Automatic update from web-platform-tests [webmcp]: Gate APIs on document.domain being disabled. If document.domain is enabled (i.e., the document is not origin-keyed, such as when using 'Origin-Agent-Cluster: ?0'), prevent the use of WebMCP APIs (registerTool, getTools, executeTool, and declarative tool registration). Synchronous calls will throw a SecurityError DOMException, and promise-returning calls will reject with a SecurityError DOMException. This gates WebMCP behind document.domain being disabled to prevent issues where the document's origin might dynamically change during a tool's lifetime. Includes unit tests and a layout test. Fixed: 519500882 Change-Id: Ia6b4b08ba38586963cef5b73b9ff1ad049a72a6e Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7896184 Reviewed-by: Khushal Sagar <khushalsagar@chromium.org> Reviewed-by: Dominic Farolino <dom@chromium.org> Commit-Queue: Mark Foltz <mfoltz@chromium.org> Cr-Commit-Position: refs/heads/main@{#1642043} -- wpt-commits: 0663893a2e918931a910da06ea02fa1aebe99103 wpt-pr: 60403
29 lines
1.1 KiB
HTML
29 lines
1.1 KiB
HTML
<!DOCTYPE html>
|
|
<meta charset="utf-8">
|
|
<title>WebMCP: Declarative tools are not registered when document.domain is enabled</title>
|
|
<link rel="author" href="mailto:dom@chromium.org">
|
|
<script src="/resources/testharness.js"></script>
|
|
<script src="/resources/testharnessreport.js"></script>
|
|
<body>
|
|
|
|
<form toolname="declarative_tool" tooldescription="Declarative tool description">
|
|
<input type="text" name="query" required>
|
|
</form>
|
|
|
|
<script>
|
|
promise_test(async t => {
|
|
// ontoolchange should not be triggered. We wait briefly to verify this.
|
|
let toolChangeTriggered = false;
|
|
document.modelContext.ontoolchange = () => {
|
|
toolChangeTriggered = true;
|
|
};
|
|
|
|
await new Promise(resolve => t.step_timeout(resolve, 200));
|
|
assert_false(toolChangeTriggered, "Declarative tool registration should not trigger ontoolchange");
|
|
|
|
// getTools() must reject with SecurityError because document.domain is enabled.
|
|
await promise_rejects_dom(t, 'SecurityError', document.modelContext.getTools());
|
|
}, "Declarative tool registration is blocked when document.domain is enabled");
|
|
</script>
|
|
</body>
|