File: async-navigator-clipboard-read-sanitize.https.html

package info (click to toggle)
firefox 145.0-1
  • links: PTS, VCS
  • area: main
  • in suites: sid
  • size: 4,653,344 kB
  • sloc: cpp: 7,594,932; javascript: 6,459,612; ansic: 3,752,905; python: 1,403,433; xml: 629,811; asm: 438,677; java: 186,421; sh: 67,287; makefile: 19,169; objc: 13,086; perl: 12,982; yacc: 4,583; cs: 3,846; pascal: 3,448; lex: 1,720; ruby: 1,003; exp: 762; php: 436; lisp: 258; awk: 247; sql: 66; sed: 54; csh: 10
file content (48 lines) | stat: -rw-r--r-- 1,566 bytes parent folder | download | duplicates (14)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
<!doctype html>
<meta charset="utf-8">
<title>Async Clipboard.read() should sanitize text/html</title>
<link rel="help" href="https://w3c.github.io/clipboard-apis/#dom-clipboard-read">
<link rel="help" href="https://bugs.chromium.org/p/chromium/issues/detail?id=1315563">
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<script src="/resources/testdriver.js"></script>
<script src="/resources/testdriver-vendor.js"></script>
<script src="resources/user-activation.js"></script>

<body>Body needed for test_driver.click()
<p><button id="button">Put payload in the clipboard</button></p>
<div id="output"></div>

<script>
let testFailed = false;
function fail() {
  testFailed = true;
}

button.onclick = () => document.execCommand('copy');
document.oncopy = ev => {
  ev.preventDefault();
  ev.clipboardData.setData(
      'text/html',
      `<form><math><mtext></form><form><mglyph><xmp></math><img src=invalid onerror=fail()></xmp>`);
};

promise_test(async test => {
  await tryGrantReadPermission();
  await test_driver.click(button);

  await waitForUserActivation();
  const items = await navigator.clipboard.read();
  const htmlBlob = await items[0].getType("text/html");
  const html = await htmlBlob.text();

  // This inserts an image with `onerror` handler if `html` is not properly sanitized
  output.innerHTML = html;

  // Allow the 'error' event to be dispatched asynchronously
  await new Promise(resolve => test.step_timeout(resolve, 100));

  assert_false(testFailed);
});
</script>
</body>