[Trusted Types] Implement script src attribute without StringContext. The [StringContext=] extendend IDL attribute is a Chrome-specific mechanism to implement Trusted Types. TT is currently being integrated into the HTML spec, and the spec editors decided against the StringContext IDL attribute, and instead specify Trusted Types checks "manually" in the spec. In some instances -- but not here -- the difference between the IDL-based and the "manual" TT checks is observable, due to the when the TT check is being made. This CL re-implements the Trusted Types check of the following properties, without StringContext: - HTMLScriptElement, src + text - HTMLObjectElement, data + codeBase - HTMLEmbedElement, src This CL should not introduce any behavioural changes. If the updated HTML specs introduces changes relative to Chrome's current behaviour, we will implement those semantic changes in a separate CL, behind a flag. Here, we only change the mechanism. Bug: 330516530 Change-Id: I270b035e69b46b02ea1a73b0b1b8407d50c60408 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/6593311 Commit-Queue: Daniel Vogelheim <vogelheim@chromium.org> Reviewed-by: Joey Arhar <jarhar@chromium.org> Cr-Commit-Position: refs/heads/main@{#1481044}
Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.
The project's web site is https://www.chromium.org.
To check out the source code locally, don't use git clone! Instead, follow the instructions on how to get the code.
Documentation in the source is rooted in docs/README.md.
Learn how to Get Around the Chromium Source Code Directory Structure.
For historical reasons, there are some small top level directories. Now the guidance is that new top level directories are for product (e.g. Chrome, Android WebView, Ash). Even if these products have multiple executables, the code should be in subdirectories of the product.
If you found a bug, please file it at https://crbug.com/new.