File: credentialless-script.https.tentative.window.js

package info (click to toggle)
firefox 144.0-1
  • links: PTS, VCS
  • area: main
  • in suites: sid
  • size: 4,637,504 kB
  • sloc: cpp: 7,576,692; javascript: 6,430,831; ansic: 3,748,119; python: 1,398,978; xml: 628,810; asm: 438,679; java: 186,194; sh: 63,212; makefile: 19,159; objc: 13,086; perl: 12,986; yacc: 4,583; cs: 3,846; pascal: 3,448; lex: 1,720; ruby: 1,003; exp: 762; php: 436; lisp: 258; awk: 247; sql: 66; sed: 53; csh: 10
file content (99 lines) | stat: -rw-r--r-- 3,605 bytes parent folder | download | duplicates (10)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
// META: script=/common/get-host-info.sub.js
// META: script=/common/utils.js
// META: script=/common/dispatcher/dispatcher.js
// META: script=./resources/common.js

window.onload = function() {
  promise_test_parallel(async test => {
    const same_origin = get_host_info().HTTPS_ORIGIN;
    const cross_origin = get_host_info().HTTPS_REMOTE_ORIGIN;
    const cookie_key = "dip_credentialless_script";
    const cookie_same_origin = "same_origin";
    const cookie_cross_origin = "cross_origin";

    await Promise.all([
      setCookie(same_origin, cookie_key, cookie_same_origin +
        cookie_same_site_none),
      setCookie(cross_origin, cookie_key, cookie_cross_origin +
        cookie_same_site_none),
    ]);

    // One window with DIP:none. (control)
    const w_control_token = token();
    const w_control_url = same_origin + executor_path +
      dip_none + `&uuid=${w_control_token}`
    const w_control = window.open(w_control_url);
    add_completion_callback(() => w_control.close());

    // One window with DIP:credentialless. (experiment)
    const w_credentialless_token = token();
    const w_credentialless_url = same_origin + executor_path +
      dip_credentialless + `&uuid=${w_credentialless_token}`;
    const w_credentialless = window.open(w_credentialless_url);
    add_completion_callback(() => w_credentialless.close());

    let scriptTest = function(
      description, origin, mode,
      expected_cookies_control,
      expected_cookies_credentialless)
    {
      promise_test_parallel(async test => {
        const token_1 = token();
        const token_2 = token();

        send(w_control_token, `
          let script = document.createElement("script");
          script.src = "${showRequestHeaders(origin, token_1)}";
          ${mode};
          document.body.appendChild(script);
        `);
        send(w_credentialless_token, `
          let script = document.createElement("script");
          script.src = "${showRequestHeaders(origin, token_2)}";
          ${mode};
          document.body.appendChild(script);
        `);

        const headers_control = JSON.parse(await receive(token_1));
        const headers_credentialless = JSON.parse(await receive(token_2));

        assert_equals(parseCookies(headers_control)[cookie_key],
          expected_cookies_control,
          "dip:none => ");
        assert_equals(parseCookies(headers_credentialless)[cookie_key],
          expected_cookies_credentialless,
          "dip:credentialless => ");
      }, `script ${description}`)
    };

    // Same-origin request always contains Cookies:
    scriptTest("same-origin + undefined",
      same_origin, '',
      cookie_same_origin,
      cookie_same_origin);
    scriptTest("same-origin + anonymous",
      same_origin, 'script.crossOrigin="anonymous"',
      cookie_same_origin,
      cookie_same_origin);
    scriptTest("same-origin + use-credentials",
      same_origin, 'script.crossOrigin="use-credentials"',
      cookie_same_origin,
      cookie_same_origin);

    // Cross-origin request contains cookies in the following cases:
    // - DIP:credentialless is not set.
    // - script.crossOrigin is `use-credentials`.
    scriptTest("cross-origin + undefined",
      cross_origin, '',
      cookie_cross_origin,
      undefined);
    scriptTest("cross-origin + anonymous",
      cross_origin, 'script.crossOrigin="anonymous"',
      undefined,
      undefined);
    scriptTest("cross-origin + use-credentials",
      cross_origin, 'script.crossOrigin="use-credentials"',
      cookie_cross_origin,
      cookie_cross_origin);
  }, "Main");
}