1
Fork 0
mirror of https://github.com/RGBCube/serenity synced 2025-05-31 09:38:11 +00:00

LibWeb: Protect ourselves during ResourceClient iteration

Notifying a Resource's clients may lead to arbitrary JS execution,
so we can't rely on the ResourceClient pointers remaining valid.
Use WeakPtr to avoid this problem.
This commit is contained in:
Andreas Kling 2020-06-01 22:09:38 +02:00
parent e5ddb76a67
commit 9170edf541
2 changed files with 17 additions and 12 deletions

View file

@ -24,6 +24,7 @@
* OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
*/
#include <AK/Function.h>
#include <LibWeb/DOM/HTMLImageElement.h>
#include <LibWeb/Loader/Resource.h>
@ -43,6 +44,18 @@ Resource::~Resource()
{
}
void Resource::for_each_client(Function<void(ResourceClient&)> callback)
{
Vector<WeakPtr<ResourceClient>, 16> clients_copy;
clients_copy.ensure_capacity(m_clients.size());
for (auto* client : m_clients)
clients_copy.append(client->make_weak_ptr());
for (auto client : clients_copy) {
if (client)
callback(*client);
}
}
void Resource::did_load(Badge<ResourceLoader>, const ByteBuffer& data, const HashMap<String, String, CaseInsensitiveStringTraits>& headers)
{
ASSERT(!m_loaded);