1 /* 2 * Copyright (C) 2007, 2008 Apple Inc. All rights reserved. 3 * 4 * Redistribution and use in source and binary forms, with or without 5 * modification, are permitted provided that the following conditions 6 * are met: 7 * 8 * 1. Redistributions of source code must retain the above copyright 9 * notice, this list of conditions and the following disclaimer. 10 * 2. Redistributions in binary form must reproduce the above copyright 11 * notice, this list of conditions and the following disclaimer in the 12 * documentation and/or other materials provided with the distribution. 13 * 3. Neither the name of Apple Computer, Inc. ("Apple") nor the names of 14 * its contributors may be used to endorse or promote products derived 15 * from this software without specific prior written permission. 16 * 17 * THIS SOFTWARE IS PROVIDED BY APPLE AND ITS CONTRIBUTORS "AS IS" AND ANY 18 * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED 19 * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE 20 * DISCLAIMED. IN NO EVENT SHALL APPLE OR ITS CONTRIBUTORS BE LIABLE FOR ANY 21 * DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES 22 * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; 23 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND 24 * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 25 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF 26 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 27 */ 28 29 #include "config.h" 30 #include "JSHTMLFrameElement.h" 31 32 #include "Document.h" 33 #include "HTMLFrameElement.h" 34 #include "HTMLNames.h" 35 #include "HTMLParserIdioms.h" 36 #include "JSDOMBinding.h" 37 38 using namespace JSC; 39 40 namespace WebCore { 41 42 using namespace HTMLNames; 43 44 static inline bool allowSettingJavascriptURL(ExecState* exec, HTMLFrameElement* imp, const String& value) 45 { 46 if (protocolIsJavaScript(stripLeadingAndTrailingHTMLSpaces(value))) { 47 Document* contentDocument = imp->contentDocument(); 48 if (contentDocument && !checkNodeSecurity(exec, contentDocument)) 49 return false; 50 } 51 return true; 52 } 53 54 void JSHTMLFrameElement::setLocation(ExecState* exec, JSValue value) 55 { 56 HTMLFrameElement* imp = static_cast<HTMLFrameElement*>(impl()); 57 String locationValue = valueToStringWithNullCheck(exec, value); 58 59 if (!allowSettingJavascriptURL(exec, imp, locationValue)) 60 return; 61 62 imp->setLocation(locationValue); 63 } 64 65 } // namespace WebCore 66