diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-09-30 13:22:17 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-09-30 13:22:17 +0200 |
| commit | f211a13dc2e5dd82eaba49222171d6f29d858eb5 (patch) | |
| tree | 222b9d55116179e35c3013239b7f8e1120907e91 /packages/meshbay-hub/tests/test_downloads.py | |
| parent | 87725dc7a2da27c2ca3b9e58af751f0e6f8c9de7 (diff) | |
| download | meshbay-f211a13dc2e5dd82eaba49222171d6f29d858eb5.tar.gz | |
fix(hub): a downloaded file opens in a tab only under a type that runs nothing
Open is offered for PDFs, raster images, audio, video and plain text, typed
from the name; HTML, SVG and the rest are not opened in the hub's origin.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/tests/test_downloads.py')
| -rw-r--r-- | packages/meshbay-hub/tests/test_downloads.py | 39 |
1 files changed, 35 insertions, 4 deletions
diff --git a/packages/meshbay-hub/tests/test_downloads.py b/packages/meshbay-hub/tests/test_downloads.py index c8c68a9..3716f4c 100644 --- a/packages/meshbay-hub/tests/test_downloads.py +++ b/packages/meshbay-hub/tests/test_downloads.py @@ -101,13 +101,44 @@ def test_the_open_action_reads_the_file_back(tmp_path): """ "Open" is the browser being handed the bytes, not a desktop application being started — no web page can do the second, and none can show a file - manager either. It is only offered for a file written into a granted folder, - since that is the one a page can read back. + manager either. A file written into a granted folder is read back from it. """ src = DOWNLOADS.read_text(encoding="utf-8") target = src[src.index("export async function openTarget"):] - assert "getFile()" in target and "window.open(" in target - assert "revokeObjectURL" in target, "the blob URL must not be leaked" + assert "openInTab(await handle.getFile(), name)" in target + opener = src[src.index("export function openInTab"):] + opener = opener[:opener.index("\n}\n")] + assert "window.open(" in opener + assert "revokeObjectURL" in opener, "the blob URL must not be leaked" + + +def test_a_tab_is_opened_only_for_a_type_that_runs_nothing(tmp_path): + """ + A tab on a `blob:` URL is a document of the hub's origin, with its session + and its keys. Measured in Chrome and Firefox: HTML typed `text/html` runs + there, the same bytes typed `text/plain` do not. So the type is chosen from + the name, never guessed from the bytes, and what could run is not opened. + """ + result = _run(""" +const opened = []; +globalThis.window = { open: (url) => opened.push(url) }; +globalThis.URL.createObjectURL = (blob) => `blob:${blob.type}`; +globalThis.URL.revokeObjectURL = () => {}; +globalThis.setTimeout = () => 0; // the revoke a minute later; node would wait for it +const bytes = new Blob(['<script>alert(1)</script>'], { type: 'text/html' }); +for (const name of ['page.html', 'page.HTM', 'logo.svg', 'feed.xml', 'x.xhtml', + 'tool.js', 'noext', 'notes.txt', 'film.MP4', 'scan.pdf', 'pic.jpeg']) { + say([name, M.openInTab(bytes, name)]); +} +say(opened); +""", tmp_path) + *verdicts, opened = result + refused = {name for name, ok in verdicts if not ok} + assert refused == {"page.html", "page.HTM", "logo.svg", "feed.xml", "x.xhtml", + "tool.js", "noext"} + assert opened == ["blob:text/plain;charset=utf-8", "blob:video/mp4", + "blob:application/pdf", "blob:image/jpeg"], \ + "a tab must get the type chosen from the name, not the blob's own" # ── Streaming to disk without the File System Access API ──────────────────── |