blob: b0e587f34f42d6d1cc11df62563ac99ce2b46130 [file] [edit]
<!DOCTYPE html>
<meta charset="utf-8">
<title>WebAuthn navigator.credentials.create() shared buffer Tests</title>
<link rel="help" href="https://w3c.github.io/webauthn/#dictionary-makecredentialoptions">
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<body></body>
<script>
"use strict";
// None of the BufferSource members of PublicKeyCredentialCreationOptions are
// [AllowShared], so converting a SharedArrayBuffer, or a view onto one, has to
// throw a TypeError.
//
// See https://github.com/whatwg/html/issues/5380 for why not `new SharedArrayBuffer()`.
const sharedBuffer = new WebAssembly.Memory({ shared: true, initial: 1, maximum: 1 }).buffer;
const sharedBuffers = [
["SharedArrayBuffer", sharedBuffer],
["Uint8Array(SharedArrayBuffer)", new Uint8Array(sharedBuffer)],
];
// Converting the argument precedes every other step of create(), so the aborted
// signal is never reached. It is there to stop a user agent that wrongly accepts
// the shared buffer from starting an authenticator request.
function createOptions(publicKey) {
return {
publicKey: {
rp: { name: "Example" },
user: { name: "example", id: new Uint8Array([1]), displayName: "Example" },
challenge: new Uint8Array([1]),
pubKeyCredParams: [{ type: "public-key", alg: -7 }],
...publicKey,
},
signal: AbortSignal.abort(),
};
}
for (const [kind, buffer] of sharedBuffers) {
promise_test(t => {
return promise_rejects_js(t, TypeError, navigator.credentials.create(createOptions({ challenge: buffer })));
}, `Bad challenge: challenge is a ${kind}`);
promise_test(t => {
const user = { name: "example", id: buffer, displayName: "Example" };
return promise_rejects_js(t, TypeError, navigator.credentials.create(createOptions({ user })));
}, `Bad user: user.id is a ${kind}`);
promise_test(t => {
const excludeCredentials = [{ type: "public-key", id: buffer }];
return promise_rejects_js(t, TypeError, navigator.credentials.create(createOptions({ excludeCredentials })));
}, `Bad excludeCredentials: excludeCredentials[0].id is a ${kind}`);
}
</script>