WebCore:
[WebKit-https.git] / WebCore / ChangeLog
index b17e13de654be138ff1465b526da6bc070b9c1b9..a9907e5098c5c53580b46d718e29d116f6bf1a13 100644 (file)
@@ -1,3 +1,15 @@
+2007-11-26  Feng Qian <ian.eng.webkit@gmail.com>
+
+        Reviewed and touched up by Sam Weinig.
+
+        Fix for http://bugs.webkit.org/show_bug.cgi?id=16073
+
+        Test: http/tests/security/xss-DENIED-invalid-domain-change.html
+
+        * dom/Document.cpp:
+        (WebCore::Document::setDomain): Don't set the securityOrigin policy unless
+        the set succeeds.  Adds some early returns as well.
+
 2007-11-26  Steve Falkenburg  <sfalken@apple.com>
 
         Build fix.