[Cookies] Add isDomainMatch logic to cookies

Fixed: chromium:1012337
Change-Id: I07a696af66296d03392f97c656742c2a0e2e3bd3
Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/2656235
Commit-Queue: Jan Scheffler <janscheffler@chromium.org>
Reviewed-by: Christian Dullweber <dullweber@chromium.org>
This commit is contained in:
Jan Scheffler
2021-01-29 15:28:03 +00:00
committed by Commit Bot
parent 4789c42897
commit c670054fcb
6 changed files with 75 additions and 2 deletions
+51
View File
@@ -219,6 +219,57 @@ export class Cookie {
getCookieLine() {
return this._cookieLine;
}
/**
* @param {string} securityOrigin
* @returns {boolean}
*/
matchesSecurityOrigin(securityOrigin) {
const hostname = new URL(securityOrigin).hostname;
return Cookie.isDomainMatch(this.domain(), hostname);
}
/**
* @param {string} domain
* @param {string} hostname
* @returns {boolean}
*/
static isDomainMatch(domain, hostname) {
// This implementation mirrors
// https://source.chromium.org/search?q=net::cookie_util::IsDomainMatch()
//
// Can domain match in two ways; as a domain cookie (where the cookie
// domain begins with ".") or as a host cookie (where it doesn't).
// Some consumers of the CookieMonster expect to set cookies on
// URLs like http://.strange.url. To retrieve cookies in this instance,
// we allow matching as a host cookie even when the domain_ starts with
// a period.
if (hostname === domain) {
return true;
}
// Domain cookie must have an initial ".". To match, it must be
// equal to url's host with initial period removed, or a suffix of
// it.
// Arguably this should only apply to "http" or "https" cookies, but
// extension cookie tests currently use the funtionality, and if we
// ever decide to implement that it should be done by preventing
// such cookies from being set.
if (!domain || domain[0] !== '.') {
return false;
}
// The host with a "." prefixed.
if (domain.substr(1) === hostname) {
return true;
}
// A pure suffix of the host (ok since we know the domain already
// starts with a ".")
return hostname.length > domain.length && hostname.endsWith(domain);
}
}
/**
+1 -1
View File
@@ -69,7 +69,7 @@ export class CookieModel extends SDKModel {
const cookies = await this.getCookiesForDomain(domain || null);
if (securityOrigin) {
const cookiesToDelete = cookies.filter(cookie => {
return securityOrigin.endsWith(cookie.domain());
return cookie.matchesSecurityOrigin(securityOrigin);
});
await this.deleteCookies(cookiesToDelete);
} else {
-1
View File
@@ -38,7 +38,6 @@ describe('The Application Tab', async () => {
return data.length ? data : undefined;
});
assert.sameDeepMembers(dataGridRowValuesBefore, [
{
name: 'third_party',
@@ -7,6 +7,7 @@
document.cookie = 'foo=bar;path=/';
document.cookie = 'foo2=bar;path=/';
// Load cross origin resource by switching the hostname to 127.0.0.1
const url = new URL('./set-cookies.rawresponse', document.location);
const image = new Image();
image.src = url.toString().replace('localhost', '127.0.0.1');
@@ -0,0 +1,7 @@
<!--
Copyright 2021 The Chromium Authors. All rights reserved.
Use of this source code is governed by a BSD-style license that can be
found in the LICENSE file.
-->
<h1>OOP iframe</h1>
<button>Button in OOP iframe</button>
@@ -174,4 +174,19 @@ describeWithEnvironment('Cookie', () => {
assertNotNull(expiresDate);
assert.strictEqual(expiresDate.toISOString(), new Date(expires).toISOString());
});
it('can check if a cookie domain matches a given host', () => {
assert.isTrue(SDK.Cookie.Cookie.isDomainMatch('example.com', 'example.com'));
assert.isFalse(SDK.Cookie.Cookie.isDomainMatch('www.example.com', 'example.com'));
assert.isTrue(SDK.Cookie.Cookie.isDomainMatch('.example.com', 'example.com'));
assert.isTrue(SDK.Cookie.Cookie.isDomainMatch('.example.com', 'www.example.com'));
assert.isFalse(SDK.Cookie.Cookie.isDomainMatch('.www.example.com', 'example.com'));
assert.isFalse(SDK.Cookie.Cookie.isDomainMatch('example.com', 'example.de'));
assert.isFalse(SDK.Cookie.Cookie.isDomainMatch('.example.com', 'example.de'));
assert.isFalse(SDK.Cookie.Cookie.isDomainMatch('.example.de', 'example.de.vu'));
assert.isFalse(SDK.Cookie.Cookie.isDomainMatch('example.com', 'notexample.com'));
});
});