aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/tests/test_downloads.py
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-hub/tests/test_downloads.py')
-rw-r--r--packages/meshbay-hub/tests/test_downloads.py39
1 files changed, 35 insertions, 4 deletions
diff --git a/packages/meshbay-hub/tests/test_downloads.py b/packages/meshbay-hub/tests/test_downloads.py
index c8c68a9..3716f4c 100644
--- a/packages/meshbay-hub/tests/test_downloads.py
+++ b/packages/meshbay-hub/tests/test_downloads.py
@@ -101,13 +101,44 @@ def test_the_open_action_reads_the_file_back(tmp_path):
"""
"Open" is the browser being handed the bytes, not a desktop application
being started — no web page can do the second, and none can show a file
- manager either. It is only offered for a file written into a granted folder,
- since that is the one a page can read back.
+ manager either. A file written into a granted folder is read back from it.
"""
src = DOWNLOADS.read_text(encoding="utf-8")
target = src[src.index("export async function openTarget"):]
- assert "getFile()" in target and "window.open(" in target
- assert "revokeObjectURL" in target, "the blob URL must not be leaked"
+ assert "openInTab(await handle.getFile(), name)" in target
+ opener = src[src.index("export function openInTab"):]
+ opener = opener[:opener.index("\n}\n")]
+ assert "window.open(" in opener
+ assert "revokeObjectURL" in opener, "the blob URL must not be leaked"
+
+
+def test_a_tab_is_opened_only_for_a_type_that_runs_nothing(tmp_path):
+ """
+ A tab on a `blob:` URL is a document of the hub's origin, with its session
+ and its keys. Measured in Chrome and Firefox: HTML typed `text/html` runs
+ there, the same bytes typed `text/plain` do not. So the type is chosen from
+ the name, never guessed from the bytes, and what could run is not opened.
+ """
+ result = _run("""
+const opened = [];
+globalThis.window = { open: (url) => opened.push(url) };
+globalThis.URL.createObjectURL = (blob) => `blob:${blob.type}`;
+globalThis.URL.revokeObjectURL = () => {};
+globalThis.setTimeout = () => 0; // the revoke a minute later; node would wait for it
+const bytes = new Blob(['<script>alert(1)</script>'], { type: 'text/html' });
+for (const name of ['page.html', 'page.HTM', 'logo.svg', 'feed.xml', 'x.xhtml',
+ 'tool.js', 'noext', 'notes.txt', 'film.MP4', 'scan.pdf', 'pic.jpeg']) {
+ say([name, M.openInTab(bytes, name)]);
+}
+say(opened);
+""", tmp_path)
+ *verdicts, opened = result
+ refused = {name for name, ok in verdicts if not ok}
+ assert refused == {"page.html", "page.HTM", "logo.svg", "feed.xml", "x.xhtml",
+ "tool.js", "noext"}
+ assert opened == ["blob:text/plain;charset=utf-8", "blob:video/mp4",
+ "blob:application/pdf", "blob:image/jpeg"], \
+ "a tab must get the type chosen from the name, not the blob's own"
# ── Streaming to disk without the File System Access API ────────────────────