Files
sousa-gecko/testing/web-platform/tests/fenced-frame/automatic-beacon-data-set-by-sibling.https.html
T
Liam Brady af237d0bb3 Bug 1940413 [wpt PR 49960] - Allow setting automatic beacon data from cross-origin subframes., a=testonly
Automatic update from web-platform-tests
Allow setting automatic beacon data from cross-origin subframes.

Cross-origin fenced frames/URN iframes can send automatic reporting
beacons, but currently require data included in these beacons to be
pre-registered via an API call accessible only to a document that is
same-origin to the fenced frame config's mapped URL. This poses a
problem for cross-origin subframes within the same entity (e.g., an ad
frame and a payment subframe from the same company) that need to include
dynamic data, like click information, in the beacon. The current
workaround involves cumbersome postMessage communication and introduces
potential timing issues, highlighting the need for a more practical
solution for cross-origin subframes to set their own beacon data.

This CL relaxes that restriction and lets cross-origin documents set
automatic beacon data as well as use it. This is subject to the same
kinds of opt ins as other cross-origin FFAR features. Namely, the root
frame must opt in via the "Allow-Fenced-Frame-Automatic-Beacons" header,
and the cross-origin subframe setting the data must opt in via the
'crossOriginExposed' parameter in the call to setReportEvent...().

See: https://github.com/WICG/fenced-frame/issues/185

Change-Id: Iea922e737fa870f2edf0c24aa81927535f779d8b
Bug: 382500834
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/6074470
Reviewed-by: Andrew Verge <averge@chromium.org>
Reviewed-by: Dominic Farolino <dom@chromium.org>
Commit-Queue: Liam Brady <lbrady@google.com>
Reviewed-by: Arthur Sonzogni <arthursonzogni@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1403202}

--

wpt-commits: 0a499ef779b92a4f28e21d1410f70e56979a7403
wpt-pr: 49960
2025-01-10 09:27:23 +00:00

60 lines
2.1 KiB
HTML

<!DOCTYPE html>
<title>Test window.fence.setReportEventDataForAutomaticBeacons</title>
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<script src="/common/utils.js"></script>
<script src="/common/dispatcher/dispatcher.js"></script>
<script src="resources/utils.js"></script>
<script src="/resources/testdriver.js"></script>
<script src="/resources/testdriver-actions.js"></script>
<script src="/resources/testdriver-vendor.js"></script>
<script src="/common/get-host-info.sub.js"></script>
<script src="resources/automatic-beacon-helper.js"></script>
<body>
<script>
promise_test(async(t) => {
// This test creates the following frame tree:
// Root Frame (A)
// └─Fenced Frame (A)
// ├─IFrame (B) [performs navigation]
// └─IFrame (B) [sets data]
// It then checks that B's navigation sends an automatic beacon without data,
// even if a different B sets automatic beacon data.
const fencedframe = await attachFencedFrameContext({
generator_api: 'fledge', register_beacon: true
});
const beacon = {
eventType: "reserved.top_navigation_start",
eventData: "This data should not be sent",
destination: ["buyer"],
crossOriginExposed: true
}
await fencedframe.execute(async (beacon) => {
const iframe_a = await attachIFrameContext({
origin: get_host_info().HTTPS_REMOTE_ORIGIN,
headers: [['Allow-Fenced-Frame-Automatic-Beacons', 'true']]
});
const iframe_b = await attachIFrameContext({
origin: get_host_info().HTTPS_REMOTE_ORIGIN,
headers: [['Allow-Fenced-Frame-Automatic-Beacons', 'true']]
});
iframe_b.execute((beacon) => {
window.fence.setReportEventDataForAutomaticBeacons(beacon);
}, [beacon]);
await setupAutomaticBeacon(iframe_a, [],
"resources/close.html", NavigationTrigger.ClickOnce,
"_blank");
}, [beacon]);
await multiClick(10, 10, fencedframe.element)
await verifyBeaconData(beacon.eventType, "<No data>",
get_host_info().HTTPS_REMOTE_ORIGIN);
}, 'An automatic beacon does not use data set by a same-origin sibling.');
</script>
</body>