SIGN IN SIGN UP

Add Document-Isolation-Policy infrastructure

https://bugs.webkit.org/show_bug.cgi?id=326321
rdar://189165672

Reviewed by Alex Christensen.

As a first step, parse the header and apply the subresource checks of
isolate-and-require-corp, behind the testable DocumentIsolationPolicyEnabled
preference. It is only honored when site isolation is enabled, as
Document-Isolation-Policy relies on it to give documents with the policy
their own process.

The policy is only honored in secure contexts. It is stored in the policy
container, so it is inherited by initial about:blank, about:srcdoc, data:,
javascript: and blob: documents, and restored from history.

isolate-and-require-corp requires cross-origin no-cors responses to have a
Cross-Origin-Resource-Policy header, just like COEP require-corp. It is
enforced for network loads, memory cache hits, responses from service
workers, and the Cache API. Navigations are not affected, so a document with
this policy can still embed cross-origin iframes without CORP.

Dedicated workers load through their owner document and therefore get its
policy. Shared and service workers do not get a policy.

isolate-and-credentialless, Document-Isolation-Policy-Report-Only, and
violation reports are not supported yet. Neither is the agent cluster
keying and cross-origin isolation that the policy also enables.

Canonical link: https://commits.webkit.org/322736@main
A
Anne van Kesteren committed
6164d9c66ecdd2da2fc3e3d65a657f58be5ddcd1
Parent: c456b28