summaryrefslogtreecommitdiffstats
path: root/devtools/client/webconsole/test/browser/browser_webconsole_hsts_invalid-headers.js
blob: 3d8b4b3331edc93f1bb10186c48644f775be070a (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
/* Any copyright is dedicated to the Public Domain.
 * http://creativecommons.org/publicdomain/zero/1.0/ */

// Tests that errors about invalid HSTS security headers are logged to the web console.

"use strict";

const TEST_URI =
  "data:text/html;charset=utf-8,<!DOCTYPE html>Web Console HSTS invalid header test";
const SJS_URL =
  "https://example.com/browser/devtools/client/webconsole/" +
  "/test/browser/test_hsts-invalid-headers.sjs";
const LEARN_MORE_URI =
  "https://developer.mozilla.org/docs/Web/HTTP/Headers/" +
  "Strict-Transport-Security" +
  DOCS_GA_PARAMS;

add_task(async function () {
  const hud = await openNewTabAndConsole(TEST_URI);

  await navigateAndCheckWarningMessage(
    {
      url: SJS_URL + "?badSyntax",
      name: "Could not parse header error displayed successfully",
      text:
        "Strict-Transport-Security: The site specified a header that could " +
        "not be parsed successfully.",
    },
    hud
  );

  await navigateAndCheckWarningMessage(
    {
      url: SJS_URL + "?noMaxAge",
      name: "No max-age error displayed successfully",
      text:
        "Strict-Transport-Security: The site specified a header that did " +
        "not include a \u2018max-age\u2019 directive.",
    },
    hud
  );

  await navigateAndCheckWarningMessage(
    {
      url: SJS_URL + "?invalidIncludeSubDomains",
      name: "Invalid includeSubDomains error displayed successfully",
      text:
        "Strict-Transport-Security: The site specified a header that " +
        "included an invalid \u2018includeSubDomains\u2019 directive.",
    },
    hud
  );

  await navigateAndCheckWarningMessage(
    {
      url: SJS_URL + "?invalidMaxAge",
      name: "Invalid max-age error displayed successfully",
      text:
        "Strict-Transport-Security: The site specified a header that " +
        "included an invalid \u2018max-age\u2019 directive.",
    },
    hud
  );

  await navigateAndCheckWarningMessage(
    {
      url: SJS_URL + "?multipleIncludeSubDomains",
      name: "Multiple includeSubDomains error displayed successfully",
      text:
        "Strict-Transport-Security: The site specified a header that " +
        "included multiple \u2018includeSubDomains\u2019 directives.",
    },
    hud
  );

  await navigateAndCheckWarningMessage(
    {
      url: SJS_URL + "?multipleMaxAge",
      name: "Multiple max-age error displayed successfully",
      text:
        "Strict-Transport-Security: The site specified a header that " +
        "included multiple \u2018max-age\u2019 directives.",
    },
    hud
  );
});

async function navigateAndCheckWarningMessage({ url, name, text }, hud) {
  await clearOutput(hud);

  const onMessage = waitForMessageByType(hud, text, ".warn");
  await navigateTo(url);
  const { node } = await onMessage;
  ok(node, name);

  const learnMoreNode = node.querySelector(".learn-more-link");
  ok(learnMoreNode, `There is a "Learn more" link`);
  const navigationResponse = await simulateLinkClick(learnMoreNode);
  is(
    navigationResponse.link,
    LEARN_MORE_URI,
    "Click on the learn more link navigates the user to the expected url"
  );
}