File: trusted-origins.py

package info (click to toggle)
firefox 144.0-1
  • links: PTS, VCS
  • area: main
  • in suites: sid
  • size: 4,637,504 kB
  • sloc: cpp: 7,576,692; javascript: 6,430,831; ansic: 3,748,119; python: 1,398,978; xml: 628,810; asm: 438,679; java: 186,194; sh: 63,212; makefile: 19,159; objc: 13,086; perl: 12,986; yacc: 4,583; cs: 3,846; pascal: 3,448; lex: 1,720; ruby: 1,003; exp: 762; php: 436; lisp: 258; awk: 247; sql: 66; sed: 53; csh: 10
file content (64 lines) | stat: -rw-r--r-- 2,054 bytes parent folder | download | duplicates (12)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
import json

SUBDOMAIN_TUPLE_TO_ALLOWED_ORIGINS_MAP = {
    ("", "web-platform"): [],
    ("www", "web-platform"): [
        {
            "scriptOrigin": "https://web-platform.test",
            "contextOrigin": ["https://web-platform.test"],
         },
        {
            "scriptOrigin": "https://www.web-platform.test",
            "contextOrigin": "*",
         },
    ],
    ("www1", "web-platform"): [
        {
            "scriptOrigin": [
                "https://google.com",
                "https://web-platform.test",
            ],
            "contextOrigin": "https://web-platform.test",
         },
        {
            "scriptOrigin": "https://www.web-platform.test",
            "contextOrigin": ["*"],
         },
    ],
    ("www2", "web-platform"): [],
    ("", "not-web-platform"): [],
    ("www", "not-web-platform"): [],
    ("www1", "not-web-platform"): [],
    ("www2", "not-web-platform"): [],
}

def get_host(request):
    return request.url_parts.netloc.split(":")[0]

def get_port(request):
    if len(request.url_parts.netloc.split(":")) > 1:
        return request.url_parts.netloc.split(":")[1]
    return 0

def get_subdomain_tuple(request):
    host = get_host(request)
    host_list = host.split(".")
    if len(host_list) == 0 or len(host_list) > 3:
        raise ValueError("Invalid host " + host)
    if len(host_list) == 1:
        return ("", host_list[0])
    return (host_list[0], host_list[1])

def get_allowed_origins(request):
    subdomain_tuple = get_subdomain_tuple(request)
    origin_list = SUBDOMAIN_TUPLE_TO_ALLOWED_ORIGINS_MAP[subdomain_tuple]
    origins_string = json.dumps(origin_list)
    test_with_port = ".test:" + str(get_port(request))
    origins_with_ports = origins_string.replace(".test", test_with_port)
    return origins_with_ports

def get_json(request, response):
    response.status = (200, b"OK")
    response.headers.set(b"Content-Type", b"application/json")
    response.headers.set(b"Access-Control-Allow-Origin", b"*")
    response.content = get_allowed_origins(request)