Files
sousa-gecko/testing/web-platform/tests/webmcp/declarative/document-domain-enabled-declarative.https.html
T
mark a. foltz 16a733b84c Bug 2045171 [wpt PR 60403] - [webmcp]: Gate APIs on document.domain being disabled., a=testonly
Automatic update from web-platform-tests
[webmcp]: Gate APIs on document.domain being disabled.

If document.domain is enabled (i.e., the document is not origin-keyed,
such as when using 'Origin-Agent-Cluster: ?0'), prevent the use of
WebMCP APIs (registerTool, getTools, executeTool, and declarative tool
registration). Synchronous calls will throw a SecurityError
DOMException, and promise-returning calls will reject with a
SecurityError DOMException.

This gates WebMCP behind document.domain being disabled to prevent
issues where the document's origin might dynamically change during a
tool's lifetime.

Includes unit tests and a layout test.

Fixed: 519500882
Change-Id: Ia6b4b08ba38586963cef5b73b9ff1ad049a72a6e
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7896184
Reviewed-by: Khushal Sagar <khushalsagar@chromium.org>
Reviewed-by: Dominic Farolino <dom@chromium.org>
Commit-Queue: Mark Foltz <mfoltz@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1642043}

--

wpt-commits: 0663893a2e918931a910da06ea02fa1aebe99103
wpt-pr: 60403
2026-06-09 18:47:03 +00:00

29 lines
1.1 KiB
HTML

<!DOCTYPE html>
<meta charset="utf-8">
<title>WebMCP: Declarative tools are not registered when document.domain is enabled</title>
<link rel="author" href="mailto:dom@chromium.org">
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<body>
<form toolname="declarative_tool" tooldescription="Declarative tool description">
<input type="text" name="query" required>
</form>
<script>
promise_test(async t => {
// ontoolchange should not be triggered. We wait briefly to verify this.
let toolChangeTriggered = false;
document.modelContext.ontoolchange = () => {
toolChangeTriggered = true;
};
await new Promise(resolve => t.step_timeout(resolve, 200));
assert_false(toolChangeTriggered, "Declarative tool registration should not trigger ontoolchange");
// getTools() must reject with SecurityError because document.domain is enabled.
await promise_rejects_dom(t, 'SecurityError', document.modelContext.getTools());
}, "Declarative tool registration is blocked when document.domain is enabled");
</script>
</body>