fix(webidl): enforce cross-realm DOM receiver brands

This commit is contained in:
ldm0
2026-10-02 03:27:49 +08:00
parent 17bcc5e39e
commit ffbd682cac
2 changed files with 25 additions and 2 deletions
@@ -1,6 +1,10 @@
use super::super::super::{
document,
node::{node_runtime_and_handle_from_args, node_runtime_and_handle_from_args_or_detached},
node::{
node_runtime_and_handle_from_args, node_runtime_and_handle_from_args_or_detached,
receiver_has_detached_state, require_element_method_receiver,
throw_incompatible_method_receiver,
},
throw_dom_exception,
};
use super::super::is_disabled_form_control;
@@ -14,9 +18,16 @@ pub(in crate::native_bridge) fn node_click_callback<'s>(
mut rv: v8::ReturnValue<'_, v8::Value>,
) {
let Ok((runtime_ptr, handle)) = node_runtime_and_handle_from_args(scope, &args) else {
document::detached_click_method_callback(scope, args, rv);
if receiver_has_detached_state(scope, args.this()) {
document::detached_click_method_callback(scope, args, rv);
return;
}
throw_incompatible_method_receiver(scope, "HTMLElement", "click");
return;
};
if !require_element_method_receiver(scope, unsafe { &*runtime_ptr }, handle, "click") {
return;
}
let outcome = activate_handle_via_synthetic_click(scope, runtime_ptr, handle, 0.0, 0.0, 0, 0);
if let Some(download) = outcome.pending_download {
unsafe { &mut *runtime_ptr }.record_pending_download_activation(download);
+12
View File
@@ -150,6 +150,10 @@ pub(super) fn event_target_add_event_listener_callback<'s>(
args: v8::FunctionCallbackArguments<'s>,
rv: v8::ReturnValue<'s, v8::Value>,
) {
if args.this().is_proxy() {
throw_type_error(scope, "Illegal invocation");
return;
}
if simple_event_target_slot_name(scope, args.this()).is_some() {
simple_event_target_add_event_listener_callback(scope, args, rv);
return;
@@ -272,6 +276,10 @@ pub(super) fn event_target_remove_event_listener_callback<'s>(
args: v8::FunctionCallbackArguments<'s>,
rv: v8::ReturnValue<'s, v8::Value>,
) {
if args.this().is_proxy() {
throw_type_error(scope, "Illegal invocation");
return;
}
if simple_event_target_slot_name(scope, args.this()).is_some() {
simple_event_target_remove_event_listener_callback(scope, args, rv);
return;
@@ -312,6 +320,10 @@ pub(super) fn event_target_dispatch_event_callback<'s>(
args: v8::FunctionCallbackArguments<'s>,
mut rv: v8::ReturnValue<'s, v8::Value>,
) {
if args.this().is_proxy() {
throw_type_error(scope, "Illegal invocation");
return;
}
if simple_event_target_slot_name(scope, args.this()).is_some() {
simple_event_target_dispatch_event_callback(scope, args, rv);
return;