mirror of
https://github.com/react/react-native-devtools-frontend.git
synced 2026-10-07 04:26:32 +08:00
[Cookies] Add isDomainMatch logic to cookies
Fixed: chromium:1012337 Change-Id: I07a696af66296d03392f97c656742c2a0e2e3bd3 Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/2656235 Commit-Queue: Jan Scheffler <janscheffler@chromium.org> Reviewed-by: Christian Dullweber <dullweber@chromium.org>
This commit is contained in:
committed by
Commit Bot
parent
4789c42897
commit
c670054fcb
@@ -219,6 +219,57 @@ export class Cookie {
|
||||
getCookieLine() {
|
||||
return this._cookieLine;
|
||||
}
|
||||
|
||||
/**
|
||||
* @param {string} securityOrigin
|
||||
* @returns {boolean}
|
||||
*/
|
||||
matchesSecurityOrigin(securityOrigin) {
|
||||
const hostname = new URL(securityOrigin).hostname;
|
||||
return Cookie.isDomainMatch(this.domain(), hostname);
|
||||
}
|
||||
|
||||
/**
|
||||
* @param {string} domain
|
||||
* @param {string} hostname
|
||||
* @returns {boolean}
|
||||
*/
|
||||
static isDomainMatch(domain, hostname) {
|
||||
// This implementation mirrors
|
||||
// https://source.chromium.org/search?q=net::cookie_util::IsDomainMatch()
|
||||
//
|
||||
// Can domain match in two ways; as a domain cookie (where the cookie
|
||||
// domain begins with ".") or as a host cookie (where it doesn't).
|
||||
|
||||
// Some consumers of the CookieMonster expect to set cookies on
|
||||
// URLs like http://.strange.url. To retrieve cookies in this instance,
|
||||
// we allow matching as a host cookie even when the domain_ starts with
|
||||
// a period.
|
||||
if (hostname === domain) {
|
||||
return true;
|
||||
}
|
||||
|
||||
// Domain cookie must have an initial ".". To match, it must be
|
||||
// equal to url's host with initial period removed, or a suffix of
|
||||
// it.
|
||||
|
||||
// Arguably this should only apply to "http" or "https" cookies, but
|
||||
// extension cookie tests currently use the funtionality, and if we
|
||||
// ever decide to implement that it should be done by preventing
|
||||
// such cookies from being set.
|
||||
if (!domain || domain[0] !== '.') {
|
||||
return false;
|
||||
}
|
||||
|
||||
// The host with a "." prefixed.
|
||||
if (domain.substr(1) === hostname) {
|
||||
return true;
|
||||
}
|
||||
|
||||
// A pure suffix of the host (ok since we know the domain already
|
||||
// starts with a ".")
|
||||
return hostname.length > domain.length && hostname.endsWith(domain);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
@@ -69,7 +69,7 @@ export class CookieModel extends SDKModel {
|
||||
const cookies = await this.getCookiesForDomain(domain || null);
|
||||
if (securityOrigin) {
|
||||
const cookiesToDelete = cookies.filter(cookie => {
|
||||
return securityOrigin.endsWith(cookie.domain());
|
||||
return cookie.matchesSecurityOrigin(securityOrigin);
|
||||
});
|
||||
await this.deleteCookies(cookiesToDelete);
|
||||
} else {
|
||||
|
||||
@@ -38,7 +38,6 @@ describe('The Application Tab', async () => {
|
||||
return data.length ? data : undefined;
|
||||
});
|
||||
|
||||
|
||||
assert.sameDeepMembers(dataGridRowValuesBefore, [
|
||||
{
|
||||
name: 'third_party',
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
document.cookie = 'foo=bar;path=/';
|
||||
document.cookie = 'foo2=bar;path=/';
|
||||
|
||||
// Load cross origin resource by switching the hostname to 127.0.0.1
|
||||
const url = new URL('./set-cookies.rawresponse', document.location);
|
||||
const image = new Image();
|
||||
image.src = url.toString().replace('localhost', '127.0.0.1');
|
||||
|
||||
@@ -0,0 +1,7 @@
|
||||
<!--
|
||||
Copyright 2021 The Chromium Authors. All rights reserved.
|
||||
Use of this source code is governed by a BSD-style license that can be
|
||||
found in the LICENSE file.
|
||||
-->
|
||||
<h1>OOP iframe</h1>
|
||||
<button>Button in OOP iframe</button>
|
||||
@@ -174,4 +174,19 @@ describeWithEnvironment('Cookie', () => {
|
||||
assertNotNull(expiresDate);
|
||||
assert.strictEqual(expiresDate.toISOString(), new Date(expires).toISOString());
|
||||
});
|
||||
|
||||
it('can check if a cookie domain matches a given host', () => {
|
||||
assert.isTrue(SDK.Cookie.Cookie.isDomainMatch('example.com', 'example.com'));
|
||||
assert.isFalse(SDK.Cookie.Cookie.isDomainMatch('www.example.com', 'example.com'));
|
||||
|
||||
assert.isTrue(SDK.Cookie.Cookie.isDomainMatch('.example.com', 'example.com'));
|
||||
assert.isTrue(SDK.Cookie.Cookie.isDomainMatch('.example.com', 'www.example.com'));
|
||||
assert.isFalse(SDK.Cookie.Cookie.isDomainMatch('.www.example.com', 'example.com'));
|
||||
|
||||
assert.isFalse(SDK.Cookie.Cookie.isDomainMatch('example.com', 'example.de'));
|
||||
assert.isFalse(SDK.Cookie.Cookie.isDomainMatch('.example.com', 'example.de'));
|
||||
assert.isFalse(SDK.Cookie.Cookie.isDomainMatch('.example.de', 'example.de.vu'));
|
||||
|
||||
assert.isFalse(SDK.Cookie.Cookie.isDomainMatch('example.com', 'notexample.com'));
|
||||
});
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user