Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(2770)

Unified Diff: chrome/browser/ssl/ssl_browser_tests.cc

Issue 2305093002: Fix incorrect SSL state being shown for client redirects. (Closed)
Patch Set: more tests Created 4 years, 3 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
« no previous file with comments | « no previous file | chrome/test/data/ssl/in_page_navigation_during_load.html » ('j') | no next file with comments »
Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
Index: chrome/browser/ssl/ssl_browser_tests.cc
diff --git a/chrome/browser/ssl/ssl_browser_tests.cc b/chrome/browser/ssl/ssl_browser_tests.cc
index a52145932ab7fe2ef322385709d0edcb4ae628b5..0a01826db958d604a1374a826974a7390f44338b 100644
--- a/chrome/browser/ssl/ssl_browser_tests.cc
+++ b/chrome/browser/ssl/ssl_browser_tests.cc
@@ -3198,6 +3198,75 @@ IN_PROC_BROWSER_TEST_F(SSLUITest, SamePageHasSSLState) {
CheckAuthenticatedState(tab, AuthState::NONE);
}
+// Checks that if a redirect occurs while the page is loading, the SSL state
+// reflects the final URL.
+IN_PROC_BROWSER_TEST_F(SSLUITest, ClientRedirectSSLState) {
+ ASSERT_TRUE(embedded_test_server()->Start());
+ ASSERT_TRUE(https_server_.Start());
+
+ GURL https_url = https_server_.GetURL("/ssl/redirect.html?");
+ GURL http_url = embedded_test_server()->GetURL("/ssl/google.html");
+
+ GURL url(https_url.spec() + http_url.spec());
+ ui_test_utils::NavigateToURLBlockUntilNavigationsComplete(browser(), url, 2);
+ WebContents* tab = browser()->tab_strip_model()->GetActiveWebContents();
+ CheckUnauthenticatedState(tab, AuthState::NONE);
+}
+
+// Checks that if a redirect occurs while the page is loading from a mixed
+// content to a valid HTTPS page, the SSL state reflects the final URL.
+IN_PROC_BROWSER_TEST_F(SSLUITest, ClientRedirectFromMixedContentSSLState) {
+ ASSERT_TRUE(https_server_.Start());
+
+ GURL url =
+ GURL(https_server_.GetURL("/ssl/redirect_with_mixed_content.html").spec()
+ + "?" +
+ https_server_.GetURL("/ssl/google.html").spec());
+
+ // Load a page that displays insecure content.
+ ui_test_utils::NavigateToURL(browser(), url);
+ WebContents* tab = browser()->tab_strip_model()->GetActiveWebContents();
+ CheckAuthenticatedState(tab, AuthState::NONE);
+}
+
+// Checks that if a redirect occurs while the page is loading from a valid HTTPS
+// page to a mixed content page, the SSL state reflects the final URL.
+IN_PROC_BROWSER_TEST_F(SSLUITest, ClientRedirectToMixedContentSSLState) {
+ ASSERT_TRUE(embedded_test_server()->Start());
+ ASSERT_TRUE(https_server_.Start());
+
+ GURL url =
+ GURL(https_server_.GetURL("/ssl/redirect.html").spec()
+ + "?" +
+ https_server_.GetURL("/ssl/page_displays_insecure_content.html").spec());
+
+ ui_test_utils::NavigateToURLBlockUntilNavigationsComplete(browser(), url, 2);
+ WebContents* tab = browser()->tab_strip_model()->GetActiveWebContents();
+ CheckAuthenticatedState(tab, AuthState::DISPLAYED_INSECURE_CONTENT);
+}
+
+// Checks that in-page navigations during page load preserves SSL state.
+IN_PROC_BROWSER_TEST_F(SSLUITest, InPageNavigationDuringLoadSSLState) {
+ ASSERT_TRUE(https_server_.Start());
+
+ ui_test_utils::NavigateToURL(
+ browser(),
+ https_server_.GetURL("/ssl/in_page_navigation_during_load.html"));
+ WebContents* tab = browser()->tab_strip_model()->GetActiveWebContents();
+ CheckAuthenticatedState(tab, AuthState::NONE);
+}
+
+// Checks that in-page navigations after the page load preserves SSL state.
+IN_PROC_BROWSER_TEST_F(SSLUITest, InPageNavigationAfterLoadSSLState) {
+ ASSERT_TRUE(https_server_.Start());
+
+ ui_test_utils::NavigateToURL(browser(),
+ https_server_.GetURL("/ssl/google.html"));
+ WebContents* tab = browser()->tab_strip_model()->GetActiveWebContents();
+ ASSERT_TRUE(content::ExecuteScript(tab, "location.hash = Math.random()"));
+ CheckAuthenticatedState(tab, AuthState::NONE);
+}
+
// TODO(jcampan): more tests to do below.
// Visit a page over https that contains a frame with a redirect.
« no previous file with comments | « no previous file | chrome/test/data/ssl/in_page_navigation_during_load.html » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698