-
Notifications
You must be signed in to change notification settings - Fork 3.1k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
webauthn: move create credential tests for residentKey/credProps to WPT
Bug: 1117630 Change-Id: I2fa4d73b7a4cfe5e7f19fd835cb32e1bb4926d2f Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/2508878 Reviewed-by: Nina Satragno <nsatragno@chromium.org> Commit-Queue: Martin Kreichgauer <martinkr@google.com> Cr-Commit-Position: refs/heads/master@{#825930}
- Loading branch information
1 parent
c18d662
commit 745dadd
Showing
2 changed files
with
222 additions
and
19 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,178 @@ | ||
<!DOCTYPE html> | ||
<html> | ||
<head> | ||
<meta charset="utf-8"> | ||
<title>navigator.credentials.create() test with residentKey and credProps</title> | ||
<meta name="timeout" content="long"> | ||
<script src="/resources/testharness.js"></script> | ||
<script src="/resources/testharnessreport.js"></script> | ||
<script src="/resources/testdriver.js"></script> | ||
<script src="/resources/testdriver-vendor.js"></script> | ||
<script src=helpers.js></script> | ||
<script> | ||
|
||
"use strict"; | ||
const credPropsTests = [ | ||
{ | ||
name: "U2F", | ||
authenticatorArgs: { | ||
protocol: "ctap1/u2f", | ||
}, | ||
expected: { | ||
discouraged: { | ||
success: true, | ||
hasRk: true, | ||
rk: false, | ||
}, | ||
preferred: { | ||
success: true, | ||
hasRk: true, | ||
rk: false, | ||
}, | ||
required: { | ||
success: false, | ||
}, | ||
}, | ||
}, | ||
{ | ||
name: "CTAP 2.0 without resident key support", | ||
authenticatorArgs: { | ||
protocol: "ctap2", | ||
hasResidentKey: false, | ||
hasUserVerification: true, | ||
isUserVerified: true, | ||
}, | ||
expected: { | ||
discouraged: { | ||
success: true, | ||
hasRk: true, | ||
rk: false, | ||
}, | ||
preferred: { | ||
success: true, | ||
hasRk: true, | ||
rk: false, | ||
}, | ||
required: { | ||
success: false, | ||
}, | ||
}, | ||
}, | ||
{ | ||
name: "CTAP 2.0 with resident key support", | ||
authenticatorArgs: { | ||
protocol: "ctap2", | ||
hasResidentKey: true, | ||
hasUserVerification: true, | ||
isUserVerified: true, | ||
}, | ||
expected: { | ||
discouraged: { | ||
success: true, | ||
// CTAP2.0 authenticators may treat all credentials as discoverable, | ||
// thus Chrome omits 'rk' in this case. | ||
hasRk: false, | ||
}, | ||
preferred: { | ||
success: true, | ||
hasRk: true, | ||
rk: true, | ||
}, | ||
required: { | ||
success: true, | ||
hasRk: true, | ||
rk: true, | ||
}, | ||
}, | ||
}, | ||
{ | ||
name: "CTAP 2.1 without resident key support", | ||
authenticatorArgs: { | ||
protocol: "ctap2_1", | ||
hasResidentKey: false, | ||
hasUserVerification: true, | ||
isUserVerified: true, | ||
}, | ||
expected: { | ||
discouraged: { | ||
success: true, | ||
hasRk: true, | ||
rk: false, | ||
}, | ||
preferred: { | ||
success: true, | ||
hasRk: true, | ||
rk: false, | ||
}, | ||
required: { | ||
success: false, | ||
}, | ||
}, | ||
}, | ||
{ | ||
name: "CTAP 2.1 with resident key support", | ||
authenticatorArgs: { | ||
protocol: "ctap2_1", | ||
hasResidentKey: true, | ||
hasUserVerification: true, | ||
isUserVerified: true, | ||
}, | ||
expected: { | ||
discouraged: { | ||
success: true, | ||
hasRk: true, | ||
rk: false, | ||
}, | ||
preferred: { | ||
success: true, | ||
hasRk: true, | ||
rk: true, | ||
}, | ||
required: { | ||
success: true, | ||
hasRk: true, | ||
rk: true, | ||
}, | ||
}, | ||
}, | ||
]; | ||
|
||
for (const fixture of credPropsTests) { | ||
for (const rkRequirement of ["discouraged", "preferred", "required"]) { | ||
virtualAuthenticatorTest(async t => { | ||
const promise = createCredential({ | ||
options: { | ||
publicKey: { | ||
authenticatorSelection: { | ||
residentKey: rkRequirement, | ||
}, | ||
extensions: { | ||
credProps: true, | ||
}, | ||
}, | ||
}, | ||
}); | ||
|
||
assert_true(rkRequirement in fixture.expected); | ||
const expected = fixture.expected[rkRequirement]; | ||
assert_true('success' in expected); | ||
if (!expected.success) { | ||
return promise_rejects_dom(t, "NotAllowedError", promise); | ||
} | ||
|
||
const cred = await promise; | ||
assert_true('credProps' in cred.getClientExtensionResults()); | ||
const credProps = cred.getClientExtensionResults().credProps; | ||
assert_equals('rk' in credProps, expected.hasRk, "hasRk"); | ||
if (expected.hasRk) { | ||
assert_equals(credProps.rk, expected.rk, "rk"); | ||
} | ||
}, fixture.authenticatorArgs, fixture.name | ||
+ ": navigator.credentials.create() with credProps extension, rk=" | ||
+ rkRequirement); | ||
} | ||
} | ||
</script> | ||
</head> | ||
<body></body> | ||
</html> |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters