File: credentialless-video.https.tentative.window.js

package info (click to toggle)
thunderbird 1%3A140.5.0esr-1~deb12u1
  • links: PTS, VCS
  • area: main
  • in suites: bookworm-proposed-updates
  • size: 4,609,180 kB
  • sloc: cpp: 7,672,739; javascript: 5,901,898; ansic: 3,898,899; python: 1,413,347; xml: 653,997; asm: 462,284; java: 180,927; sh: 113,491; makefile: 20,463; perl: 14,288; objc: 13,059; yacc: 4,583; pascal: 3,352; lex: 1,720; ruby: 1,222; exp: 762; sql: 715; awk: 580; php: 436; lisp: 430; sed: 70; csh: 10
file content (53 lines) | stat: -rw-r--r-- 1,871 bytes parent folder | download | duplicates (12)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
// META: script=/common/get-host-info.sub.js
// META: script=/common/utils.js
// META: script=/common/dispatcher/dispatcher.js
// META: script=./resources/common.js

const same_origin = get_host_info().HTTPS_ORIGIN;
const cross_origin = get_host_info().HTTPS_REMOTE_ORIGIN;
const cookie_key = "dip_credentialless_image";
const cookie_same_origin = "same_origin";
const cookie_cross_origin = "cross_origin";

promise_setup(async test => {
  await Promise.all([
    setCookie(same_origin, cookie_key, cookie_same_origin +
      cookie_same_site_none),
    setCookie(cross_origin, cookie_key, cookie_cross_origin +
      cookie_same_site_none),
  ]);
}, "Setup cookies");

const videoTest = function(description, origin, mode, expected_cookie) {
  promise_test(async test => {
    const video_token = token();

    let video = document.createElement("video");
    video.src = showRequestHeaders(origin, video_token);
    video.autoplay = true;
    if (mode)
      video.crossOrigin = mode;
    document.body.appendChild(video);

    const headers = JSON.parse(await receive(video_token));

    assert_equals(parseCookies(headers)[cookie_key], expected_cookie);
  }, `video ${description}`)
};

// Same-origin request always contains Cookies:
videoTest("same-origin + undefined",
  same_origin, undefined, cookie_same_origin);
videoTest("same-origin + anonymous",
  same_origin, 'anonymous', cookie_same_origin);
videoTest("same-origin + use-credentials",
  same_origin, 'use-credentials', cookie_same_origin);

// Cross-origin request contains cookies, only when sent in CORS mode, using
// crossOrigin = "use-credentials".
videoTest("cross-origin + undefined",
  cross_origin, '', undefined);
videoTest("cross-origin + anonymous",
  cross_origin, 'anonymous', undefined);
videoTest("cross-origin + use-credentials",
  cross_origin, 'use-credentials', cookie_cross_origin);