File: async-html-script-removal.https.html

package info (click to toggle)
firefox 144.0-1
  • links: PTS, VCS
  • area: main
  • in suites: sid
  • size: 4,637,504 kB
  • sloc: cpp: 7,576,692; javascript: 6,430,831; ansic: 3,748,119; python: 1,398,978; xml: 628,810; asm: 438,679; java: 186,194; sh: 63,212; makefile: 19,159; objc: 13,086; perl: 12,986; yacc: 4,583; cs: 3,846; pascal: 3,448; lex: 1,720; ruby: 1,003; exp: 762; php: 436; lisp: 258; awk: 247; sql: 66; sed: 53; csh: 10
file content (60 lines) | stat: -rw-r--r-- 2,562 bytes parent folder | download | duplicates (12)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
<!doctype html>
<meta charset="utf-8">
<title>
  Async Clipboard write ([text/html ClipboardItem]) -> readHtml (and remove scripts) tests
</title>
<link rel="help" href="https://w3c.github.io/clipboard-apis/#async-clipboard-api">
<body>Body needed for test_driver.click()</body>
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<script src="/resources/testdriver.js"></script>
<script src="/resources/testdriver-vendor.js"></script>
<script src="resources/user-activation.js"></script>
<script>
'use strict';
// This function removes extra spaces between tags in html. For example, the
// following html: "<p> Hello </p>   <body> World </body>" would turn into this
//           html: "<p> Hello </p> <body> World </body>"
// We remove the extra spaces because in html they are considered equivalent,
// but when we are comparing for equality the spaces make a difference.
function reformatHtml(html) {
  const parser = new DOMParser();
  const htmlString =
    parser.parseFromString(html, 'text/html').documentElement.innerHTML;
  const reformattedString = htmlString.replace(/\>\s*\</g, '> <');
  return reformattedString;
}

// The string must be concatenated in this way because the html parser
// will recognize a script tag even in quotes as a real script tag. By
// splitting it up in this way we avoid that error.
const html_with_script =
  '<title>Title of the document</title> <script>const a = 5;</scr'
  + 'ipt> <p>Hello World</p>';
const html_script =
  '<script>const a = 5;</scr'
  + 'ipt>';
promise_test(async t => {
  await tryGrantReadPermission();
  await tryGrantWritePermission();
  const blobInput = new Blob([html_with_script], {type: 'text/html'});
  const clipboardItem = new ClipboardItem({'text/html': blobInput});
  await waitForUserActivation();
  await navigator.clipboard.write([clipboardItem]);
  await waitForUserActivation();
  const clipboardItems = await navigator.clipboard.read();

  const html = clipboardItems[0];
  assert_equals(html.types.length, 1);
  assert_equals(html.types[0], 'text/html');

  const blobOutput = await html.getType('text/html');
  assert_equals(blobOutput.type, 'text/html');

  const blobText = await (new Response(blobOutput)).text();

  const outputHtml = reformatHtml(blobText);
  const html_script_no_spaces = reformatHtml(html_script);
  assert_true(!outputHtml.includes(html_script_no_spaces));
}, 'Verify write and read clipboard with scripts removed given text/html. The string "' + html_script + '" has been removed.');
</script>