OLD | NEW |
1 // Copyright 2014 The Chromium Authors. All rights reserved. | 1 // Copyright 2014 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 #include "core/frame/SubresourceIntegrity.h" | 5 #include "core/frame/SubresourceIntegrity.h" |
6 | 6 |
7 #include "core/HTMLNames.h" | 7 #include "core/HTMLNames.h" |
8 #include "core/dom/Document.h" | 8 #include "core/dom/Document.h" |
9 #include "core/fetch/IntegrityMetadata.h" | 9 #include "core/fetch/IntegrityMetadata.h" |
10 #include "core/fetch/Resource.h" | 10 #include "core/fetch/Resource.h" |
11 #include "core/fetch/ResourcePtr.h" | |
12 #include "core/html/HTMLScriptElement.h" | 11 #include "core/html/HTMLScriptElement.h" |
13 #include "platform/Crypto.h" | 12 #include "platform/Crypto.h" |
14 #include "platform/weborigin/KURL.h" | 13 #include "platform/weborigin/KURL.h" |
15 #include "platform/weborigin/SecurityOrigin.h" | 14 #include "platform/weborigin/SecurityOrigin.h" |
16 #include "testing/gtest/include/gtest/gtest.h" | 15 #include "testing/gtest/include/gtest/gtest.h" |
17 #include "wtf/RefPtr.h" | 16 #include "wtf/RefPtr.h" |
18 #include "wtf/Vector.h" | 17 #include "wtf/Vector.h" |
19 #include "wtf/dtoa/utils.h" | 18 #include "wtf/dtoa/utils.h" |
20 #include "wtf/text/WTFString.h" | 19 #include "wtf/text/WTFString.h" |
21 | 20 |
(...skipping 131 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
153 scriptElement->setAttribute(HTMLNames::integrityAttr, integrity); | 152 scriptElement->setAttribute(HTMLNames::integrityAttr, integrity); |
154 EXPECT_TRUE(SubresourceIntegrity::CheckSubresourceIntegrity(*scriptEleme
nt, script, size, url, *createTestResource(url, requestorUrl, corsStatus).get())
); | 153 EXPECT_TRUE(SubresourceIntegrity::CheckSubresourceIntegrity(*scriptEleme
nt, script, size, url, *createTestResource(url, requestorUrl, corsStatus).get())
); |
155 } | 154 } |
156 | 155 |
157 void expectIntegrityFailure(const char* integrity, const char* script, size_
t size, const KURL& url, const KURL& requestorUrl, CorsStatus corsStatus = WithC
ors) | 156 void expectIntegrityFailure(const char* integrity, const char* script, size_
t size, const KURL& url, const KURL& requestorUrl, CorsStatus corsStatus = WithC
ors) |
158 { | 157 { |
159 scriptElement->setAttribute(HTMLNames::integrityAttr, integrity); | 158 scriptElement->setAttribute(HTMLNames::integrityAttr, integrity); |
160 EXPECT_FALSE(SubresourceIntegrity::CheckSubresourceIntegrity(*scriptElem
ent, script, size, url, *createTestResource(url, requestorUrl, corsStatus).get()
)); | 159 EXPECT_FALSE(SubresourceIntegrity::CheckSubresourceIntegrity(*scriptElem
ent, script, size, url, *createTestResource(url, requestorUrl, corsStatus).get()
)); |
161 } | 160 } |
162 | 161 |
163 ResourcePtr<Resource> createTestResource(const KURL& url, const KURL& allowO
riginUrl, CorsStatus corsStatus) | 162 PassRefPtrWillBeRawPtr<Resource> createTestResource(const KURL& url, const K
URL& allowOriginUrl, CorsStatus corsStatus) |
164 { | 163 { |
165 ResourceResponse response; | 164 ResourceResponse response; |
166 response.setURL(url); | 165 response.setURL(url); |
167 response.setHTTPStatusCode(200); | 166 response.setHTTPStatusCode(200); |
168 if (corsStatus == WithCors) { | 167 if (corsStatus == WithCors) { |
169 response.setHTTPHeaderField("access-control-allow-origin", SecurityO
rigin::create(allowOriginUrl)->toAtomicString()); | 168 response.setHTTPHeaderField("access-control-allow-origin", SecurityO
rigin::create(allowOriginUrl)->toAtomicString()); |
170 response.setHTTPHeaderField("access-control-allow-credentials", "tru
e"); | 169 response.setHTTPHeaderField("access-control-allow-credentials", "tru
e"); |
171 } | 170 } |
172 ResourcePtr<Resource> resource = new Resource(ResourceRequest(response.u
rl()), Resource::Raw); | 171 RefPtrWillBeRawPtr<Resource> resource = Resource::create(ResourceRequest
(response.url()), Resource::Raw); |
173 resource->setResponse(response); | 172 resource->setResponse(response); |
174 return resource; | 173 return resource; |
175 } | 174 } |
176 | 175 |
177 KURL secureURL; | 176 KURL secureURL; |
178 KURL insecureURL; | 177 KURL insecureURL; |
179 RefPtr<SecurityOrigin> secureOrigin; | 178 RefPtr<SecurityOrigin> secureOrigin; |
180 RefPtr<SecurityOrigin> insecureOrigin; | 179 RefPtr<SecurityOrigin> insecureOrigin; |
181 | 180 |
182 RefPtrWillBePersistent<Document> document; | 181 RefPtrWillBePersistent<Document> document; |
(...skipping 251 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
434 expectIntegrity(kUnsupportedHashFunctionIntegrity, kBasicScript, strlen(kBas
icScript), secureURL, insecureURL); | 433 expectIntegrity(kUnsupportedHashFunctionIntegrity, kBasicScript, strlen(kBas
icScript), secureURL, insecureURL); |
435 | 434 |
436 expectIntegrity(kSha256AndSha384Integrities, kBasicScript, strlen(kBasicScri
pt), secureURL, insecureURL); | 435 expectIntegrity(kSha256AndSha384Integrities, kBasicScript, strlen(kBasicScri
pt), secureURL, insecureURL); |
437 expectIntegrity(kBadSha256AndGoodSha384Integrities, kBasicScript, strlen(kBa
sicScript), secureURL, insecureURL); | 436 expectIntegrity(kBadSha256AndGoodSha384Integrities, kBasicScript, strlen(kBa
sicScript), secureURL, insecureURL); |
438 | 437 |
439 expectIntegrityFailure(kSha256Integrity, kBasicScript, strlen(kBasicScript),
secureURL, insecureURL, NoCors); | 438 expectIntegrityFailure(kSha256Integrity, kBasicScript, strlen(kBasicScript),
secureURL, insecureURL, NoCors); |
440 expectIntegrityFailure(kGoodSha256AndBadSha384Integrities, kBasicScript, str
len(kBasicScript), secureURL, insecureURL); | 439 expectIntegrityFailure(kGoodSha256AndBadSha384Integrities, kBasicScript, str
len(kBasicScript), secureURL, insecureURL); |
441 } | 440 } |
442 | 441 |
443 } // namespace blink | 442 } // namespace blink |
OLD | NEW |