C.J. Winslow
58f7b7638a
Security: add per-wrapper IDs to untrusted-content markers ( #19009 )
...
Fixes #10927
Adds unique per-wrapper IDs to external-content boundary markers to
prevent spoofing attacks where malicious content could inject fake
marker boundaries.
- Generate random 16-char hex ID per wrap operation
- Start/end markers share the same ID for pairing
- Sanitizer strips markers with or without IDs (handles legacy + spoofed)
- Added test for attacker-injected markers with fake IDs
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-02-21 01:16:02 -05:00
..
2026-02-19 15:28:14 +00:00
2026-02-21 01:16:02 -05:00
2026-02-21 01:13:02 -05:00
2026-02-20 16:36:25 +00:00
2026-02-19 15:51:22 +01:00
2026-02-20 22:40:30 -05:00
2026-02-20 19:59:54 -08:00
2026-02-20 20:19:29 -08:00
2026-02-20 21:19:21 -06:00
2026-02-20 22:31:58 -06:00
2026-02-20 12:51:14 -06:00
2026-02-20 23:52:43 -05:00
2026-02-21 00:48:22 -05:00
2026-02-20 20:19:29 -08:00
2026-02-19 14:26:12 +01:00
2026-02-20 18:21:13 +00:00
2026-02-19 15:19:38 +00:00
2026-02-19 09:59:47 +01:00
2026-02-19 16:32:33 +01:00
2026-02-19 10:00:41 +01:00
2026-02-19 03:15:36 -08:00
2026-02-20 13:32:49 -06:00
2026-02-20 23:52:43 -05:00
2026-02-20 23:52:43 -05:00
2026-02-19 14:22:01 +01:00
2026-02-19 20:33:37 -06:00
2026-02-19 15:09:19 +00:00
2026-02-19 15:19:38 +00:00
2026-02-19 15:19:38 +00:00
2026-02-19 21:54:52 -06:00
2026-02-18 04:49:22 +00:00
2026-02-21 01:16:02 -05:00
2026-02-19 21:16:26 -06:00
2026-02-20 23:52:43 -05:00
2026-02-18 23:34:15 +00:00
2026-02-19 14:44:34 -08:00
2026-02-21 09:20:20 +05:30
2026-02-18 17:48:02 +00:00
2026-02-19 15:28:14 +00:00
2026-02-20 13:32:49 -06:00
2026-02-21 01:13:02 -05:00
2026-02-19 15:19:38 +00:00
2026-02-20 21:50:50 -05:00
2026-02-18 05:31:13 +00:00
2026-02-18 01:34:35 +00:00
2026-02-19 12:42:07 -08:00
2026-02-19 10:44:46 +01:00
2026-02-16 22:35:27 -05:00
2026-02-19 08:49:52 +00:00
2026-02-18 01:34:35 +00:00
2026-02-18 23:27:50 +00:00
2026-02-17 11:22:49 +09:00
2026-02-19 14:27:36 +00:00
2026-02-18 00:02:51 -05:00
2026-02-18 00:02:51 -05:00