mirror of
https://github.com/lexmount/moli.git
synced 2026-10-07 08:01:00 +00:00
fix(wpt-cross): model nosniff script fixture
This commit is contained in:
@@ -1246,6 +1246,24 @@ def _inspect_headers_response_headers(
|
||||
return response_headers
|
||||
|
||||
|
||||
def _nosniff_javascript_response(query: str) -> tuple[str | None, bytes]:
|
||||
"""Model fetch/nosniff/resources/js.py's MIME-controlled script body."""
|
||||
|
||||
params = parse_qsl(query, keep_blank_values=True)
|
||||
outcome = next(
|
||||
(value for name, value in params if name == "outcome"),
|
||||
"f",
|
||||
)
|
||||
content_type = next(
|
||||
(value for name, value in params if name == "type"),
|
||||
None,
|
||||
)
|
||||
type_label = content_type if content_type is not None else "Content-Type missing"
|
||||
result_call = "log('FAIL: " + type_label + "')" if outcome == "f" else "p()"
|
||||
body = ("// nothing to see here\n" + result_call).encode()
|
||||
return content_type, body
|
||||
|
||||
|
||||
def _url_host_literal(hostname: str) -> str:
|
||||
if hostname.startswith("[") and hostname.endswith("]"):
|
||||
return hostname
|
||||
@@ -2089,6 +2107,9 @@ def _make_handler(
|
||||
status_code=pipe_status_code or 200,
|
||||
)
|
||||
return
|
||||
if path == "/fetch/nosniff/resources/js.py":
|
||||
self._serve_nosniff_javascript(parsed.query, emit_body=emit_body)
|
||||
return
|
||||
if path == (
|
||||
"/html/semantics/scripting-1/the-script-element/module/"
|
||||
"resources/delayed-modulescript.py"
|
||||
@@ -2986,6 +3007,20 @@ def _make_handler(
|
||||
extra_headers=[("X-Request-Method", self.command)],
|
||||
)
|
||||
|
||||
def _serve_nosniff_javascript(self, query: str, *, emit_body: bool) -> None:
|
||||
content_type, body = _nosniff_javascript_response(query)
|
||||
self.send_response(200)
|
||||
self.send_header("X-Content-Type-Options", "nosniff")
|
||||
self.send_header("Content-Length", str(len(body)))
|
||||
if content_type is not None:
|
||||
self.send_header("Content-Type", content_type)
|
||||
self.end_headers()
|
||||
if emit_body:
|
||||
try:
|
||||
self.wfile.write(body)
|
||||
except (BrokenPipeError, ConnectionResetError):
|
||||
return
|
||||
|
||||
def _send_bytes(
|
||||
self,
|
||||
content_type: str | None,
|
||||
|
||||
@@ -124,8 +124,9 @@ from moli_benchmark.wpt_cross.server import (
|
||||
_inject_bench_report_bridge_config,
|
||||
_host_header_hostname,
|
||||
_headers_include,
|
||||
_normalize_harness_case_key,
|
||||
_inspect_headers_response_headers,
|
||||
_normalize_harness_case_key,
|
||||
_nosniff_javascript_response,
|
||||
_needs_wpt_template_substitution,
|
||||
_legacy_wpt_resource_alias,
|
||||
_pipe_response_header_operations,
|
||||
@@ -4174,6 +4175,55 @@ test(() => {}, "ok");
|
||||
"x-request-referer, x-request-origin",
|
||||
)
|
||||
|
||||
def test_fixture_server_models_fetch_nosniff_javascript_handler(self) -> None:
|
||||
self.assertEqual(
|
||||
_nosniff_javascript_response(""),
|
||||
(
|
||||
None,
|
||||
b"// nothing to see here\nlog('FAIL: Content-Type missing')",
|
||||
),
|
||||
)
|
||||
self.assertEqual(
|
||||
_nosniff_javascript_response("type=text%2Fjavascript&outcome=p"),
|
||||
("text/javascript", b"// nothing to see here\np()"),
|
||||
)
|
||||
|
||||
with tempfile.TemporaryDirectory() as root:
|
||||
root_path = Path(root)
|
||||
(root_path / "resources").mkdir()
|
||||
(root_path / "resources" / "testharness.js").write_text(
|
||||
"// testharness", encoding="utf-8"
|
||||
)
|
||||
with WptFixtureServer(root_path) as server:
|
||||
base_url = f"{server.base_url}/fetch/nosniff/resources/js.py"
|
||||
responses = []
|
||||
for query in (
|
||||
"",
|
||||
"?type=",
|
||||
"?type=text%2Fjavascript&outcome=p",
|
||||
):
|
||||
with urlopen(base_url + query, timeout=2) as response:
|
||||
responses.append(
|
||||
(
|
||||
response.headers.get("Content-Type"),
|
||||
response.headers["X-Content-Type-Options"],
|
||||
response.read(),
|
||||
)
|
||||
)
|
||||
|
||||
self.assertEqual(
|
||||
responses,
|
||||
[
|
||||
(
|
||||
None,
|
||||
"nosniff",
|
||||
b"// nothing to see here\nlog('FAIL: Content-Type missing')",
|
||||
),
|
||||
("", "nosniff", b"// nothing to see here\nlog('FAIL: ')"),
|
||||
("text/javascript", "nosniff", b"// nothing to see here\np()"),
|
||||
],
|
||||
)
|
||||
|
||||
def test_fixture_server_models_xhr_delay_py_methods(self) -> None:
|
||||
with tempfile.TemporaryDirectory() as root:
|
||||
root_path = Path(root)
|
||||
|
||||
Reference in New Issue
Block a user