Files
sousa-gecko/testing/web-platform/tests/webmcp/imperative/exposedTo-invalid-origins.https.html
T
Dominic Farolino 9664979c87 Bug 2053854 [wpt PR 61186] - WebMCP: Remove navigator.modelContext, a=testonly
Automatic update from web-platform-tests
WebMCP: Remove navigator.modelContext

This CL is a follow-up to https://crrev.com/c/7867800. It removes
navigator.modelContext in favor of document.modelContext.

R=khushalsagar

Bug: 489045948
Change-Id: I1a4636afc7b0585412ccc3fabe9369148cd9c3cd
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8062992
Reviewed-by: Khushal Sagar <khushalsagar@chromium.org>
Auto-Submit: Dominic Farolino <dom@chromium.org>
Commit-Queue: Khushal Sagar <khushalsagar@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1659793}

--

wpt-commits: 546a309f0e765b577b4f1b8ee60208e5004045ed
wpt-pr: 61186
2026-07-12 11:59:28 +00:00

58 lines
1.8 KiB
HTML

<!DOCTYPE html>
<html>
<head>
<title>Invalid origins in exposedTo array</title>
<link rel="author" href="mailto:dom@chromium.org">
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
</head>
<body>
<script>
const test_cases = [
{success: false, origin: '/'},
{success: false, origin: '*'},
{success: false, origin: 'https://example:bogus'},
{success: false, origin: 'https://\ud800.com'},
{success: false, origin: 'http://example.com'},
{success: false, origin: 'ftp://example.com'},
{success: false, origin: 'about:blank'},
{success: false, origin: 'about:srcdoc'},
{success: true, origin: 'https://example.com'},
{success: true, origin: 'http://localhost:3000'},
];
for (const test of test_cases) {
promise_test(async t => {
const register = () => {
return document.modelContext.registerTool({
name: 'test_tool_' + Math.random(),
description: 'Test tool',
execute: async () => 'hello'
}, { exposedTo: [test.origin] });
};
if (!test.success) {
return promise_rejects_dom(t, 'SecurityError', register(), `Should throw SecurityError for origin: ${test.origin}`);
} else {
try {
await register();
} catch (e) {
throw new Error(`Should not have thrown for ${test.origin}`);
}
}}, `registerTool() throws SecurityError for invalid or ` +
`non-potentially-trustworthy origins like ${test.origin} in exposedTo`);
}
promise_test(async t => {
const signal = AbortSignal.abort('aborted');
return promise_rejects_exactly(t, 'aborted', document.modelContext.registerTool({
name: "name",
description: "description",
execute: () => {}
}, { signal, exposedTo: ['about:blank#invalidOrigin']}) )
}, "registerTool() with abort signal reason because signal is processed before `exposedTo`");
</script>
</body>
</html>