File: chrome_webui_navigation_browsertest.cc

package info (click to toggle)
chromium 139.0.7258.127-1
  • links: PTS, VCS
  • area: main
  • in suites:
  • size: 6,122,068 kB
  • sloc: cpp: 35,100,771; ansic: 7,163,530; javascript: 4,103,002; python: 1,436,920; asm: 946,517; xml: 746,709; pascal: 187,653; perl: 88,691; sh: 88,436; objc: 79,953; sql: 51,488; cs: 44,583; fortran: 24,137; makefile: 22,147; tcl: 15,277; php: 13,980; yacc: 8,984; ruby: 7,485; awk: 3,720; lisp: 3,096; lex: 1,327; ada: 727; jsp: 228; sed: 36
file content (105 lines) | stat: -rw-r--r-- 4,947 bytes parent folder | download | duplicates (8)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
// Copyright 2020 The Chromium Authors
// Use of this source code is governed by a BSD-style license that can be
// found in the LICENSE file.

#include "chrome/browser/profiles/profile.h"
#include "chrome/browser/ui/browser.h"
#include "chrome/browser/ui/tabs/tab_strip_model.h"
#include "chrome/test/base/in_process_browser_test.h"
#include "chrome/test/base/ui_test_utils.h"
#include "content/public/browser/webui_config_map.h"
#include "content/public/common/url_constants.h"
#include "content/public/test/browser_test.h"
#include "content/public/test/browser_test_utils.h"
#include "content/public/test/scoped_web_ui_controller_factory_registration.h"
#include "content/public/test/test_navigation_observer.h"
#include "content/public/test/web_ui_browsertest_util.h"
#include "ipc/ipc_security_test_util.h"
#include "net/dns/mock_host_resolver.h"
#include "net/test/embedded_test_server/embedded_test_server.h"
#include "ui/webui/untrusted_web_ui_browsertest_util.h"
#include "url/url_constants.h"

// Tests embedder specific behavior of WebUIs.
class ChromeWebUINavigationBrowserTest : public InProcessBrowserTest {
 protected:
  void SetUpOnMainThread() override {
    host_resolver()->AddRule("*", "127.0.0.1");
    ASSERT_TRUE(embedded_test_server()->Start());
  }

 private:
  content::TestWebUIControllerFactory factory_;
  content::ScopedWebUIControllerFactoryRegistration factory_registration_{
      &factory_};
};

// Verify that a browser check stops websites from embeding chrome:// iframes.
// This is a copy of the DisallowEmbeddingChromeSchemeFromWebFrameBrowserCheck
// test in content/browser/webui/web_ui_navigation_browsertest.cc. We need a
// copy here because the browser side check is done by embedders.
IN_PROC_BROWSER_TEST_F(ChromeWebUINavigationBrowserTest,
                       DisallowEmbeddingChromeSchemeFromWebFrameBrowserCheck) {
  GURL main_frame_url(embedded_test_server()->GetURL("/title1.html"));
  auto* web_contents = browser()->tab_strip_model()->GetActiveWebContents();
  EXPECT_TRUE(ui_test_utils::NavigateToURL(browser(), main_frame_url));
  auto* main_frame = web_contents->GetPrimaryMainFrame();

  // Add iframe but don't navigate it to a chrome:// URL yet.
  EXPECT_TRUE(content::ExecJs(main_frame,
                              "var frame = document.createElement('iframe');\n"
                              "document.body.appendChild(frame);\n",
                              content::EXECUTE_SCRIPT_DEFAULT_OPTIONS,
                              1 /* world_id */));

  content::RenderFrameHost* child = content::ChildFrameAt(main_frame, 0);
  EXPECT_EQ("about:blank", child->GetLastCommittedURL());

  content::TestNavigationObserver observer(web_contents);
  content::PwnMessageHelper::OpenURL(
      child, content::GetWebUIURL("web-ui/title1.html?noxfo=true"));
  observer.Wait();

  // Retrieve the RenderFrameHost again since it might have been swapped.
  child = content::ChildFrameAt(main_frame, 0);
  EXPECT_EQ(content::kBlockedURL, child->GetLastCommittedURL());
}

// Verify that a browser check stops websites from embeding chrome-untrusted://
// iframes. This is a copy of the
// DisallowEmbeddingChromeUntrustedSchemeFromWebFrameBrowserCheck test in
// content/browser/webui/web_ui_navigation_browsertest.cc. We need a copy here
// because the browser side check is done by embedders.
IN_PROC_BROWSER_TEST_F(
    ChromeWebUINavigationBrowserTest,
    DisallowEmbeddingChromeUntrustedSchemeFromWebFrameBrowserCheck) {
  GURL main_frame_url(embedded_test_server()->GetURL("/title1.html"));
  auto* web_contents = browser()->tab_strip_model()->GetActiveWebContents();
  EXPECT_TRUE(ui_test_utils::NavigateToURL(browser(), main_frame_url));
  auto* main_frame = web_contents->GetPrimaryMainFrame();

  // Add iframe but don't navigate it to a chrome-untrusted:// URL yet.
  EXPECT_TRUE(content::ExecJs(main_frame,
                              "var frame = document.createElement('iframe');\n"
                              "document.body.appendChild(frame);\n",
                              content::EXECUTE_SCRIPT_DEFAULT_OPTIONS,
                              1 /* world_id */));

  content::RenderFrameHost* child = content::ChildFrameAt(main_frame, 0);
  EXPECT_EQ("about:blank", child->GetLastCommittedURL());

  content::TestNavigationObserver observer(web_contents);
  content::TestUntrustedDataSourceHeaders headers;
  headers.no_xfo = true;
  content::WebUIConfigMap::GetInstance().AddUntrustedWebUIConfig(
      std::make_unique<ui::TestUntrustedWebUIConfig>("test-iframe-host",
                                                     headers));

  content::PwnMessageHelper::OpenURL(
      child, content::GetChromeUntrustedUIURL("test-iframe-host/title1.html"));
  observer.Wait();

  // Retrieve the RenderFrameHost again since it might have been swapped.
  child = content::ChildFrameAt(main_frame, 0);
  EXPECT_EQ(content::kBlockedURL, child->GetLastCommittedURL());
}