Add Document-Isolation-Policy infrastructure
https://bugs.webkit.org/show_bug.cgi?id=326321 rdar://189165672 Reviewed by Alex Christensen. As a first step, parse the header and apply the subresource checks of isolate-and-require-corp, behind the testable DocumentIsolationPolicyEnabled preference. It is only honored when site isolation is enabled, as Document-Isolation-Policy relies on it to give documents with the policy their own process. The policy is only honored in secure contexts. It is stored in the policy container, so it is inherited by initial about:blank, about:srcdoc, data:, javascript: and blob: documents, and restored from history. isolate-and-require-corp requires cross-origin no-cors responses to have a Cross-Origin-Resource-Policy header, just like COEP require-corp. It is enforced for network loads, memory cache hits, responses from service workers, and the Cache API. Navigations are not affected, so a document with this policy can still embed cross-origin iframes without CORP. Dedicated workers load through their owner document and therefore get its policy. Shared and service workers do not get a policy. isolate-and-credentialless, Document-Isolation-Policy-Report-Only, and violation reports are not supported yet. Neither is the agent cluster keying and cross-origin isolation that the policy also enables. Canonical link: https://commits.webkit.org/322736@main
A
Anne van Kesteren committed
6164d9c66ecdd2da2fc3e3d65a657f58be5ddcd1
Parent: c456b28