summaryrefslogtreecommitdiffstats
path: root/extensions/permissions/test/unit/test_permmanager_site_scope.js
blob: dbfe9dc0222cac9af6549b0f48b62e28de3cb8b7 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
const TEST_SITE_URI = Services.io.newURI("http://example.com");
const TEST_FQDN_1_URI = Services.io.newURI("http://test1.example.com");
const TEST_FQDN_2_URI = Services.io.newURI("http://test2.example.com");
const TEST_OTHER_URI = Services.io.newURI("http://example.net");
const TEST_PERMISSION = "3rdPartyStorage^https://example.org";
const TEST_FRAME_PERMISSION = "3rdPartyFrameStorage^https://example.org";

async function do_test(permission) {
  let pm = Services.perms;

  let principal = Services.scriptSecurityManager.createContentPrincipal(
    TEST_SITE_URI,
    {}
  );

  let subdomain1Principal =
    Services.scriptSecurityManager.createContentPrincipal(TEST_FQDN_1_URI, {});

  let subdomain2Principal =
    Services.scriptSecurityManager.createContentPrincipal(TEST_FQDN_2_URI, {});

  let otherPrincipal = Services.scriptSecurityManager.createContentPrincipal(
    TEST_OTHER_URI,
    {}
  );

  // Set test permission for site
  pm.addFromPrincipal(principal, permission, pm.ALLOW_ACTION);

  // Check normal site permission
  Assert.equal(
    Ci.nsIPermissionManager.ALLOW_ACTION,
    pm.testPermissionFromPrincipal(principal, permission)
  );

  // Check subdomain permission
  Assert.equal(
    Ci.nsIPermissionManager.ALLOW_ACTION,
    pm.testPermissionFromPrincipal(subdomain1Principal, permission)
  );

  // Check other site permission
  Assert.equal(
    Ci.nsIPermissionManager.UNKNOWN_ACTION,
    pm.testPermissionFromPrincipal(otherPrincipal, permission)
  );

  // Remove the permission from the site
  pm.removeFromPrincipal(principal, permission);
  Assert.equal(
    pm.testPermissionFromPrincipal(principal, permission),
    Ci.nsIPermissionManager.UNKNOWN_ACTION
  );
  Assert.equal(
    pm.testPermissionFromPrincipal(subdomain1Principal, permission),
    Ci.nsIPermissionManager.UNKNOWN_ACTION
  );

  // Set test permission for subdomain
  pm.addFromPrincipal(subdomain1Principal, permission, pm.ALLOW_ACTION);

  // Check normal site permission
  Assert.equal(
    Ci.nsIPermissionManager.ALLOW_ACTION,
    pm.testPermissionFromPrincipal(principal, permission)
  );

  // Check subdomain permission
  Assert.equal(
    Ci.nsIPermissionManager.ALLOW_ACTION,
    pm.testPermissionFromPrincipal(subdomain1Principal, permission)
  );

  // Check other subdomain permission
  Assert.equal(
    Ci.nsIPermissionManager.ALLOW_ACTION,
    pm.testPermissionFromPrincipal(subdomain2Principal, permission)
  );

  // Check other site permission
  Assert.equal(
    Ci.nsIPermissionManager.UNKNOWN_ACTION,
    pm.testPermissionFromPrincipal(otherPrincipal, permission)
  );

  // Check that subdomains include the site-scoped in the getAllForPrincipal
  let sitePerms = pm.getAllForPrincipal(principal, permission);
  let subdomain1Perms = pm.getAllForPrincipal(subdomain1Principal, permission);
  let subdomain2Perms = pm.getAllForPrincipal(subdomain2Principal, permission);
  let otherSitePerms = pm.getAllForPrincipal(otherPrincipal, permission);

  Assert.equal(sitePerms.length, 1);
  Assert.equal(subdomain1Perms.length, 1);
  Assert.equal(subdomain2Perms.length, 1);
  Assert.equal(otherSitePerms.length, 0);

  // Remove the permission from the subdomain
  pm.removeFromPrincipal(subdomain1Principal, permission);
  Assert.equal(
    pm.testPermissionFromPrincipal(principal, permission),
    Ci.nsIPermissionManager.UNKNOWN_ACTION
  );
  Assert.equal(
    pm.testPermissionFromPrincipal(subdomain1Principal, permission),
    Ci.nsIPermissionManager.UNKNOWN_ACTION
  );
  Assert.equal(
    pm.testPermissionFromPrincipal(subdomain2Principal, permission),
    Ci.nsIPermissionManager.UNKNOWN_ACTION
  );
}

add_task(async function do3rdPartyStorageTest() {
  do_test(TEST_PERMISSION);
});

add_task(async function do3rdPartyFrameStorageTest() {
  do_test(TEST_FRAME_PERMISSION);
});