function initTest() {
SimpleTest.waitForExplicitFinish();
// Allow all cookies, then do the actual test initialization
SpecialPowers.pushPrefEnv({ "set": [
["network.cookie.cookieBehavior", 0],
// Bug 1617611: Fix all the tests broken by "cookies SameSite=lax by default"
["network.cookie.sameSite.laxByDefault", false],
["network.cors_preflight.authorization_covered_by_wildcard", false],
]
}, initTestCallback);
}
function initTestCallback() {
window.addEventListener("message", function(e) {
gen.next(e.data);
});
gen = runTest();
gen.next()
}
async function clearCORSPreflightCacheTest() {
// need to be on the parent process to access cors-preflight-cache service to:
// send the CORS preflight cache length to the content process (before clearing)
// clear the CORS preflight cache
// and send the cache length again (after clearing)
let script = SpecialPowers.loadChromeScript(function() {
addMessageListener("start", function(principal) {
try {
let preflightCache = Cc["@mozilla.org/network/cors-preflight-cache;1"]
.getService(Ci.nsICORSPreflightCache);
let entries = preflightCache.getEntries(principal);
sendAsyncMessage("before", entries.length);
for (let entry of entries) {
preflightCache.clearEntry(entry);
}
let afterEntries = preflightCache.getEntries(principal);
sendAsyncMessage("after", afterEntries.length);
} catch (e) {
console.error("Failed to get or clear the CORS preflight cache", e);
sendAsyncMessage("before", -1);
sendAsyncMessage("after", -1);
}
});
});
// document.location.origin varies depending on --enable-xorigin-tests:
// .com or .org
// we pass the "opposite" url to the parent process (as principal)
let url = (document.location.origin == "https://example.org") ? "https://example.com" : "https://example.org";
let oa = SpecialPowers.wrap(document).nodePrincipal.originAttributes;
let principal = SpecialPowers.Services.scriptSecurityManager
.createContentPrincipal(SpecialPowers.Services.io.newURI(url), oa); script.sendAsyncMessage("start", principal);
// on the content process:
// assert on the expected CORS preflight cache sizes, before and after
await script.promiseOneMessage("before").then(val => {
// This check depends on the number of preflight cache items created
// by other tests in this file.
// For our purposes here, it is important only that the value is valid and
// indicating existing entries in the CORS preflight cache (positive values)
ok(val > 0, "CORS preflight cache size before clearing as expected");
});
await script.promiseOneMessage("after").then(val => {
is(val, 0, "CORS preflight cache empty after clearing");
});
SimpleTest.finish();
}
// eslint-disable-next-line complexity
function* runTest() { var loader = document.getElementById('loader'); var loaderWindow = loader.contentWindow;
loader.onload = function () { gen.next() };
// Test preflight-less requests
basePath = "/tests/dom/security/test/cors/file_CrossSiteXHR_server.sjs?" base = self.location.origin;
baseHost = self.location.host;
baseURL = base + basePath;
if ("username" in test) {
req.username = test.username;
}
if ("password" in test) {
req.password = test.password;
}
if (test.noAllowPreflight)
req.url += "&noAllowPreflight";
if (test.allowCred)
req.url += "&allowCred";
if (test.pass && "headers" in test) {
function isUnsafeHeader(name) {
lName = name.toLowerCase();
return lName != "accept" &&
lName != "accept-language" &&
(lName != "content-type" ||
!["text/plain", "multipart/form-data", "application/x-www-form-urlencoded"]
.includes(test.headers[name].toLowerCase()));
}
req.url += "&headers=" + escape(JSON.stringify(test.headers));
reqHeaders =
escape(Object.keys(test.headers)
.filter(isUnsafeHeader)
.map(s => s.toLowerCase())
.sort()
.join(","));
req.url += reqHeaders ? "&requestHeaders=" + reqHeaders : "";
}
if ("allowHeaders" in test)
req.url += "&allowHeaders=" + escape(test.allowHeaders);
if ("allowMethods" in test)
req.url += "&allowMethods=" + escape(test.allowMethods);
if (test.body)
req.url += "&body=" + escape(test.body);
if (test.status) {
req.url += "&status=" + test.status;
req.url += "&statusMessage=" + escape(test.statusMessage);
}
if (test.preflightStatus)
req.url += "&preflightStatus=" + test.preflightStatus;
if (test.responseHeaders)
req.url += "&responseHeaders=" + escape(JSON.stringify(test.responseHeaders));
if (test.exposeHeaders)
req.url += "&exposeHeaders=" + escape(test.exposeHeaders);
if (test.preflightBody)
req.url += "&preflightBody=" + escape(test.preflightBody);
loaderWindow.postMessage(JSON.stringify(req), origin);
res = JSON.parse(yield);
if (test.pass) {
is(res.didFail, false, "shouldn't have failed in test for " + JSON.stringify(test));
if (test.status) {
is(res.status, test.status, "wrong status in test for " + JSON.stringify(test));
is(res.statusText, test.statusMessage, "wrong status text for " + JSON.stringify(test));
}
else {
is(res.status, 200, "wrong status in test for " + JSON.stringify(test));
is(res.statusText, "OK", "wrong status text for " + JSON.stringify(test));
}
if (test.method !== "HEAD") {
is(res.responseXML, "<res>hello pass</res>", "wrong responseXML in test for " + JSON.stringify(test));
is(res.responseText, "<res>hello pass</res>\n", "wrong responseText in test for " + JSON.stringify(test));
is(res.events.join(","), "opening,rs1,sending,loadstart,rs2,rs3,rs4,load,loadend", "wrong responseText in test for " + JSON.stringify(test));
}
else {
is(res.responseXML, null, "wrong responseXML in test for " + JSON.stringify(test));
is(res.responseText, "", "wrong responseText in test for " + JSON.stringify(test));
is(res.events.join(","), "opening,rs1,sending,loadstart,rs2,rs4,load,loadend", "wrong responseText in test for " + JSON.stringify(test));
}
if (test.responseHeaders) {
for (header in test.responseHeaders) {
if (!test.expectedResponseHeaders.includes(header)) {
is(res.responseHeaders[header], null, "|xhr.getResponseHeader()|wrong response header (" + header + ") in test for " +
JSON.stringify(test));
is(res.allResponseHeaders[header], undefined, "|xhr.getAllResponseHeaderss()|wrong response header (" + header + ") in test for " +
JSON.stringify(test));
}
else {
is(res.responseHeaders[header], test.responseHeaders[header], "|xhr.getResponseHeader()|wrong response header (" + header + ") in test for " +
JSON.stringify(test));
is(res.allResponseHeaders[header.toLowerCase()], test.responseHeaders[header], "|xhr.getAllResponseHeaderss()|wrong response header (" + header + ") in test for " +
JSON.stringify(test));
}
}
}
}
else {
is(res.didFail, true, "should have failed in test for " + JSON.stringify(test));
is(res.status, 0, "wrong status in test for " + JSON.stringify(test));
is(res.statusText, "", "wrong status text for " + JSON.stringify(test));
is(res.responseXML, null, "wrong responseXML in test for " + JSON.stringify(test));
is(res.responseText, "", "wrong responseText in test for " + JSON.stringify(test));
if (!res.sendThrew) {
is(res.events.join(","), "opening,rs1,sending,loadstart,rs4,error,loadend", "wrong events in test for " + JSON.stringify(test));
}
is(res.progressEvents, 0, "wrong events in test for " + JSON.stringify(test));
if (test.responseHeaders) {
for (header in test.responseHeaders) {
is(res.responseHeaders[header], null, "wrong response header (" + header + ") in test for " +
JSON.stringify(test));
}
}
}
}
if (test.setCookie)
req.url += "&setCookie=" + escape(test.setCookie);
if (test.cookie)
req.url += "&cookie=" + escape(test.cookie);
if (test.noCookie)
req.url += "&noCookie";
if ("allowHeaders" in test)
req.url += "&allowHeaders=" + escape(test.allowHeaders);
if ("allowMethods" in test)
req.url += "&allowMethods=" + escape(test.allowMethods);
res = JSON.parse(yield);
if (test.pass) {
is(res.didFail, false, "shouldn't have failed in test for " + JSON.stringify(test));
is(res.status, 200, "wrong status in test for " + JSON.stringify(test));
is(res.statusText, "OK", "wrong status text for " + JSON.stringify(test));
is(res.responseXML, "<res>hello pass</res>", "wrong responseXML in test for " + JSON.stringify(test));
is(res.responseText, "<res>hello pass</res>\n", "wrong responseText in test for " + JSON.stringify(test));
is(res.events.join(","), "opening,rs1,sending,loadstart,rs2,rs3,rs4,load,loadend", "wrong responseText in test for " + JSON.stringify(test));
}
else {
is(res.didFail, true, "should have failed in test for " + JSON.stringify(test));
is(res.status, 0, "wrong status in test for " + JSON.stringify(test));
is(res.statusText, "", "wrong status text for " + JSON.stringify(test));
is(res.responseXML, null, "wrong responseXML in test for " + JSON.stringify(test));
is(res.responseText, "", "wrong responseText in test for " + JSON.stringify(test));
is(res.events.join(","), "opening,rs1,sending,loadstart,rs4,error,loadend", "wrong events in test for " + JSON.stringify(test));
is(res.progressEvents, 0, "wrong events in test for " + JSON.stringify(test));
}
}
// Make sure to clear cookies to avoid affecting other tests
document.cookie = "a=; partitioned; secure; samesite=none; path=/; expires=Thu, 01-Jan-1970 00:00:01 GMT"
is(document.cookie, "", "No cookies should be left over");
res = JSON.parse(yield);
if (test.pass) {
is(res.didFail, false, "shouldn't have failed in test for " + JSON.stringify(test));
is(res.status, 200, "wrong status in test for " + JSON.stringify(test));
is(res.statusText, "OK", "wrong status text for " + JSON.stringify(test));
is(res.responseXML, "<res>hello pass</res>", "wrong responseXML in test for " + JSON.stringify(test));
is(res.responseText, "<res>hello pass</res>\n", "wrong responseText in test for " + JSON.stringify(test));
is(res.events.join(","), "opening,rs1,sending,loadstart,rs2,rs3,rs4,load,loadend", "wrong responseText in test for " + JSON.stringify(test));
}
else {
is(res.didFail, true, "should have failed in test for " + JSON.stringify(test));
is(res.status, 0, "wrong status in test for " + JSON.stringify(test));
is(res.statusText, "", "wrong status text for " + JSON.stringify(test));
is(res.responseXML, null, "wrong responseXML in test for " + JSON.stringify(test));
is(res.responseText, "", "wrong responseText in test for " + JSON.stringify(test));
is(res.events.join(","), "opening,rs1,sending,loadstart,rs4,error,loadend", "wrong events in test for " + JSON.stringify(test));
is(res.progressEvents, 0, "wrong progressevents in test for " + JSON.stringify(test));
}
}
¤ Diese beiden folgenden Angebotsgruppen bietet das Unternehmen0.53Angebot
(Wie Sie bei der Firma Beratungs- und Dienstleistungen beauftragen können 2026-09-29)
¤
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.