[email protected] | aa84a7e | 2012-03-15 21:29:06 | [diff] [blame] | 1 | // Copyright (c) 2012 The Chromium Authors. All rights reserved. |
[email protected] | c145edad | 2009-11-18 02:14:27 | [diff] [blame] | 2 | // Use of this source code is governed by a BSD-style license that can be |
| 3 | // found in the LICENSE file. |
| 4 | |
[email protected] | 218aa6a1 | 2011-09-13 17:38:38 | [diff] [blame] | 5 | #include "base/bind.h" |
danakj | db9ae794 | 2020-11-11 16:01:35 | [diff] [blame] | 6 | #include "base/callback_helpers.h" |
avi | 6846aef | 2015-12-26 01:09:38 | [diff] [blame] | 7 | #include "base/macros.h" |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 8 | #include "base/path_service.h" |
Lei Zhang | fe5b8693 | 2019-02-01 17:26:59 | [diff] [blame] | 9 | #include "base/strings/stringprintf.h" |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 10 | #include "chrome/browser/content_settings/cookie_settings_factory.h" |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 11 | #include "chrome/browser/net/storage_test_utils.h" |
[email protected] | 8ecad5e | 2010-12-02 21:18:33 | [diff] [blame] | 12 | #include "chrome/browser/profiles/profile.h" |
[email protected] | 7b5dc00 | 2010-11-16 23:08:10 | [diff] [blame] | 13 | #include "chrome/browser/ui/browser.h" |
[email protected] | 59253a65 | 2012-11-20 00:17:26 | [diff] [blame] | 14 | #include "chrome/browser/ui/tabs/tab_strip_model.h" |
[email protected] | 30fde82 | 2011-10-28 09:49:05 | [diff] [blame] | 15 | #include "chrome/common/pref_names.h" |
[email protected] | af44e7fb | 2011-07-29 18:32:32 | [diff] [blame] | 16 | #include "chrome/test/base/in_process_browser_test.h" |
| 17 | #include "chrome/test/base/ui_test_utils.h" |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 18 | #include "components/content_settings/core/browser/cookie_settings.h" |
| 19 | #include "components/content_settings/core/common/features.h" |
droger | 8ff2b7e | 2015-06-26 16:30:02 | [diff] [blame] | 20 | #include "components/content_settings/core/common/pref_names.h" |
Christian Dullweber | 4a8afe2 | 2019-09-19 16:57:32 | [diff] [blame] | 21 | #include "components/network_session_configurator/common/network_switches.h" |
brettw | b1fc1b8 | 2016-02-02 00:19:08 | [diff] [blame] | 22 | #include "components/prefs/pref_service.h" |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 23 | #include "content/public/common/content_paths.h" |
Ayu Ishii | 6491a9a | 2020-03-27 21:43:55 | [diff] [blame] | 24 | #include "content/public/common/content_switches.h" |
Peter Kasting | 919ce65 | 2020-05-07 10:22:36 | [diff] [blame] | 25 | #include "content/public/test/browser_test.h" |
[email protected] | 88509ab | 2012-08-27 15:04:14 | [diff] [blame] | 26 | #include "content/public/test/browser_test_utils.h" |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 27 | #include "content/public/test/test_navigation_observer.h" |
[email protected] | f2cb3cf | 2013-03-21 01:40:53 | [diff] [blame] | 28 | #include "net/dns/mock_host_resolver.h" |
svaldez | e274587 | 2015-11-04 23:30:20 | [diff] [blame] | 29 | #include "net/test/embedded_test_server/embedded_test_server.h" |
Christian Dullweber | 8594631 | 2019-10-29 10:02:07 | [diff] [blame] | 30 | #include "ui/base/window_open_disposition.h" |
[email protected] | c145edad | 2009-11-18 02:14:27 | [diff] [blame] | 31 | |
[email protected] | 631bb74 | 2011-11-02 11:29:39 | [diff] [blame] | 32 | using content::BrowserThread; |
| 33 | |
[email protected] | 9eaa18e | 2010-06-29 20:51:01 | [diff] [blame] | 34 | namespace { |
| 35 | |
[email protected] | 9eaa18e | 2010-06-29 20:51:01 | [diff] [blame] | 36 | class CookiePolicyBrowserTest : public InProcessBrowserTest { |
| 37 | protected: |
Christian Dullweber | 4a8afe2 | 2019-09-19 16:57:32 | [diff] [blame] | 38 | CookiePolicyBrowserTest() |
| 39 | : https_server_(net::EmbeddedTestServer::TYPE_HTTPS) {} |
[email protected] | c145edad | 2009-11-18 02:14:27 | [diff] [blame] | 40 | |
jam | 1a5b558 | 2017-05-01 16:50:10 | [diff] [blame] | 41 | void SetUpOnMainThread() override { |
| 42 | host_resolver()->AddRule("*", "127.0.0.1"); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 43 | base::FilePath path; |
| 44 | base::PathService::Get(content::DIR_TEST_DATA, &path); |
Christian Dullweber | 4a8afe2 | 2019-09-19 16:57:32 | [diff] [blame] | 45 | https_server_.ServeFilesFromDirectory(path); |
| 46 | https_server_.AddDefaultHandlers(GetChromeTestDataDir()); |
| 47 | ASSERT_TRUE(https_server_.Start()); |
| 48 | } |
| 49 | |
| 50 | void SetUpCommandLine(base::CommandLine* command_line) override { |
| 51 | // HTTPS server only serves a valid cert for localhost, so this is needed |
| 52 | // to load pages from other hosts without an error. |
| 53 | command_line->AppendSwitch(switches::kIgnoreCertificateErrors); |
Ayu Ishii | 6491a9a | 2020-03-27 21:43:55 | [diff] [blame] | 54 | command_line->AppendSwitchASCII(switches::kEnableBlinkFeatures, |
| 55 | "CookieStoreDocument"); |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 56 | } |
| 57 | |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 58 | GURL GetURL(const std::string& host) { |
| 59 | GURL url(https_server_.GetURL(host, "/")); |
| 60 | return url; |
| 61 | } |
| 62 | |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 63 | void SetBlockThirdPartyCookies(bool value) { |
Christian Dullweber | 80e5f26 | 2020-08-25 13:25:22 | [diff] [blame] | 64 | browser()->profile()->GetPrefs()->SetInteger( |
| 65 | prefs::kCookieControlsMode, |
| 66 | static_cast<int>( |
| 67 | value ? content_settings::CookieControlsMode::kBlockThirdParty |
| 68 | : content_settings::CookieControlsMode::kOff)); |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 69 | } |
| 70 | |
| 71 | void NavigateToPageWithFrame(const std::string& host) { |
Christian Dullweber | 4a8afe2 | 2019-09-19 16:57:32 | [diff] [blame] | 72 | GURL main_url(https_server_.GetURL(host, "/iframe.html")); |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 73 | ui_test_utils::NavigateToURL(browser(), main_url); |
| 74 | } |
| 75 | |
Christian Dullweber | 8594631 | 2019-10-29 10:02:07 | [diff] [blame] | 76 | void NavigateToNewTabWithFrame(const std::string& host) { |
| 77 | GURL main_url(https_server_.GetURL(host, "/iframe.html")); |
| 78 | ui_test_utils::NavigateToURLWithDisposition( |
| 79 | browser(), main_url, WindowOpenDisposition::NEW_FOREGROUND_TAB, |
Fergal Daly | ffa9bba | 2020-01-27 23:45:02 | [diff] [blame] | 80 | ui_test_utils::BROWSER_TEST_WAIT_FOR_LOAD_STOP); |
Christian Dullweber | 8594631 | 2019-10-29 10:02:07 | [diff] [blame] | 81 | } |
| 82 | |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 83 | void NavigateFrameTo(const std::string& host, const std::string& path) { |
Christian Dullweber | 4a8afe2 | 2019-09-19 16:57:32 | [diff] [blame] | 84 | GURL page = https_server_.GetURL(host, path); |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 85 | content::WebContents* web_contents = |
| 86 | browser()->tab_strip_model()->GetActiveWebContents(); |
| 87 | EXPECT_TRUE(NavigateIframeToURL(web_contents, "test", page)); |
| 88 | } |
| 89 | |
| 90 | void ExpectFrameContent(const std::string& expected) { |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 91 | storage::test::ExpectFrameContent(GetFrame(), expected); |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 92 | } |
| 93 | |
| 94 | void NavigateNestedFrameTo(const std::string& host, const std::string& path) { |
Christian Dullweber | 4a8afe2 | 2019-09-19 16:57:32 | [diff] [blame] | 95 | GURL url(https_server_.GetURL(host, path)); |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 96 | content::WebContents* web_contents = |
| 97 | browser()->tab_strip_model()->GetActiveWebContents(); |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 98 | content::TestNavigationObserver load_observer(web_contents); |
| 99 | ASSERT_TRUE(ExecuteScript( |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 100 | GetFrame(), |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 101 | base::StringPrintf("document.body.querySelector('iframe').src = '%s';", |
| 102 | url.spec().c_str()))); |
| 103 | load_observer.Wait(); |
| 104 | } |
| 105 | |
| 106 | void ExpectNestedFrameContent(const std::string& expected) { |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 107 | storage::test::ExpectFrameContent(GetNestedFrame(), expected); |
Christian Dullweber | 8594631 | 2019-10-29 10:02:07 | [diff] [blame] | 108 | } |
| 109 | |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 110 | content::RenderFrameHost* GetFrame() { |
| 111 | content::WebContents* web_contents = |
| 112 | browser()->tab_strip_model()->GetActiveWebContents(); |
| 113 | return ChildFrameAt(web_contents->GetMainFrame(), 0); |
| 114 | } |
| 115 | |
| 116 | content::RenderFrameHost* GetNestedFrame() { |
| 117 | return ChildFrameAt(GetFrame(), 0); |
| 118 | } |
| 119 | |
Christian Dullweber | 4a8afe2 | 2019-09-19 16:57:32 | [diff] [blame] | 120 | protected: |
| 121 | net::test_server::EmbeddedTestServer https_server_; |
| 122 | |
[email protected] | c145edad | 2009-11-18 02:14:27 | [diff] [blame] | 123 | private: |
| 124 | DISALLOW_COPY_AND_ASSIGN(CookiePolicyBrowserTest); |
| 125 | }; |
| 126 | |
| 127 | // Visits a page that sets a first-party cookie. |
| 128 | IN_PROC_BROWSER_TEST_F(CookiePolicyBrowserTest, AllowFirstPartyCookies) { |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 129 | SetBlockThirdPartyCookies(false); |
[email protected] | c145edad | 2009-11-18 02:14:27 | [diff] [blame] | 130 | |
Christian Dullweber | 4a8afe2 | 2019-09-19 16:57:32 | [diff] [blame] | 131 | GURL url(https_server_.GetURL("/set-cookie?cookie1")); |
[email protected] | c145edad | 2009-11-18 02:14:27 | [diff] [blame] | 132 | |
[email protected] | 1f2469a | 2012-12-13 21:19:55 | [diff] [blame] | 133 | std::string cookie = content::GetCookies(browser()->profile(), url); |
[email protected] | c145edad | 2009-11-18 02:14:27 | [diff] [blame] | 134 | ASSERT_EQ("", cookie); |
| 135 | |
| 136 | ui_test_utils::NavigateToURL(browser(), url); |
| 137 | |
[email protected] | 1f2469a | 2012-12-13 21:19:55 | [diff] [blame] | 138 | cookie = content::GetCookies(browser()->profile(), url); |
[email protected] | c145edad | 2009-11-18 02:14:27 | [diff] [blame] | 139 | EXPECT_EQ("cookie1", cookie); |
| 140 | } |
| 141 | |
[email protected] | c145edad | 2009-11-18 02:14:27 | [diff] [blame] | 142 | // Visits a page that is a redirect across domain boundary to a page that sets |
| 143 | // a first-party cookie. |
| 144 | IN_PROC_BROWSER_TEST_F(CookiePolicyBrowserTest, |
| 145 | AllowFirstPartyCookiesRedirect) { |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 146 | SetBlockThirdPartyCookies(true); |
[email protected] | c145edad | 2009-11-18 02:14:27 | [diff] [blame] | 147 | |
Christian Dullweber | 4a8afe2 | 2019-09-19 16:57:32 | [diff] [blame] | 148 | GURL url(https_server_.GetURL("/server-redirect?")); |
| 149 | GURL redirected_url(https_server_.GetURL("/set-cookie?cookie2")); |
[email protected] | c145edad | 2009-11-18 02:14:27 | [diff] [blame] | 150 | |
[email protected] | 95409e1 | 2010-08-17 20:07:11 | [diff] [blame] | 151 | // Change the host name from 127.0.0.1 to www.example.com so it triggers |
[email protected] | c145edad | 2009-11-18 02:14:27 | [diff] [blame] | 152 | // third-party cookie blocking if the first party for cookies URL is not |
| 153 | // changed when we follow a redirect. |
[email protected] | 95409e1 | 2010-08-17 20:07:11 | [diff] [blame] | 154 | ASSERT_EQ("127.0.0.1", redirected_url.host()); |
[email protected] | c145edad | 2009-11-18 02:14:27 | [diff] [blame] | 155 | GURL::Replacements replacements; |
mgiuca | 77752c3 | 2015-02-05 07:31:18 | [diff] [blame] | 156 | replacements.SetHostStr("www.example.com"); |
[email protected] | c145edad | 2009-11-18 02:14:27 | [diff] [blame] | 157 | redirected_url = redirected_url.ReplaceComponents(replacements); |
| 158 | |
[email protected] | 1f2469a | 2012-12-13 21:19:55 | [diff] [blame] | 159 | std::string cookie = |
| 160 | content::GetCookies(browser()->profile(), redirected_url); |
[email protected] | c145edad | 2009-11-18 02:14:27 | [diff] [blame] | 161 | ASSERT_EQ("", cookie); |
| 162 | |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 163 | // This cookie can be set even if it is Lax-by-default because the redirect |
| 164 | // counts as a top-level navigation and therefore the context is lax. |
[email protected] | c145edad | 2009-11-18 02:14:27 | [diff] [blame] | 165 | ui_test_utils::NavigateToURL(browser(), |
| 166 | GURL(url.spec() + redirected_url.spec())); |
| 167 | |
[email protected] | 1f2469a | 2012-12-13 21:19:55 | [diff] [blame] | 168 | cookie = content::GetCookies(browser()->profile(), redirected_url); |
[email protected] | c145edad | 2009-11-18 02:14:27 | [diff] [blame] | 169 | EXPECT_EQ("cookie2", cookie); |
| 170 | } |
[email protected] | 9eaa18e | 2010-06-29 20:51:01 | [diff] [blame] | 171 | |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 172 | // Third-Party Frame Tests |
| 173 | IN_PROC_BROWSER_TEST_F(CookiePolicyBrowserTest, |
| 174 | ThirdPartyCookiesIFrameAllowSetting) { |
| 175 | SetBlockThirdPartyCookies(false); |
| 176 | |
| 177 | NavigateToPageWithFrame("a.com"); |
| 178 | |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 179 | storage::test::ExpectCookiesOnHost(browser()->profile(), GetURL("b.com"), ""); |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 180 | |
| 181 | // Navigate iframe to a cross-site, cookie-setting endpoint, and verify that |
| 182 | // the cookie is set: |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 183 | NavigateFrameTo("b.com", "/set-cookie?thirdparty=1;SameSite=None;Secure"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 184 | storage::test::ExpectCookiesOnHost(browser()->profile(), GetURL("b.com"), |
| 185 | "thirdparty=1"); |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 186 | |
| 187 | // Navigate iframe to a cross-site frame with a frame, and navigate _that_ |
| 188 | // frame to a cross-site, cookie-setting endpoint, and verify that the cookie |
| 189 | // is set: |
| 190 | NavigateFrameTo("b.com", "/iframe.html"); |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 191 | // Still need SameSite=None and Secure because the top-level is a.com so this |
| 192 | // is still cross-site. |
| 193 | NavigateNestedFrameTo("b.com", |
| 194 | "/set-cookie?thirdparty=2;SameSite=None;Secure"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 195 | storage::test::ExpectCookiesOnHost(browser()->profile(), GetURL("b.com"), |
| 196 | "thirdparty=2"); |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 197 | |
| 198 | // Navigate iframe to a cross-site frame with a frame, and navigate _that_ |
| 199 | // frame to a cross-site, cookie-setting endpoint, and verify that the cookie |
| 200 | // is set: |
| 201 | NavigateFrameTo("c.com", "/iframe.html"); |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 202 | NavigateNestedFrameTo("b.com", |
| 203 | "/set-cookie?thirdparty=3;SameSite=None;Secure"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 204 | storage::test::ExpectCookiesOnHost(browser()->profile(), GetURL("b.com"), |
| 205 | "thirdparty=3"); |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 206 | } |
| 207 | |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 208 | // This test does the same navigations as the test above, so we can be assured |
| 209 | // that the cookies are actually blocked because of the |
| 210 | // block-third-party-cookies setting, and not just because of SameSite or |
| 211 | // whatever. |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 212 | IN_PROC_BROWSER_TEST_F(CookiePolicyBrowserTest, |
| 213 | ThirdPartyCookiesIFrameBlockSetting) { |
| 214 | SetBlockThirdPartyCookies(true); |
| 215 | |
| 216 | NavigateToPageWithFrame("a.com"); |
| 217 | |
| 218 | // Navigate iframe to a cross-site, cookie-setting endpoint, and verify that |
| 219 | // the cookie is not set: |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 220 | NavigateFrameTo("b.com", "/set-cookie?thirdparty=1;SameSite=None;Secure"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 221 | storage::test::ExpectCookiesOnHost(browser()->profile(), GetURL("b.com"), ""); |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 222 | |
| 223 | // Navigate iframe to a cross-site frame with a frame, and navigate _that_ |
| 224 | // frame to a cross-site, cookie-setting endpoint, and verify that the cookie |
| 225 | // is not set: |
| 226 | NavigateFrameTo("b.com", "/iframe.html"); |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 227 | NavigateNestedFrameTo("b.com", |
| 228 | "/set-cookie?thirdparty=2;SameSite=None;Secure"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 229 | storage::test::ExpectCookiesOnHost(browser()->profile(), GetURL("b.com"), ""); |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 230 | |
| 231 | // Navigate iframe to a cross-site frame with a frame, and navigate _that_ |
| 232 | // frame to a cross-site, cookie-setting endpoint, and verify that the cookie |
| 233 | // is not set: |
| 234 | NavigateFrameTo("c.com", "/iframe.html"); |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 235 | NavigateNestedFrameTo("b.com", |
| 236 | "/set-cookie?thirdparty=3;SameSite=None;Secure"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 237 | storage::test::ExpectCookiesOnHost(browser()->profile(), GetURL("b.com"), ""); |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 238 | } |
| 239 | |
| 240 | IN_PROC_BROWSER_TEST_F(CookiePolicyBrowserTest, |
| 241 | ThirdPartyCookiesIFrameAllowReading) { |
| 242 | SetBlockThirdPartyCookies(false); |
| 243 | |
| 244 | // Set a cookie on `b.com`. |
Christian Dullweber | 4a8afe2 | 2019-09-19 16:57:32 | [diff] [blame] | 245 | content::SetCookie(browser()->profile(), https_server_.GetURL("b.com", "/"), |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 246 | "thirdparty=1;SameSite=None;Secure"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 247 | storage::test::ExpectCookiesOnHost(browser()->profile(), GetURL("b.com"), |
| 248 | "thirdparty=1"); |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 249 | |
| 250 | NavigateToPageWithFrame("a.com"); |
| 251 | |
| 252 | // Navigate iframe to a cross-site, cookie-reading endpoint, and verify that |
| 253 | // the cookie is sent: |
| 254 | NavigateFrameTo("b.com", "/echoheader?cookie"); |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 255 | ExpectFrameContent("thirdparty=1"); |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 256 | |
| 257 | // Navigate iframe to a cross-site frame with a frame, and navigate _that_ |
| 258 | // frame to a cross-site page that echos the cookie header, and verify that |
| 259 | // the cookie is sent: |
| 260 | NavigateFrameTo("b.com", "/iframe.html"); |
| 261 | NavigateNestedFrameTo("b.com", "/echoheader?cookie"); |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 262 | ExpectNestedFrameContent("thirdparty=1"); |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 263 | |
| 264 | // Navigate iframe to a cross-site frame with a frame, and navigate _that_ |
| 265 | // frame to a distinct cross-site page that echos the cookie header, and |
| 266 | // verify that the cookie is not sent: |
| 267 | NavigateFrameTo("c.com", "/iframe.html"); |
| 268 | NavigateNestedFrameTo("b.com", "/echoheader?cookie"); |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 269 | ExpectNestedFrameContent("thirdparty=1"); |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 270 | } |
| 271 | |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 272 | // This test does the same navigations as the test above, so we can be assured |
| 273 | // that the cookies are actually blocked because of the |
| 274 | // block-third-party-cookies setting, and not just because of SameSite or |
| 275 | // whatever. |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 276 | IN_PROC_BROWSER_TEST_F(CookiePolicyBrowserTest, |
| 277 | ThirdPartyCookiesIFrameBlockReading) { |
| 278 | SetBlockThirdPartyCookies(true); |
| 279 | |
| 280 | // Set a cookie on `b.com`. |
Christian Dullweber | 4a8afe2 | 2019-09-19 16:57:32 | [diff] [blame] | 281 | content::SetCookie(browser()->profile(), https_server_.GetURL("b.com", "/"), |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 282 | "thirdparty=1;SameSite=None;Secure"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 283 | storage::test::ExpectCookiesOnHost(browser()->profile(), GetURL("b.com"), |
| 284 | "thirdparty=1"); |
Mike West | dd5cc63 | 2018-09-07 17:44:23 | [diff] [blame] | 285 | |
| 286 | NavigateToPageWithFrame("a.com"); |
| 287 | |
| 288 | // Navigate iframe to a cross-site, cookie-reading endpoint, and verify that |
| 289 | // the cookie is not sent: |
| 290 | NavigateFrameTo("b.com", "/echoheader?cookie"); |
| 291 | ExpectFrameContent("None"); |
| 292 | |
| 293 | // Navigate iframe to a cross-site frame with a frame, and navigate _that_ |
| 294 | // frame to a cross-site page that echos the cookie header, and verify that |
| 295 | // the cookie is not sent: |
| 296 | NavigateFrameTo("b.com", "/iframe.html"); |
| 297 | NavigateNestedFrameTo("b.com", "/echoheader?cookie"); |
| 298 | ExpectNestedFrameContent("None"); |
| 299 | |
| 300 | // Navigate iframe to a cross-site frame with a frame, and navigate _that_ |
| 301 | // frame to a distinct cross-site page that echos the cookie header, and |
| 302 | // verify that the cookie is not sent: |
| 303 | NavigateFrameTo("c.com", "/iframe.html"); |
| 304 | NavigateNestedFrameTo("b.com", "/echoheader?cookie"); |
| 305 | ExpectNestedFrameContent("None"); |
| 306 | } |
| 307 | |
Christian Dullweber | 7ee0708 | 2019-10-15 08:13:37 | [diff] [blame] | 308 | IN_PROC_BROWSER_TEST_F(CookiePolicyBrowserTest, |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 309 | ThirdPartyCookiesIFrameExceptions) { |
| 310 | SetBlockThirdPartyCookies(true); |
| 311 | |
| 312 | // Set a cookie on `b.com`. |
Christian Dullweber | 4a8afe2 | 2019-09-19 16:57:32 | [diff] [blame] | 313 | content::SetCookie(browser()->profile(), https_server_.GetURL("b.com", "/"), |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 314 | "thirdparty=1;SameSite=None;Secure"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 315 | storage::test::ExpectCookiesOnHost(browser()->profile(), GetURL("b.com"), |
| 316 | "thirdparty=1"); |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 317 | |
| 318 | // Set a cookie on othersite.com. |
| 319 | content::SetCookie(browser()->profile(), |
| 320 | https_server_.GetURL("othersite.com", "/"), |
| 321 | "thirdparty=other;SameSite=None;Secure"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 322 | storage::test::ExpectCookiesOnHost( |
| 323 | browser()->profile(), GetURL("othersite.com"), "thirdparty=other"); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 324 | |
| 325 | // Allow all requests to b.com to have cookies. |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 326 | // On the other hand, othersite.com does not have an exception set for it. |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 327 | auto cookie_settings = |
| 328 | CookieSettingsFactory::GetForProfile(browser()->profile()); |
Christian Dullweber | 4a8afe2 | 2019-09-19 16:57:32 | [diff] [blame] | 329 | GURL url = https_server_.GetURL("b.com", "/"); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 330 | cookie_settings->SetCookieSetting(url, ContentSetting::CONTENT_SETTING_ALLOW); |
| 331 | |
| 332 | NavigateToPageWithFrame("a.com"); |
| 333 | |
| 334 | // Navigate iframe to a cross-site, cookie-reading endpoint, and verify that |
| 335 | // the cookie is sent: |
| 336 | NavigateFrameTo("b.com", "/echoheader?cookie"); |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 337 | ExpectFrameContent("thirdparty=1"); |
| 338 | // Navigate iframe to othersite.com and verify that the cookie is not sent. |
| 339 | NavigateFrameTo("othersite.com", "/echoheader?cookie"); |
| 340 | ExpectFrameContent("None"); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 341 | |
| 342 | // Navigate iframe to a cross-site frame with a frame, and navigate _that_ |
| 343 | // frame to a cross-site page that echos the cookie header, and verify that |
| 344 | // the cookie is sent: |
| 345 | NavigateFrameTo("b.com", "/iframe.html"); |
| 346 | NavigateNestedFrameTo("b.com", "/echoheader?cookie"); |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 347 | ExpectNestedFrameContent("thirdparty=1"); |
| 348 | // Navigate nested iframe to othersite.com and verify that the cookie is not |
| 349 | // sent. |
| 350 | NavigateNestedFrameTo("othersite.com", "/echoheader?cookie"); |
| 351 | ExpectNestedFrameContent("None"); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 352 | |
| 353 | // Navigate iframe to a cross-site frame with a frame, and navigate _that_ |
| 354 | // frame to a distinct cross-site page that echos the cookie header, and |
| 355 | // verify that the cookie is sent: |
| 356 | NavigateFrameTo("c.com", "/iframe.html"); |
| 357 | NavigateNestedFrameTo("b.com", "/echoheader?cookie"); |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 358 | ExpectNestedFrameContent("thirdparty=1"); |
| 359 | // Navigate nested iframe to othersite.com and verify that the cookie is not |
| 360 | // sent. |
| 361 | NavigateNestedFrameTo("othersite.com", "/echoheader?cookie"); |
| 362 | ExpectNestedFrameContent("None"); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 363 | } |
| 364 | |
Christian Dullweber | 7ee0708 | 2019-10-15 08:13:37 | [diff] [blame] | 365 | IN_PROC_BROWSER_TEST_F(CookiePolicyBrowserTest, |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 366 | ThirdPartyCookiesIFrameThirdPartyExceptions) { |
| 367 | SetBlockThirdPartyCookies(true); |
| 368 | |
| 369 | // Set a cookie on `b.com`. |
Christian Dullweber | 4a8afe2 | 2019-09-19 16:57:32 | [diff] [blame] | 370 | content::SetCookie(browser()->profile(), https_server_.GetURL("b.com", "/"), |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 371 | "thirdparty=1;SameSite=None;Secure"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 372 | storage::test::ExpectCookiesOnHost(browser()->profile(), GetURL("b.com"), |
| 373 | "thirdparty=1"); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 374 | |
| 375 | // Allow all requests on the top frame domain a.com to have cookies. |
| 376 | auto cookie_settings = |
| 377 | CookieSettingsFactory::GetForProfile(browser()->profile()); |
Christian Dullweber | 4a8afe2 | 2019-09-19 16:57:32 | [diff] [blame] | 378 | GURL url = https_server_.GetURL("a.com", "/"); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 379 | cookie_settings->SetThirdPartyCookieSetting( |
| 380 | url, ContentSetting::CONTENT_SETTING_ALLOW); |
| 381 | |
| 382 | NavigateToPageWithFrame("a.com"); |
| 383 | |
| 384 | // Navigate iframe to a cross-site, cookie-reading endpoint, and verify that |
| 385 | // the cookie is sent: |
| 386 | NavigateFrameTo("b.com", "/echoheader?cookie"); |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 387 | ExpectFrameContent("thirdparty=1"); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 388 | |
| 389 | // Navigate iframe to a cross-site frame with a frame, and navigate _that_ |
| 390 | // frame to a cross-site page that echos the cookie header, and verify that |
| 391 | // the cookie is sent: |
| 392 | NavigateFrameTo("b.com", "/iframe.html"); |
| 393 | NavigateNestedFrameTo("b.com", "/echoheader?cookie"); |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 394 | ExpectNestedFrameContent("thirdparty=1"); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 395 | |
| 396 | // Navigate iframe to a cross-site frame with a frame, and navigate _that_ |
| 397 | // frame to a distinct cross-site page that echos the cookie header, and |
| 398 | // verify that the cookie is sent: |
| 399 | NavigateFrameTo("c.com", "/iframe.html"); |
| 400 | NavigateNestedFrameTo("b.com", "/echoheader?cookie"); |
Lily Chen | 52a72af | 2019-10-23 15:37:11 | [diff] [blame] | 401 | ExpectNestedFrameContent("thirdparty=1"); |
| 402 | |
| 403 | // Now repeat the above with a dfiferent top frame site, which does not have |
| 404 | // an exception set for it. |
| 405 | NavigateToPageWithFrame("othersite.com"); |
| 406 | |
| 407 | // Navigate iframe to a cross-site, cookie-reading endpoint, and verify that |
| 408 | // the cookie is not sent: |
| 409 | NavigateFrameTo("b.com", "/echoheader?cookie"); |
| 410 | ExpectFrameContent("None"); |
| 411 | |
| 412 | // Navigate iframe to a cross-site frame with a frame, and navigate _that_ |
| 413 | // frame to a cross-site page that echos the cookie header, and verify that |
| 414 | // the cookie is not sent: |
| 415 | NavigateFrameTo("b.com", "/iframe.html"); |
| 416 | NavigateNestedFrameTo("b.com", "/echoheader?cookie"); |
| 417 | ExpectNestedFrameContent("None"); |
| 418 | |
| 419 | // Navigate iframe to a cross-site frame with a frame, and navigate _that_ |
| 420 | // frame to a distinct cross-site page that echos the cookie header, and |
| 421 | // verify that the cookie is not sent: |
| 422 | NavigateFrameTo("c.com", "/iframe.html"); |
| 423 | NavigateNestedFrameTo("b.com", "/echoheader?cookie"); |
| 424 | ExpectNestedFrameContent("None"); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 425 | } |
| 426 | |
Christian Dullweber | 7ee0708 | 2019-10-15 08:13:37 | [diff] [blame] | 427 | IN_PROC_BROWSER_TEST_F(CookiePolicyBrowserTest, ThirdPartyIFrameStorage) { |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 428 | NavigateToPageWithFrame("a.com"); |
| 429 | NavigateFrameTo("b.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 430 | storage::test::ExpectStorageForFrame(GetFrame(), false); |
| 431 | storage::test::SetStorageForFrame(GetFrame()); |
| 432 | storage::test::ExpectStorageForFrame(GetFrame(), true); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 433 | |
| 434 | SetBlockThirdPartyCookies(true); |
| 435 | |
| 436 | NavigateToPageWithFrame("a.com"); |
| 437 | NavigateFrameTo("b.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 438 | storage::test::ExpectStorageForFrame(GetFrame(), false); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 439 | |
| 440 | // Allow all requests to b.com to access storage. |
| 441 | auto cookie_settings = |
| 442 | CookieSettingsFactory::GetForProfile(browser()->profile()); |
Christian Dullweber | 4a8afe2 | 2019-09-19 16:57:32 | [diff] [blame] | 443 | GURL a_url = https_server_.GetURL("a.com", "/"); |
| 444 | GURL b_url = https_server_.GetURL("b.com", "/"); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 445 | cookie_settings->SetCookieSetting(b_url, |
| 446 | ContentSetting::CONTENT_SETTING_ALLOW); |
| 447 | |
| 448 | NavigateToPageWithFrame("a.com"); |
| 449 | NavigateFrameTo("b.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 450 | storage::test::ExpectStorageForFrame(GetFrame(), true); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 451 | |
| 452 | // Remove ALLOW setting. |
| 453 | cookie_settings->ResetCookieSetting(b_url); |
| 454 | |
| 455 | NavigateToPageWithFrame("a.com"); |
| 456 | NavigateFrameTo("b.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 457 | storage::test::ExpectStorageForFrame(GetFrame(), false); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 458 | |
| 459 | // Allow all third-parties on a.com to access storage. |
| 460 | cookie_settings->SetThirdPartyCookieSetting( |
| 461 | a_url, ContentSetting::CONTENT_SETTING_ALLOW); |
| 462 | |
| 463 | NavigateToPageWithFrame("a.com"); |
| 464 | NavigateFrameTo("b.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 465 | storage::test::ExpectStorageForFrame(GetFrame(), true); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 466 | } |
| 467 | |
Christian Dullweber | 7ee0708 | 2019-10-15 08:13:37 | [diff] [blame] | 468 | IN_PROC_BROWSER_TEST_F(CookiePolicyBrowserTest, NestedThirdPartyIFrameStorage) { |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 469 | NavigateToPageWithFrame("a.com"); |
| 470 | NavigateFrameTo("b.com", "/iframe.html"); |
| 471 | NavigateNestedFrameTo("c.com", "/browsing_data/site_data.html"); |
| 472 | |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 473 | storage::test::ExpectStorageForFrame(GetNestedFrame(), false); |
| 474 | storage::test::SetStorageForFrame(GetNestedFrame()); |
| 475 | storage::test::ExpectStorageForFrame(GetNestedFrame(), true); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 476 | |
| 477 | SetBlockThirdPartyCookies(true); |
| 478 | |
| 479 | NavigateToPageWithFrame("a.com"); |
| 480 | NavigateFrameTo("b.com", "/iframe.html"); |
| 481 | NavigateNestedFrameTo("c.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 482 | storage::test::ExpectStorageForFrame(GetNestedFrame(), false); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 483 | |
| 484 | // Allow all requests to b.com to access storage. |
| 485 | auto cookie_settings = |
| 486 | CookieSettingsFactory::GetForProfile(browser()->profile()); |
Christian Dullweber | 4a8afe2 | 2019-09-19 16:57:32 | [diff] [blame] | 487 | GURL a_url = https_server_.GetURL("a.com", "/"); |
| 488 | GURL c_url = https_server_.GetURL("c.com", "/"); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 489 | cookie_settings->SetCookieSetting(c_url, |
| 490 | ContentSetting::CONTENT_SETTING_ALLOW); |
| 491 | |
| 492 | NavigateToPageWithFrame("a.com"); |
| 493 | NavigateFrameTo("b.com", "/iframe.html"); |
| 494 | NavigateNestedFrameTo("c.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 495 | storage::test::ExpectStorageForFrame(GetNestedFrame(), true); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 496 | |
| 497 | // Remove ALLOW setting. |
| 498 | cookie_settings->ResetCookieSetting(c_url); |
| 499 | |
| 500 | NavigateToPageWithFrame("a.com"); |
| 501 | NavigateFrameTo("b.com", "/iframe.html"); |
| 502 | NavigateNestedFrameTo("c.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 503 | storage::test::ExpectStorageForFrame(GetNestedFrame(), false); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 504 | |
| 505 | // Allow all third-parties on a.com to access storage. |
| 506 | cookie_settings->SetThirdPartyCookieSetting( |
| 507 | a_url, ContentSetting::CONTENT_SETTING_ALLOW); |
| 508 | |
| 509 | NavigateToPageWithFrame("a.com"); |
| 510 | NavigateFrameTo("b.com", "/iframe.html"); |
| 511 | NavigateNestedFrameTo("c.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 512 | storage::test::ExpectStorageForFrame(GetNestedFrame(), true); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 513 | } |
| 514 | |
Christian Dullweber | 7ee0708 | 2019-10-15 08:13:37 | [diff] [blame] | 515 | IN_PROC_BROWSER_TEST_F(CookiePolicyBrowserTest, NestedFirstPartyIFrameStorage) { |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 516 | NavigateToPageWithFrame("a.com"); |
| 517 | NavigateFrameTo("b.com", "/iframe.html"); |
| 518 | NavigateNestedFrameTo("a.com", "/browsing_data/site_data.html"); |
| 519 | |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 520 | storage::test::ExpectStorageForFrame(GetNestedFrame(), false); |
| 521 | storage::test::SetStorageForFrame(GetNestedFrame()); |
| 522 | storage::test::ExpectStorageForFrame(GetNestedFrame(), true); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 523 | |
| 524 | SetBlockThirdPartyCookies(true); |
| 525 | |
| 526 | NavigateToPageWithFrame("a.com"); |
| 527 | NavigateFrameTo("b.com", "/iframe.html"); |
| 528 | NavigateNestedFrameTo("a.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 529 | storage::test::ExpectStorageForFrame(GetNestedFrame(), false); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 530 | |
| 531 | // Allow all requests to b.com to access storage. |
| 532 | auto cookie_settings = |
| 533 | CookieSettingsFactory::GetForProfile(browser()->profile()); |
Christian Dullweber | 4a8afe2 | 2019-09-19 16:57:32 | [diff] [blame] | 534 | GURL a_url = https_server_.GetURL("a.com", "/"); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 535 | cookie_settings->SetCookieSetting(a_url, |
| 536 | ContentSetting::CONTENT_SETTING_ALLOW); |
| 537 | |
| 538 | NavigateToPageWithFrame("a.com"); |
| 539 | NavigateFrameTo("b.com", "/iframe.html"); |
| 540 | NavigateNestedFrameTo("a.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 541 | storage::test::ExpectStorageForFrame(GetNestedFrame(), true); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 542 | |
| 543 | // Remove ALLOW setting. |
| 544 | cookie_settings->ResetCookieSetting(a_url); |
| 545 | |
| 546 | NavigateToPageWithFrame("a.com"); |
| 547 | NavigateFrameTo("b.com", "/iframe.html"); |
| 548 | NavigateNestedFrameTo("a.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 549 | storage::test::ExpectStorageForFrame(GetNestedFrame(), false); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 550 | |
| 551 | // Allow all third-parties on a.com to access storage. |
| 552 | cookie_settings->SetThirdPartyCookieSetting( |
| 553 | a_url, ContentSetting::CONTENT_SETTING_ALLOW); |
| 554 | |
| 555 | NavigateToPageWithFrame("a.com"); |
| 556 | NavigateFrameTo("b.com", "/iframe.html"); |
| 557 | NavigateNestedFrameTo("a.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 558 | storage::test::ExpectStorageForFrame(GetNestedFrame(), true); |
Christian Dullweber | 10d62c1 | 2019-08-19 12:08:19 | [diff] [blame] | 559 | } |
| 560 | |
Christian Dullweber | 8594631 | 2019-10-29 10:02:07 | [diff] [blame] | 561 | // Test third-party cookie blocking of features that allow to communicate |
| 562 | // between tabs such as SharedWorkers. |
| 563 | IN_PROC_BROWSER_TEST_F(CookiePolicyBrowserTest, MultiTabTest) { |
| 564 | NavigateToPageWithFrame("a.com"); |
| 565 | NavigateFrameTo("b.com", "/browsing_data/site_data.html"); |
| 566 | |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 567 | storage::test::ExpectCrossTabInfoForFrame(GetFrame(), false); |
| 568 | storage::test::SetCrossTabInfoForFrame(GetFrame()); |
| 569 | storage::test::ExpectCrossTabInfoForFrame(GetFrame(), true); |
Christian Dullweber | 8594631 | 2019-10-29 10:02:07 | [diff] [blame] | 570 | |
| 571 | // Create a second tab to test communication between tabs. |
| 572 | NavigateToNewTabWithFrame("a.com"); |
| 573 | NavigateFrameTo("b.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 574 | storage::test::ExpectCrossTabInfoForFrame(GetFrame(), true); |
Christian Dullweber | 8594631 | 2019-10-29 10:02:07 | [diff] [blame] | 575 | |
| 576 | SetBlockThirdPartyCookies(true); |
| 577 | |
| 578 | NavigateToPageWithFrame("a.com"); |
| 579 | NavigateFrameTo("b.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 580 | storage::test::ExpectCrossTabInfoForFrame(GetFrame(), false); |
Christian Dullweber | 8594631 | 2019-10-29 10:02:07 | [diff] [blame] | 581 | |
| 582 | // Allow all requests to b.com to access cookies. |
| 583 | auto cookie_settings = |
| 584 | CookieSettingsFactory::GetForProfile(browser()->profile()); |
| 585 | GURL a_url = https_server_.GetURL("a.com", "/"); |
| 586 | GURL b_url = https_server_.GetURL("b.com", "/"); |
| 587 | cookie_settings->SetCookieSetting(b_url, |
| 588 | ContentSetting::CONTENT_SETTING_ALLOW); |
| 589 | |
| 590 | NavigateToPageWithFrame("a.com"); |
| 591 | NavigateFrameTo("b.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 592 | storage::test::ExpectCrossTabInfoForFrame(GetFrame(), true); |
Christian Dullweber | 8594631 | 2019-10-29 10:02:07 | [diff] [blame] | 593 | |
| 594 | // Remove ALLOW setting. |
| 595 | cookie_settings->ResetCookieSetting(b_url); |
| 596 | |
| 597 | NavigateToPageWithFrame("a.com"); |
| 598 | NavigateFrameTo("b.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 599 | storage::test::ExpectCrossTabInfoForFrame(GetFrame(), false); |
Christian Dullweber | 8594631 | 2019-10-29 10:02:07 | [diff] [blame] | 600 | |
| 601 | // Allow all third-parties on a.com to access cookies. |
| 602 | cookie_settings->SetThirdPartyCookieSetting( |
| 603 | a_url, ContentSetting::CONTENT_SETTING_ALLOW); |
| 604 | |
| 605 | NavigateToPageWithFrame("a.com"); |
| 606 | NavigateFrameTo("b.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 607 | storage::test::ExpectCrossTabInfoForFrame(GetFrame(), true); |
Christian Dullweber | 8594631 | 2019-10-29 10:02:07 | [diff] [blame] | 608 | } |
| 609 | |
| 610 | // Same as MultiTabTest but with a nested frame on a.com inside a b.com frame. |
| 611 | // The a.com frame should be treated as third-party although it matches the |
| 612 | // top-frame-origin. |
| 613 | IN_PROC_BROWSER_TEST_F(CookiePolicyBrowserTest, MultiTabNestedTest) { |
| 614 | NavigateToPageWithFrame("a.com"); |
| 615 | NavigateFrameTo("b.com", "/iframe.html"); |
| 616 | NavigateNestedFrameTo("a.com", "/browsing_data/site_data.html"); |
| 617 | |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 618 | storage::test::ExpectCrossTabInfoForFrame(GetNestedFrame(), false); |
| 619 | storage::test::SetCrossTabInfoForFrame(GetNestedFrame()); |
| 620 | storage::test::ExpectCrossTabInfoForFrame(GetNestedFrame(), true); |
Christian Dullweber | 8594631 | 2019-10-29 10:02:07 | [diff] [blame] | 621 | |
| 622 | // Create a second tab to test communication between tabs. |
| 623 | NavigateToNewTabWithFrame("a.com"); |
| 624 | NavigateFrameTo("b.com", "/iframe.html"); |
| 625 | NavigateNestedFrameTo("a.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 626 | storage::test::ExpectCrossTabInfoForFrame(GetNestedFrame(), true); |
Christian Dullweber | 8594631 | 2019-10-29 10:02:07 | [diff] [blame] | 627 | |
| 628 | SetBlockThirdPartyCookies(true); |
| 629 | |
| 630 | NavigateToPageWithFrame("a.com"); |
| 631 | NavigateFrameTo("b.com", "/iframe.html"); |
| 632 | NavigateNestedFrameTo("a.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 633 | storage::test::ExpectCrossTabInfoForFrame(GetNestedFrame(), false); |
Christian Dullweber | 8594631 | 2019-10-29 10:02:07 | [diff] [blame] | 634 | |
| 635 | // Allow all requests to a.com to access cookies. |
| 636 | auto cookie_settings = |
| 637 | CookieSettingsFactory::GetForProfile(browser()->profile()); |
| 638 | GURL a_url = https_server_.GetURL("a.com", "/"); |
| 639 | cookie_settings->SetCookieSetting(a_url, |
| 640 | ContentSetting::CONTENT_SETTING_ALLOW); |
| 641 | |
| 642 | NavigateToPageWithFrame("a.com"); |
| 643 | NavigateFrameTo("b.com", "/iframe.html"); |
| 644 | NavigateNestedFrameTo("a.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 645 | storage::test::ExpectCrossTabInfoForFrame(GetNestedFrame(), true); |
Christian Dullweber | 8594631 | 2019-10-29 10:02:07 | [diff] [blame] | 646 | |
| 647 | // Remove ALLOW setting. |
| 648 | cookie_settings->ResetCookieSetting(a_url); |
| 649 | |
| 650 | NavigateToPageWithFrame("a.com"); |
| 651 | NavigateFrameTo("b.com", "/iframe.html"); |
| 652 | NavigateNestedFrameTo("a.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 653 | storage::test::ExpectCrossTabInfoForFrame(GetNestedFrame(), false); |
Christian Dullweber | 8594631 | 2019-10-29 10:02:07 | [diff] [blame] | 654 | |
| 655 | // Allow all third-parties on a.com to access cookies. |
| 656 | cookie_settings->SetThirdPartyCookieSetting( |
| 657 | a_url, ContentSetting::CONTENT_SETTING_ALLOW); |
| 658 | |
| 659 | NavigateToPageWithFrame("a.com"); |
| 660 | NavigateFrameTo("b.com", "/iframe.html"); |
| 661 | NavigateNestedFrameTo("a.com", "/browsing_data/site_data.html"); |
Brandon Maslen | 6134c85 | 2020-05-18 21:45:21 | [diff] [blame] | 662 | storage::test::ExpectCrossTabInfoForFrame(GetNestedFrame(), true); |
Christian Dullweber | 8594631 | 2019-10-29 10:02:07 | [diff] [blame] | 663 | } |
| 664 | |
[email protected] | 9eaa18e | 2010-06-29 20:51:01 | [diff] [blame] | 665 | } // namespace |