Description
The empty URL is used both for representing a missing origin (browser-initiated navigation request) and a unique/opaque origin. This is problematic since the security implications are very different in these two cases: browser-initiated requests usually should have high security clearance, while requests from unique origins should be restricted.
Attachments
For Gerrit Dashboard: QTBUG-69372 | ||||||
---|---|---|---|---|---|---|
# | Subject | Branch | Project | Status | CR | V |
234849,5 | QWebEngineUrlRequestJob: QUrl("null") for unique initiator origins | 5.11 | qt/qtwebengine | Status: MERGED | +2 | 0 |