Files
sousa-gecko/storage/test/browser/encryption/browser_encrypt.js
T
Benjamin Beurdouche 0d007d4288 Bug 1996558 - Lock SQLite-encryption pref and route override through enterprise policy r=mkaply
Lock the pref in modules/libpref/init/all.js so end users cannot toggle
it from about:config or user.js, and add it to the Preferences
enterprise-policy allowlist so admins can still drive it from
policies.json.

The pref stays declared as a StaticPref in StaticPrefList.yaml; this
patch only adds the locking and policy plumbing.

Differential Revision: https://phabricator.services.mozilla.com/D297713
2026-06-16 13:00:24 +00:00

66 lines
1.7 KiB
JavaScript

/* Any copyright is dedicated to the Public Domain.
http://creativecommons.org/publicdomain/zero/1.0/ */
// Test that databases are encrypted on disk.
"use strict";
const lazy = {};
ChromeUtils.defineESModuleGetters(lazy, {
Sqlite: "resource://gre/modules/Sqlite.sys.mjs",
});
async function removeIfExists(path) {
if (await IOUtils.exists(path)) {
await IOUtils.remove(path);
}
}
add_task(async function testSecurityEnableEncryption() {
if (
!Services.prefs.getBoolPref(
"security.storage.encryption.sqlite.enabled",
false
)
) {
ok(true, "SQLite encryption disabled (landing default); skipping.");
return;
}
let profileDir = Services.dirsvc.get("ProfD", Ci.nsIFile).path;
let dbName = `test_encryption_encrypt_${Date.now()}_${Math.random()
.toString(36)
.slice(2, 8)}.sqlite`;
let dbPath = PathUtils.join(profileDir, dbName);
for (let suffix of ["", "-wal", "-shm", "-journal"]) {
await removeIfExists(dbPath + suffix);
}
let conn = await lazy.Sqlite.openConnection({ path: dbName });
is(conn._connectionData._open, true, "Connection should be open");
let lorem =
"Lorem ipsum dolor sit amet, consectetur adipiscing elit. Proin a convallis nisl. Donec tincidunt sodales felis vitae tempus sed. ";
await conn.execute("CREATE TABLE IF NOT EXISTS test (value TEXT);");
await conn.execute("INSERT INTO test (value) VALUES ('" + lorem + "');");
await conn.close();
let contents = await IOUtils.read(dbPath);
// Checking for a substring is easier than checking for a subarray.
const decoder = new TextDecoder();
let text = decoder.decode(contents);
is(
text.includes(lorem),
false,
"Encrypted database should not contain plain-text values"
);
});