angler-fishThe Vulnerability History Project

Check CSP before registering ServiceWorkers

      Service Worker registrations should be subject to the same CSP checks as
other workers. The spec doesn't say this explicitly
(https://www.w3.org/TR/CSP2/#directive-child-src-workers says &quotWorker or
SharedWorker constructors&quot), but it seems to be in the spirit of things,
and it matches Firefox's behavior.

BUG=579801

Review URL: https://codereview.chromium.org/1861253004

Cr-Commit-Position: refs/heads/master@{#385775}
    
commit 5289a5d4c98681e9a0f2d28da0c7aa35e282db57
-1
-14
-6
-15
-9
expand_less