| <!DOCTYPE html> |
| <meta charset="utf-8"> |
| <title>WebAuthn navigator.credentials.get() shared buffer Tests</title> |
| <link rel="help" href="https://w3c.github.io/webauthn/#dictionary-assertion-options"> |
| <script src="/resources/testharness.js"></script> |
| <script src="/resources/testharnessreport.js"></script> |
| <body></body> |
| <script> |
| "use strict"; |
| |
| // None of the BufferSource members of PublicKeyCredentialRequestOptions are |
| // [AllowShared], so converting a SharedArrayBuffer, or a view onto one, has to |
| // throw a TypeError. |
| // |
| // See https://github.com/whatwg/html/issues/5380 for why not `new SharedArrayBuffer()`. |
| const sharedBuffer = new WebAssembly.Memory({ shared: true, initial: 1, maximum: 1 }).buffer; |
| const sharedBuffers = [ |
| ["SharedArrayBuffer", sharedBuffer], |
| ["Uint8Array(SharedArrayBuffer)", new Uint8Array(sharedBuffer)], |
| ]; |
| |
| // Converting the argument precedes every other step of get(), so the aborted |
| // signal is never reached. It is there to stop a user agent that wrongly accepts |
| // the shared buffer from starting an authenticator request. |
| function requestOptions(publicKey) { |
| return { |
| publicKey: { |
| challenge: new Uint8Array([1]), |
| ...publicKey, |
| }, |
| signal: AbortSignal.abort(), |
| }; |
| } |
| |
| for (const [kind, buffer] of sharedBuffers) { |
| promise_test(t => { |
| return promise_rejects_js(t, TypeError, navigator.credentials.get(requestOptions({ challenge: buffer }))); |
| }, `Bad challenge: challenge is a ${kind}`); |
| |
| promise_test(t => { |
| const allowCredentials = [{ type: "public-key", id: buffer }]; |
| return promise_rejects_js(t, TypeError, navigator.credentials.get(requestOptions({ allowCredentials }))); |
| }, `Bad allowCredentials: allowCredentials[0].id is a ${kind}`); |
| } |
| </script> |