroll_to_anchor(url.fragment()); |