Files
sousa-gecko/testing/web-platform/tests/storage-access-api/requestStorageAccess.sub.https.window.js
T
Chris Fredrickson 831b9367a9 Bug 2041862 [wpt PR 60115] - [SAA] Add assertion for hasStorageAccess in ABA embeds, a=testonly
Automatic update from web-platform-tests
[SAA] Add assertion for `hasStorageAccess` in ABA embeds

This requirement is part of the spec as of
https://github.com/privacycg/storage-access/pull/244.

Change-Id: I697621e8eae589dc4db06353660333f8eaaa5964
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7795672
Commit-Queue: Anusha Muley <anushamuley@google.com>
Reviewed-by: Anusha Muley <anushamuley@google.com>
Auto-Submit: Chris Fredrickson <cfredric@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1634938}

--

wpt-commits: f9eb4250fa0682c83be9454a761b9f6b34bfc9ed
wpt-pr: 60115
2026-05-29 15:56:41 +00:00

113 lines
4.8 KiB
JavaScript

// META: script=helpers.js
// META: script=/cookies/resources/cookie-helper.sub.js
// META: script=/resources/testdriver.js
// META: script=/resources/testdriver-vendor.js
'use strict';
// Document-level test config flags:
//
// testPrefix: Prefix each test case with an indicator so we know what context
// they are run in if they are used in multiple iframes.
//
// topLevelDocument: Keep track of if we run these tests in a nested context, we
// don't want to recurse forever.
const {testPrefix, topLevelDocument} = processQueryParams();
const canUseAutogrant = topLevelDocument ||
testPrefix.includes('same-site') ||
testPrefix.includes('same-origin') ||
testPrefix.includes('cross-origin') ||
testPrefix.includes('ABA');
const initialCookie = "initial-cookie=unpartitioned;Secure;SameSite=None;Path=/";
if (!topLevelDocument) {
// WPT synthesizes a top-level HTML test for this JS file, and in that case we
// don't want to, or need to, call set_test_context.
test_driver.set_test_context(window.top);
}
// Common tests to run in all frames.
promise_test(async () => {
assert_not_equals(document.requestStorageAccess, undefined);
}, "[" + testPrefix + "] document.requestStorageAccess() should exist on the document interface");
// Most tests need to start with the feature in "prompt" state.
async function CommonSetup() {
await SetFirstPartyCookie(location.origin, initialCookie);
if (!canUseAutogrant) {
await test_driver.set_permission({ name: 'storage-access' }, 'prompt');
}
}
promise_test(
async t => {
await CommonSetup();
if (canUseAutogrant) {
await document.requestStorageAccess().catch(t.unreached_func(
'document.requestStorageAccess() call should resolve in top-level frame or same-site iframe.'));
assert_true(await CanAccessCookiesViaHTTP(), 'After obtaining storage access, subresource requests from the frame should send and set cookies.');
assert_true(CanAccessCookiesViaJS(), 'After obtaining storage access, scripts in the frame should be able to access cookies.');
if (testPrefix.includes('ABA')) {
assert_true(await document.hasStorageAccess(), 'After obtaining storage access, `hasStorageAccess` should resolve with true.');
}
} else {
return promise_rejects_dom(
t, "NotAllowedError", document.requestStorageAccess(),
"document.requestStorageAccess() call without user gesture.");
}
},
'[' + testPrefix +
'] document.requestStorageAccess() should resolve in top-level frame or same-site iframe, otherwise reject with a NotAllowedError with no user gesture.');
promise_test(
async (t) => {
await CommonSetup();
await MaybeSetStorageAccess("*", "*", "blocked");
await test_driver.set_permission({name: 'storage-access'}, 'granted');
t.add_cleanup(async () => {
await test_driver.delete_all_cookies();
});
await document.requestStorageAccess();
assert_true(await CanAccessCookiesViaHTTP(), 'After obtaining storage access, subresource requests from the frame should send and set cookies.');
assert_true(CanAccessCookiesViaJS(), 'After obtaining storage access, scripts in the frame should be able to access cookies.');
},
'[' + testPrefix +
'] document.requestStorageAccess() should be resolved with no user gesture when a permission grant exists, and ' +
'should allow cookie access');
if (!canUseAutogrant) {
promise_test(
async t => {
t.add_cleanup(async () => {
await test_driver.set_permission({name: 'storage-access'}, 'prompt');
});
await SetFirstPartyCookie(location.origin, initialCookie);
await test_driver.set_permission(
{name: 'storage-access'}, 'denied');
await RunCallbackWithGesture(() => {
return promise_rejects_dom(t, "NotAllowedError", document.requestStorageAccess(),
"document.requestStorageAccess() call with denied permission");
});
},
'[' + testPrefix +
'] document.requestStorageAccess() should be rejected with a NotAllowedError with denied permission');
} else {
promise_test(
async t => {
t.add_cleanup(async () => {
await test_driver.set_permission({name: 'storage-access'}, 'prompt');
});
await SetFirstPartyCookie(location.origin, initialCookie);
await document.requestStorageAccess();
assert_true(await CanAccessCookiesViaHTTP(), 'After obtaining storage access, subresource requests from the frame should send and set cookies.');
assert_true(CanAccessCookiesViaJS(), 'After obtaining storage access, scripts in the frame should be able to access cookies.');
},
`[${testPrefix}] document.requestStorageAccess() should resolve without permission grant or user gesture`);
}