Skip to content

Add current_url to request - #67

Merged
notriddle merged 1 commit into
rust-ammonia:masterfrom
TimvdLippe:add-request-current-url
Mar 22, 2026
Merged

Add current_url to request#67
notriddle merged 1 commit into
rust-ammonia:masterfrom
TimvdLippe:add-request-current-url

Conversation

@TimvdLippe

Copy link
Copy Markdown
Contributor

The specification uses two different URLs: the url and the current URL. The distinction is relevant when redirecting 1. When we report a violation, we should use the original URL that started the request. However, all checks on URLs then need to use the current URLs. This ensures that after a redirect, the new URL is then checked against the CSP policy.

This is extensively tested by WPT, see the results in the corresponding Servo PR 2.

@TimvdLippe

Copy link
Copy Markdown
Contributor Author

Marking as draft so that I can test with WPT on Servo and ensure we cover all cases correctly now.

The specification uses two different URLs: the url and the current URL.
The distinction is relevant when redirecting [1]. When we report a
violation, we should use the original URL that started the request.
However, all checks on URLs then need to use the current URLs. This
ensures that after a redirect, the new URL is then checked against
the CSP policy.

This is extensively tested by WPT, see the results in the corresponding
Servo PR [2].

[1]: https://w3c.github.io/webappsec-csp/#create-violation-for-request
[2]: servo/servo#43438
@TimvdLippe
TimvdLippe force-pushed the add-request-current-url branch from 6ae77c9 to d469f3b Compare March 18, 2026 21:59
@TimvdLippe
TimvdLippe marked this pull request as ready for review March 19, 2026 06:26
@TimvdLippe

Copy link
Copy Markdown
Contributor Author

Test results look good. After merging, can you publish 0.7.0 for this? Thanks!

@notriddle
notriddle merged commit 9f392e2 into rust-ammonia:master Mar 22, 2026
8 checks passed
@notriddle

Copy link
Copy Markdown
Member

Okay, the release is pushed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants