Ignoring revisions in .git-blame-ignore-revs. Click here to bypass and see the normal blame view.

338 lines
12 KiB
HTML
Raw Normal View History

<!DOCTYPE html>
<!--
Copyright (C) 2016 The Android Open Source Project
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
-->
<meta name="viewport" content="width=device-width, minimum-scale=1.0, initial-scale=1.0, user-scalable=yes">
<title>gr-diff-selection</title>
<script src="../../../bower_components/webcomponentsjs/webcomponents-lite.min.js"></script>
<script src="../../../bower_components/web-component-tester/browser.js"></script>
Polygerrit now loads polymer-resin polymer-resin intercepts polymer property assignments before they reach XSS-vulnerable sinks like `href="..."` and text nodes in `<script>` elements. This follows the instructions in WORKSPACE for adding a new bower dependency with kaspern's tweak to use the dependency in a rule so that it's found. //lib/js/bower_components.bzl has already been rolled-back per those instructions. The license is the polymer license as can be seen at https://github.com/Polymer/polymer-resin/blob/master/LICENSE though I'm not sure that //tools/js/bower2bazel.py recognizes it as such. Docs for the added component are available at https://github.com/Polymer/polymer-resin/blob/master/README.md https://github.com/Polymer/polymer-resin/blob/master/getting-started.md With this change, when I introduce an XSS vulnerability as below, polymer-resin intercepts and stops it. Patch that introduces a strawman vulnerability. --- a/polygerrit-ui/app/elements/core/gr-main-header/gr-main-header.js +++ b/polygerrit-ui/app/elements/core/gr-main-header/gr-main-header.js @@ -55,6 +55,10 @@ url: '/q/status:abandoned', name: 'Abandoned', }, + { + url: location.hash.replace(/^#/, '') || 'http://example.com/#fragment_echoed_here', + name: 'XSS Me', + }, ], }]; --- Address kaspern's and paladox's comments. --- Undo version bumps for bower dependencies. --- Change Soy index template to parallel app/index.html. --- update polymer-resin to version 1.1.1-beta ---- Load polymer-resin into polygerrit-ui/**/*_test.html After this, I ran the tests with -l chrome -l firefox I ran a handful of tests with -p and observed that the console shows "initResin" is called before test cases start executing. These changes were done programmaticly by running the script below (approximately) thus: ``` gerrit/ $ cd polygerrit-ui/app app/ $ find . -name \*test.html | xargs perl hack-tests.pl ``` ``` use strict; sub removeResin($) { my $s = $_[0]; $s =~ s@<link rel="import" href="[^"]*/polymer-resin/[^"]*"[^>]*>\n?@@; $s =~ s@<script src="[^"]*/polymer-resin/[^"]*"></script>\n?@@; $s =~ s@<script>\s*security\.polymer_resin.*?</script>\n?@@s; return $s; } for my $f (@ARGV) { next if $f =~ m@/bower_components/|/node_modules/@; system('git', 'checkout', $f); print "$f\n"; my @lines = (); open(IN, "<$f") or die "$f: $!"; my $maxLineOfMatch = 0; while (<IN>) { push(@lines, $_); # Put a marker after core loading directives. $maxLineOfMatch = scalar(@lines) if m@/webcomponentsjs/|/polymer[.]html\b|/browser[.]js@; } close(IN) or die "$f: $!"; die "$f missing loading directives" unless $maxLineOfMatch; # Given ./a/b/c/my_test.html, $pathToRoot is "../../.." # assuming no non-leading . or .. components in the path from find. my $pathToRoot = $f; $pathToRoot =~ s@^\.\/@@; $pathToRoot =~ s@^(.*?/)?app/@@; $pathToRoot =~ s@\/[^\/]*$@@; $pathToRoot =~ s@[^/]+@..@g; my $nLines = scalar(@lines); open(OUT, ">$f") or die "$f: $!"; # Output the lines up to the last polymer-resin dependency # loaded explicitly by this test. my $before = join '', @lines[0..($maxLineOfMatch - 1)]; $before = removeResin($before); print OUT "$before"; # Dump out the lines that load polymer-resin and configure it for # polygerrit. if (1) { print OUT qq'<link rel="import" href="$pathToRoot/bower_components/polymer-resin/standalone/polymer-resin-debug.html"/> <script> security.polymer_resin.install({allowedIdentifierPrefixes: [\'\']}); </script> '; } # Emit any remaining lines. my $after = join '', @lines[$maxLineOfMatch..$#lines]; $after = removeResin($after); $after =~ s/^\n*//; print OUT "$after"; close(OUT) or die "$f: $!"; } ``` --- update polymer-resin to version 1.2.1-beta --- update Soy index template to new style polymer-resin initialization ---- fix lint warnings ---- Load test/common-test-setup.html into *_test.html Instead of inserting instructions to load and initialize polymer-resin into every test file, add a common-test-setup.html that does that and also fold iron-test-helpers loading into it. ---- imported files do not need to load webcomponentsjs Change-Id: I71221c36ed8a0fe7f8720c1064a2fcc9555bb8df
2017-05-08 14:07:13 -04:00
<link rel="import" href="../../../test/common-test-setup.html"/>
<link rel="import" href="gr-diff-selection.html">
<script>void(0);</script>
<test-fixture id="basic">
<template>
<gr-diff-selection>
<table id="diffTable" class="side-by-side">
<tr class="diff-row">
<td class="lineNum left" data-value="1">1</td>
<td class="content">
<div class="contentText" data-side="left">ba ba</div>
<div data-side="left">
<div class="gr-diff-comment-thread">
<div class="gr-formatted-text message">
<span id="output" class="gr-linked-text">This is a comment</span>
</div>
</div>
</div>
</td>
<td class="lineNum right" data-value="1">1</td>
<td class="content">
<div class="contentText" data-side="right">some other text</div>
</td>
</tr>
<tr class="diff-row">
<td class="lineNum left" data-value="2">2</td>
<td class="content">
<div class="contentText" data-side="left">zin</div>
</td>
<td class="lineNum right" data-value="2">2</td>
<td class="content">
<div class="contentText" data-side="right">more more more</div>
<div data-side="right">
<div class="gr-diff-comment-thread">
<div class="gr-formatted-text message">
<span id="output" class="gr-linked-text">This is a comment on the right</span>
</div>
</div>
</div>
</td>
</tr>
<tr class="diff-row">
<td class="lineNum left" data-value="3">3</td>
<td class="content">
<div class="contentText" data-side="left">ga ga</div>
<div data-side="left">
<div class="gr-diff-comment-thread">
<div class="gr-formatted-text message">
<span id="output" class="gr-linked-text">This is <a>a</a> different comment 💩 unicode is fun</span>
</div>
</div>
</div>
</td>
<td class="lineNum right" data-value="3">3</td>
</tr>
<tr class="diff-row">
<td class="lineNum left" data-value="4">4</td>
<td class="content">
<div class="contentText" data-side="left">ga ga</div>
<div data-side="left">
<div class="gr-diff-comment-thread">
<textarea data-side="right">test for textarea copying</textarea>
</div>
</div>
</td>
<td class="lineNum right" data-value="4">4</td>
</tr>
<tr class="not-diff-row">
<td class="other">
<div class="contentText" data-side="right">some other text</div>
</td>
</tr>
</table>
</gr-diff-selection>
</template>
</test-fixture>
<script>
suite('gr-diff-selection', () => {
let element;
let sandbox;
const emulateCopyOn = function(target) {
const fakeEvent = {
target,
preventDefault: sandbox.stub(),
clipboardData: {
setData: sandbox.stub(),
},
};
element._getCopyEventTarget.returns(target);
element._handleCopy(fakeEvent);
return fakeEvent;
};
setup(() => {
element = fixture('basic');
sandbox = sinon.sandbox.create();
sandbox.stub(element, '_getCopyEventTarget');
element._cachedDiffBuilder = {
getLineElByChild: sandbox.stub().returns({}),
getSideByLineEl: sandbox.stub(),
diffElement: element.querySelector('#diffTable'),
};
element.diff = {
content: [
{
a: ['ba ba'],
b: ['some other text'],
},
{
a: ['zin'],
b: ['more more more'],
},
{
a: ['ga ga'],
b: ['some other text'],
},
],
};
});
teardown(() => {
sandbox.restore();
});
test('applies selected-left on left side click', () => {
element.classList.add('selected-right');
element._cachedDiffBuilder.getSideByLineEl.returns('left');
MockInteractions.down(element);
assert.isTrue(
element.classList.contains('selected-left'), 'adds selected-left');
assert.isFalse(
element.classList.contains('selected-right'),
'removes selected-right');
});
test('applies selected-right on right side click', () => {
element.classList.add('selected-left');
element._cachedDiffBuilder.getSideByLineEl.returns('right');
MockInteractions.down(element);
assert.isTrue(
element.classList.contains('selected-right'), 'adds selected-right');
assert.isFalse(
element.classList.contains('selected-left'), 'removes selected-left');
});
test('ignores copy for non-content Element', () => {
sandbox.stub(element, '_getSelectedText');
emulateCopyOn(element.querySelector('.not-diff-row'));
assert.isFalse(element._getSelectedText.called);
});
test('asks for text for left side Elements', () => {
element._cachedDiffBuilder.getSideByLineEl.returns('left');
sandbox.stub(element, '_getSelectedText');
emulateCopyOn(element.querySelector('div.contentText'));
assert.deepEqual(['left', false], element._getSelectedText.lastCall.args);
});
test('reacts to copy for content Elements', () => {
sandbox.stub(element, '_getSelectedText');
emulateCopyOn(element.querySelector('div.contentText'));
assert.isTrue(element._getSelectedText.called);
});
test('copy event is prevented for content Elements', () => {
sandbox.stub(element, '_getSelectedText');
element._cachedDiffBuilder.getSideByLineEl.returns('left');
element._getSelectedText.returns('test');
const event = emulateCopyOn(element.querySelector('div.contentText'));
assert.isTrue(event.preventDefault.called);
});
test('inserts text into clipboard on copy', () => {
sandbox.stub(element, '_getSelectedText').returns('the text');
const event = emulateCopyOn(element.querySelector('div.contentText'));
assert.deepEqual(
['Text', 'the text'], event.clipboardData.setData.lastCall.args);
});
test('copies content correctly', () => {
// Fetch the line number.
element._cachedDiffBuilder.getLineElByChild = function(child) {
while (!child.classList.contains('content') && child.parentElement) {
child = child.parentElement;
}
return child.previousElementSibling;
};
element.classList.add('selected-left');
element.classList.remove('selected-right');
const selection = window.getSelection();
selection.removeAllRanges();
const range = document.createRange();
range.setStart(element.querySelector('div.contentText').firstChild, 3);
range.setEnd(
element.querySelectorAll('div.contentText')[4].firstChild, 2);
selection.addRange(range);
assert.equal(element._getSelectedText('left'), 'ba\nzin\nga');
});
test('copies comments', () => {
element.classList.add('selected-left');
element.classList.add('selected-comment');
element.classList.remove('selected-right');
const selection = window.getSelection();
selection.removeAllRanges();
const range = document.createRange();
range.setStart(
element.querySelector('.gr-formatted-text *').firstChild, 3);
range.setEnd(
element.querySelectorAll('.gr-formatted-text *')[2].childNodes[2], 7);
selection.addRange(range);
assert.equal('s is a comment\nThis is a differ',
element._getSelectedText('left', true));
});
test('respects astral chars in comments', () => {
element.classList.add('selected-left');
element.classList.add('selected-comment');
element.classList.remove('selected-right');
const selection = window.getSelection();
selection.removeAllRanges();
const range = document.createRange();
const nodes = element.querySelectorAll('.gr-formatted-text *');
range.setStart(nodes[2].childNodes[2], 13);
range.setEnd(nodes[2].childNodes[2], 23);
selection.addRange(range);
assert.equal('mment 💩 u',
element._getSelectedText('left', true));
});
test('defers to default behavior for textarea', () => {
element.classList.add('selected-left');
element.classList.remove('selected-right');
const selectedTextSpy = sandbox.spy(element, '_getSelectedText');
emulateCopyOn(element.querySelector('textarea'));
assert.isFalse(selectedTextSpy.called);
});
test('regression test for 4794', () => {
element._cachedDiffBuilder.getLineElByChild = function(child) {
while (!child.classList.contains('content') && child.parentElement) {
child = child.parentElement;
}
return child.previousElementSibling;
};
element.classList.add('selected-right');
element.classList.remove('selected-left');
const selection = window.getSelection();
selection.removeAllRanges();
const range = document.createRange();
range.setStart(
element.querySelectorAll('div.contentText')[1].firstChild, 4);
range.setEnd(
element.querySelectorAll('div.contentText')[1].firstChild, 10);
selection.addRange(range);
assert.equal(element._getSelectedText('right'), ' other');
});
suite('_getTextContentForRange', () => {
let selection;
let range;
let nodes;
setup(() => {
element.classList.add('selected-left');
element.classList.add('selected-comment');
element.classList.remove('selected-right');
selection = window.getSelection();
selection.removeAllRanges();
range = document.createRange();
nodes = element.querySelectorAll('.gr-formatted-text *');
});
test('multi level element contained in range', () => {
range.setStart(nodes[2].childNodes[0], 1);
range.setEnd(nodes[2].childNodes[2], 7);
selection.addRange(range);
assert.equal(element._getTextContentForRange(element, selection, range),
'his is a differ');
});
test('multi level element as startContainer of range', () => {
range.setStart(nodes[2].childNodes[1], 0);
range.setEnd(nodes[2].childNodes[2], 7);
selection.addRange(range);
assert.equal(element._getTextContentForRange(element, selection, range),
'a differ');
});
test('startContainer === endContainer', () => {
range.setStart(nodes[0].firstChild, 2);
range.setEnd(nodes[0].firstChild, 12);
selection.addRange(range);
assert.equal(element._getTextContentForRange(element, selection, range),
'is is a co');
});
});
test('cache is reset when diff changes', () => {
element._linesCache = {left: 'test', right: 'test'};
element.diff = {};
flushAsynchronousOperations();
assert.deepEqual(element._linesCache, {left: null, right: null});
});
});
</script>