Automatic update from web-platform-tests WPT: fix overuse of PREFETCH_PROXY_BYPASS_HOST (#53271) Several tests had copied usage of PREFETCH_PROXY_BYPASS_HOST when it was not necessary, and instead they could work with any cross-origin or cross-site host. Move them to using get_host_info().NOTSAMESITE_HOST instead for this purpose. (This host had to be exposed by editing get-host-info.sub.js.) Rename PREFETCH_PROXY_BYPASS_HOST to CROSS_ORIGIN_HOST_THAT_WORKS_WITH_ACIWCO ("ACIWCO" = "anonymous-client-ip-when-cross-origin"), and add a comment about exactly when it is to be used, plus a TODO about making this a more official part of the web platform tests infrastructure in the future. Notable specific test cases: * anonymous-client.https.html was actually testing the ACIWCO feature, so it uses CROSS_ORIGIN_HOST_THAT_WORKS_WITH_ACIWCO legitimately. * cross-origin-cookies.https.html was testing two things: cross-origin cookies, and the fact that if two prefetches were sent, the first with ACIWCO and the second without, then ACIWCO would apply. Split it into two tests, so that one test can focus only on cookies and the other can test the ACIWCO interaction. * user-pass.https.html was using ACIWCO for no reason related to the test. Stop doing so. We thus end up with only two test files, anonymous-client.https.html and cross-origin-cookies-anonymous-client-ip-duplicate.https.html, which depend on ACIWCO. Future work will move these into a specific virtual test suite. Bug: 409806816 Change-Id: Ia7de51862e0b99ddc13bfcf71ecf4d04a2f89b02 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/6650746 Auto-Submit: Domenic Denicola <domenic@chromium.org> Commit-Queue: Hiroki Nakagawa <nhiroki@chromium.org> Reviewed-by: Hiroki Nakagawa <nhiroki@chromium.org> Cr-Commit-Position: refs/heads/main@{#1476054} Co-authored-by: Domenic Denicola <domenic@chromium.org> -- wpt-commits: 4c174f4ad156adb4adb14168d2d6565b1aa5ee36 wpt-pr: 53271
44 lines
1.9 KiB
HTML
44 lines
1.9 KiB
HTML
<!DOCTYPE html>
|
|
<meta name="timeout" content="long">
|
|
<script src="/resources/testharness.js"></script>
|
|
<script src="/resources/testharnessreport.js"></script>
|
|
<script src="/common/dispatcher/dispatcher.js"></script>
|
|
<script src="/common/utils.js"></script>
|
|
<script src="/common/get-host-info.sub.js"></script>
|
|
<script src="../resources/utils.js"></script>
|
|
<script src="resources/utils.sub.js"></script>
|
|
|
|
<meta name="variant" content="?cross-origin=true">
|
|
<meta name="variant" content="?cross-origin=false">
|
|
|
|
<script>
|
|
setup(() => assertSpeculationRulesIsSupported());
|
|
|
|
let cross_origin = Object.fromEntries(new URLSearchParams(location.search))["cross-origin"] === "true";
|
|
promise_test(async t => {
|
|
let executor = "authenticate.py";
|
|
let credentials = { username: "user", password: "pass" };
|
|
let agent = await spawnWindow(t, { executor, ...credentials });
|
|
let request_credentials = await agent.getRequestCredentials();
|
|
assert_equals(request_credentials.username, credentials.username);
|
|
assert_equals(request_credentials.password, credentials.password);
|
|
|
|
let host = cross_origin ? { hostname: get_host_info().NOTSAMESITE_HOST } : {};
|
|
let nextUrl = agent.getExecutorURL({ page: 2, executor, ...host });
|
|
await agent.forceSinglePrefetch(nextUrl);
|
|
await agent.navigate(nextUrl);
|
|
|
|
let requestHeaders = await agent.getRequestHeaders();
|
|
request_credentials = await agent.getRequestCredentials();
|
|
if (cross_origin) {
|
|
assert_equals(request_credentials.username, undefined);
|
|
assert_equals(request_credentials.password, undefined);
|
|
}
|
|
else {
|
|
assert_equals(request_credentials.username, credentials.username);
|
|
assert_equals(request_credentials.password, credentials.password);
|
|
}
|
|
assert_prefetched(requestHeaders);
|
|
}, "test www-authenticate basic does not forward credentials to cross-origin pages.");
|
|
</script>
|