| <!DOCTYPE html> |
| <meta charset="utf-8"> |
| <title>WebAuthn navigator.credentials.create() shared buffer Tests</title> |
| <link rel="help" href="https://w3c.github.io/webauthn/#dictionary-makecredentialoptions"> |
| <script src="/resources/testharness.js"></script> |
| <script src="/resources/testharnessreport.js"></script> |
| <body></body> |
| <script> |
| "use strict"; |
| |
| // None of the BufferSource members of PublicKeyCredentialCreationOptions are |
| // [AllowShared], so converting a SharedArrayBuffer, or a view onto one, has to |
| // throw a TypeError. |
| // |
| // See https://github.com/whatwg/html/issues/5380 for why not `new SharedArrayBuffer()`. |
| const sharedBuffer = new WebAssembly.Memory({ shared: true, initial: 1, maximum: 1 }).buffer; |
| const sharedBuffers = [ |
| ["SharedArrayBuffer", sharedBuffer], |
| ["Uint8Array(SharedArrayBuffer)", new Uint8Array(sharedBuffer)], |
| ]; |
| |
| // Converting the argument precedes every other step of create(), so the aborted |
| // signal is never reached. It is there to stop a user agent that wrongly accepts |
| // the shared buffer from starting an authenticator request. |
| function createOptions(publicKey) { |
| return { |
| publicKey: { |
| rp: { name: "Example" }, |
| user: { name: "example", id: new Uint8Array([1]), displayName: "Example" }, |
| challenge: new Uint8Array([1]), |
| pubKeyCredParams: [{ type: "public-key", alg: -7 }], |
| ...publicKey, |
| }, |
| signal: AbortSignal.abort(), |
| }; |
| } |
| |
| for (const [kind, buffer] of sharedBuffers) { |
| promise_test(t => { |
| return promise_rejects_js(t, TypeError, navigator.credentials.create(createOptions({ challenge: buffer }))); |
| }, `Bad challenge: challenge is a ${kind}`); |
| |
| promise_test(t => { |
| const user = { name: "example", id: buffer, displayName: "Example" }; |
| return promise_rejects_js(t, TypeError, navigator.credentials.create(createOptions({ user }))); |
| }, `Bad user: user.id is a ${kind}`); |
| |
| promise_test(t => { |
| const excludeCredentials = [{ type: "public-key", id: buffer }]; |
| return promise_rejects_js(t, TypeError, navigator.credentials.create(createOptions({ excludeCredentials }))); |
| }, `Bad excludeCredentials: excludeCredentials[0].id is a ${kind}`); |
| } |
| </script> |