Automatic update from web-platform-tests [SAA] Fix test failures due to default cookie availability This fixes the tests such that they no longer assume that third-party cookies are blocked by default (or that test_driver.set_storage_access does anything; see https://github.com/privacycg/storage-access/issues/162 for discussion). Fixed: b:446148374 Change-Id: I11c1e4fee88cbde810d31445357b233fcebc566b Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/6973284 Commit-Queue: Chris Fredrickson <cfredric@chromium.org> Auto-Submit: Chris Fredrickson <cfredric@chromium.org> Reviewed-by: Dylan Cutler <dylancutler@google.com> Cr-Commit-Position: refs/heads/main@{#1519499} -- Remove new assertion -- wpt-commits: c3f887e7f1f9ff410de609304f95e550d4a37570, 8539bf6cb4b87d36ceef4cee1b951f203cfda2e8 wpt-pr: 55018
117 lines
4.4 KiB
HTML
117 lines
4.4 KiB
HTML
<!DOCTYPE html>
|
|
<title>Federated Credential Management API / Storage Access API autogrants tests.</title>
|
|
<meta name="timeout" content="long">
|
|
<link rel="help" href="https://fedidcg.github.io/FedCM">
|
|
<link rel="help" href="https://privacycg.github.io/storage-access/">
|
|
<script src="/resources/testharness.js"></script>
|
|
<script src="/resources/testharnessreport.js"></script>
|
|
<script src="/resources/testdriver.js"></script>
|
|
<script src="/resources/testdriver-vendor.js"></script>
|
|
<script src="/storage-access-api/helpers.js"></script>
|
|
|
|
<script type="module">
|
|
import {request_options_with_mediation_required,
|
|
fedcm_test,
|
|
select_manifest,
|
|
fedcm_get_and_select_first_account} from './support/fedcm-helper.sub.js';
|
|
|
|
const www_alt = "https://{{hosts[alt][www]}}:{{ports[https][0]}}";
|
|
const responder_html_load_ack = "/storage-access-api/resources/script-with-cookie-header.py?script=embedded_responder.js&should_ack_load=true";
|
|
|
|
fedcm_test(async t => {
|
|
await MaybeSetStorageAccess("*", "*", "blocked");
|
|
let test_options = request_options_with_mediation_required();
|
|
await select_manifest(t, test_options);
|
|
|
|
await fedcm_get_and_select_first_account(t, test_options);
|
|
|
|
const frame_loaded = new Promise(r => {
|
|
onmessage = e => {
|
|
if (e.data == "loaded") {
|
|
r(e.data);
|
|
}
|
|
}
|
|
});
|
|
const frame = await CreateFrame(www_alt + responder_html_load_ack, false,
|
|
undefined, `identity-credentials-get ${www_alt};`);
|
|
assert_equals(await frame_loaded, "loaded");
|
|
if (await FrameHasStorageAccess(frame)) {
|
|
// Nothing to test here, as cross-site cookies are not blocked.
|
|
// See https://github.com/privacycg/storage-access/issues/162.
|
|
return;
|
|
}
|
|
|
|
assert_true(await RequestStorageAccessInFrame(frame),
|
|
"requestStorageAccess doesn't require a gesture since the FedCM account is already connected.");
|
|
|
|
assert_true(await FrameHasStorageAccess(frame), "frame should have storage access now.");
|
|
assert_equals(await GetPermissionInFrame(frame), "prompt");
|
|
}, "Test that FedCM accounts autogrant storage access.");
|
|
|
|
fedcm_test(async t => {
|
|
await MaybeSetStorageAccess("*", "*", "blocked");
|
|
let test_options = request_options_with_mediation_required();
|
|
await select_manifest(t, test_options);
|
|
|
|
await fedcm_get_and_select_first_account(t, test_options);
|
|
|
|
const frame_loaded = new Promise(r => {
|
|
onmessage = e => {
|
|
if (e.data == "loaded") {
|
|
r(e.data);
|
|
}
|
|
}
|
|
});
|
|
const frame = await CreateFrame(www_alt + responder_html_load_ack, false);
|
|
assert_equals(await frame_loaded, "loaded");
|
|
if (await FrameHasStorageAccess(frame)) {
|
|
// Nothing to test here, as cross-site cookies are not blocked.
|
|
// See https://github.com/privacycg/storage-access/issues/162.
|
|
return;
|
|
}
|
|
|
|
assert_false(await RequestStorageAccessInFrame(frame),
|
|
"requestStorageAccess requires a gesture since the 'identity-credentials-get' policy is absent.");
|
|
|
|
assert_false(await FrameHasStorageAccess(frame), "frame should not have storage access.");
|
|
assert_equals(await GetPermissionInFrame(frame), "prompt");
|
|
}, "Test that FedCM accounts do not autogrant storage access without permissions policy.");
|
|
|
|
fedcm_test(async t => {
|
|
await MaybeSetStorageAccess("*", "*", "blocked");
|
|
let test_options = request_options_with_mediation_required();
|
|
await select_manifest(t, test_options);
|
|
|
|
await fedcm_get_and_select_first_account(t, test_options);
|
|
try {
|
|
await navigator.credentials.preventSilentAccess();
|
|
} catch (ex) {
|
|
// In Chrome's content_shell, the promise will be rejected
|
|
// even though the part we care about succeeds.
|
|
}
|
|
|
|
const frame_loaded = new Promise(r => {
|
|
onmessage = e => {
|
|
if (e.data == "loaded") {
|
|
r(e.data);
|
|
}
|
|
}
|
|
});
|
|
const frame = await CreateFrame(www_alt + responder_html_load_ack, false,
|
|
undefined, `identity-credentials-get ${www_alt};`);
|
|
assert_equals(await frame_loaded, "loaded");
|
|
if (await FrameHasStorageAccess(frame)) {
|
|
// Nothing to test here, as cross-site cookies are not blocked.
|
|
// See https://github.com/privacycg/storage-access/issues/162.
|
|
return;
|
|
}
|
|
|
|
assert_false(await RequestStorageAccessInFrame(frame),
|
|
"requestStorageAccess requires a gesture since the preventSilentAccess flag is true.");
|
|
|
|
assert_false(await FrameHasStorageAccess(frame), "frame should not have storage access.");
|
|
assert_equals(await GetPermissionInFrame(frame), "prompt");
|
|
}, "Test that FedCM accounts do not autogrant storage access if preventSilentAccess is set.");
|
|
|
|
</script>
|