Files
sousa-gecko/testing/web-platform/tests/credential-management/credentialscontainer-get-basics.https.html
T
Mohamed Amir Yosef fbcbaeeb45 Bug 2024993 [wpt PR 58639] - Credential Management: Test rejection of incompatible types in get(), a=testonly
Automatic update from web-platform-tests
Credential Management: Test rejection of incompatible types in get() (#58639)

* Add tests for incompatible credential types in navigator.credentials.get()

PR 261 in w3c/webappsec-credential-management restricts the set of compatible credential types in the same get() request. This change adds tests for various incompatible combinations to ensure they reject with a NotSupportedError.

* Update valid combination test to be more idiomatic using promise_rejects_dom

Based on reviewer feedback, the valid combination test now uses promise_rejects_dom to assert that the call reaches the fetching phase (failing with NotAllowedError) instead of being blocked by the compatibility check (NotSupportedError).
--

wpt-commits: 89191eb4a6fdbc94758d9ea3908278f142464edb
wpt-pr: 58639
2026-04-09 19:28:33 +00:00

121 lines
4.0 KiB
HTML

<!DOCTYPE html>
<title>Credential Management API: get() basics.</title>
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<script>
promise_test(async (t) => {
await promise_rejects_dom(
t,
"NotSupportedError",
navigator.credentials.get()
);
await promise_rejects_dom(
t,
"NotSupportedError",
navigator.credentials.get({})
);
await promise_rejects_dom(
t,
"NotSupportedError",
navigator.credentials.get({ x: "y" })
);
await promise_rejects_dom(
t,
"NotSupportedError",
navigator.credentials.get({ x: "y", y: "z" })
);
await promise_rejects_dom(
t,
"NotSupportedError",
navigator.credentials.get({ x: "y" })
);
await promise_rejects_dom(
t,
"NotSupportedError",
navigator.credentials.get({ mediation: "required" })
);
const abortController = new AbortController();
const { signal } = abortController;
await promise_rejects_dom(
t,
"NotSupportedError",
navigator.credentials.get({ signal })
);
await promise_rejects_dom(
t,
"NotSupportedError",
navigator.credentials.get({ signal, mediation: "required" })
);
}, "Calling navigator.credentials.get() without a valid matching interface.");
promise_test(async (t) => {
const invalidCombinations = [
{ password: true, publicKey: { challenge: new Uint8Array() } },
{ password: true, otp: { transport: ["sms"] } },
{ password: true, identity: { providers: [] } },
{ federated: { providers: ['https://idp.example.com'] }, publicKey: { challenge: new Uint8Array() } },
{ federated: { providers: ['https://idp.example.com'] }, otp: { transport: ["sms"] } },
{ federated: { providers: ['https://idp.example.com'] }, identity: { providers: [] } },
{ publicKey: { challenge: new Uint8Array() }, otp: { transport: ["sms"] } },
{ publicKey: { challenge: new Uint8Array() }, identity: { providers: [] } },
{ otp: { transport: ["sms"] }, identity: { providers: [] } },
];
for (const options of invalidCombinations) {
await promise_rejects_dom(
t,
"NotSupportedError",
navigator.credentials.get(options)
);
}
}, "Calling navigator.credentials.get() with invalid combinations of credential types.");
promise_test(async (t) => {
// Valid combination (password + federated) is allowed by the spec. It should reach the
// fetching phase, where it will fail with NotAllowedError due to lack of user activation,
// but crucially NOT NotSupportedError.
await promise_rejects_dom(
t,
"NotAllowedError",
navigator.credentials.get({
password: true,
federated: { providers: ['https://idp.example.com'] }
})
);
}, "Calling navigator.credentials.get() with valid combination (password + federated).");
promise_test(function(t) {
const controller = new AbortController();
controller.abort("custom reason");
return promise_rejects_exactly(t, "custom reason",
navigator.credentials.get({ signal: controller.signal }));
}, "navigator.credentials.get() aborted with custom reason");
promise_test(async function(t) {
const reasons = [{}, [], new Error("custom error")];
for (let reason of reasons) {
const result = navigator.credentials.get({ signal: AbortSignal.abort(reason) });
await promise_rejects_exactly(t, reason, result);
}
}, "navigator.credentials.get() aborted with different objects");
promise_test(function(t) {
const error = new Error("custom error");
const controller = new AbortController();
const result = navigator.credentials.get({ signal: controller.signal });
controller.abort(error); // aborted after the promise is created
return promise_rejects_exactly(t, error, result);
}, "navigator.credentials.get() rejects when aborted after the promise creation");
</script>