LEFT | RIGHT |
1 /* | 1 /* |
2 * This file is part of Adblock Plus <https://adblockplus.org/>, | 2 * This file is part of Adblock Plus <https://adblockplus.org/>, |
3 * Copyright (C) 2006-present eyeo GmbH | 3 * Copyright (C) 2006-present eyeo GmbH |
4 * | 4 * |
5 * Adblock Plus is free software: you can redistribute it and/or modify | 5 * Adblock Plus is free software: you can redistribute it and/or modify |
6 * it under the terms of the GNU General Public License version 3 as | 6 * it under the terms of the GNU General Public License version 3 as |
7 * published by the Free Software Foundation. | 7 * published by the Free Software Foundation. |
8 * | 8 * |
9 * Adblock Plus is distributed in the hope that it will be useful, | 9 * Adblock Plus is distributed in the hope that it will be useful, |
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of | 10 * but WITHOUT ANY WARRANTY; without even the implied warranty of |
(...skipping 380 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
391 if (document instanceof HTMLDocument) | 391 if (document instanceof HTMLDocument) |
392 { | 392 { |
393 let sandbox = window.frameElement && | 393 let sandbox = window.frameElement && |
394 window.frameElement.getAttribute("sandbox"); | 394 window.frameElement.getAttribute("sandbox"); |
395 | 395 |
396 if (typeof sandbox != "string" || /(^|\s)allow-scripts(\s|$)/i.test(sandbox)) | 396 if (typeof sandbox != "string" || /(^|\s)allow-scripts(\s|$)/i.test(sandbox)) |
397 { | 397 { |
398 let script = document.createElement("script"); | 398 let script = document.createElement("script"); |
399 script.type = "application/javascript"; | 399 script.type = "application/javascript"; |
400 script.async = false; | 400 script.async = false; |
401 let code = "(" + injected + ")('" + randomEventName + "');"; | 401 // Firefox 58 only bypasses site CSPs when assigning to 'src'. |
402 let blob = new Blob([code], { type: "text/javascript" }); | 402 let url = URL.createObjectURL(new Blob([ |
403 let url = URL.createObjectURL(blob); | 403 "(" + injected + ")('" + randomEventName + "');" |
| 404 ])); |
404 script.src = url; | 405 script.src = url; |
405 document.documentElement.appendChild(script); | 406 document.documentElement.appendChild(script); |
406 document.documentElement.removeChild(script); | 407 document.documentElement.removeChild(script); |
407 URL.revokeObjectURL(url); | 408 URL.revokeObjectURL(url); |
408 } | 409 } |
409 } | 410 } |
LEFT | RIGHT |