mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-28 23:52:28 +02:00
v1.90.0.0 feat: make browser cookie imports explicit and safe (#2964)
* fix(browse): prepare reliable cookie import wave for validation * ci: sequence quality and behavior for validation branch * fix(browse): isolate Windows qualification and preserve native diagnostics * test(browse): cover cookie workflow quality and isolate Windows user paths * test(browse): trace native member startup and initialize fresh folders * fix(browse): keep Windows member stdin alive through EOF * fix(browse): latch native timeouts and compare contained Edge startup * test(browse): verify native version metadata and actual Windows argv * test(browse): qualify Dia import on isolated macOS CI * fix(browse): require picker origin for session mutations * fix(browse): bound credential reads through stream completion * test(browse): inspect owned Windows process arguments natively * test(evals): preserve passing coverage during cookie repair reruns * test(browse): isolate Dia qualification in a fresh macOS account * test(browse): pass bounded integer timeouts to native Mac probes * test(browse): distinguish Windows profile initialization from containment * test(browse): await descendant pipe readiness before parent exit * test(browse): initialize and restore isolated macOS Keychain state * test(browse): initialize Windows fixture folders before qualification * test(ci): pin the same Node runtime across Windows checks * test(browse): distinguish native macOS browser preflight stages * test(browse): isolate Windows descendant console lifetime * test(browse): preserve native receipts and identify fixture lock holders * test(browse): prepare dependency resolution before native Mac worker startup * test(ci): include lock and close checks in native diagnostics * test(browse): preserve native owner probe stages and subprocess deadlines * fix(browse): classify Chromium profile-in-use exit precisely * test(browse): retain Mac qualification evidence through cleanup failures * test(browse): bound Mac fixture paths and retire its owned user domain * test(browse): accept vanished fixture entries without weakening cleanup * test(browse): identify probe-created macOS user domains safely * test(browse): observe Mac user domains without targeting them first * test(browse): use passive fresh-user ownership throughout Mac qualification * test(browse): distinguish profile and registered-home Keychain lookups * test(browse): qualify Dia under one registered account home * test(browse): identify Dia startup and owned process-group failures * test(browse): classify bounded Dia startup diagnostics without leaking output * fix(test): preserve native Mac sandboxing and reap owned browser children * fix(browse): preserve Chromium sandboxing for native profile imports * test(browse): inspect signed Mach-O architecture without launching Xcode tools * test(browse): sample pending Dia startup and reap on all cleanup paths * test(browse): compare protected Dia launches in fresh Bun and Node accounts * test(browse): inspect isolated Mac GUI readiness without browser access * v1.90.0.0 fix: bind cookie picker actions to their document * test: validate cookie guards and fit nested launch fixtures * ci: configure the bundled Chromium sandbox helper * fix(browse): classify Playwright authentication timeouts * test: retain bounded Windows lifecycle diagnostics * test(cso): reuse bounded NTFS precision candidates * test(review): handle explicit preservation choices safely * test(browse): remove owned fixture directories with explicit primitives * test(review): distinguish descriptive reuse from edit commitments * test: admit only the approved unscored cookie workflow refusal * test: keep the Office Hours judge mock export-complete * fix: keep dependency-free CI planners independent of the model SDK * test: observe the exact holder after a native fixture unlink failure * fix: start seeded PTY observations at owned readiness * test: acquire identity-bound Windows deletion admission before profile resets * test: preserve qualified Git index bits without authorizing mutations
This commit is contained in:
@@ -6,7 +6,7 @@
|
||||
* that could silently remove a fix without breaking compilation.
|
||||
*/
|
||||
|
||||
import { describe, it, expect, beforeAll, afterAll } from 'bun:test';
|
||||
import { describe, it, expect, beforeAll, afterAll, spyOn } from 'bun:test';
|
||||
import * as fs from 'fs';
|
||||
import * as path from 'path';
|
||||
import * as os from 'os';
|
||||
@@ -364,11 +364,38 @@ describe('cookie-import domain validation', () => {
|
||||
expect(block).toContain('does not match current page domain');
|
||||
});
|
||||
|
||||
it('cookie-import-browser handler validates --domain against page hostname', () => {
|
||||
const block = sliceBetween(WRITE_SRC, "case 'cookie-import-browser':", "case 'style':");
|
||||
expect(block).toContain('normalizedDomain');
|
||||
expect(block).toContain('pageHostname');
|
||||
expect(block).toContain('does not match current page domain');
|
||||
it('cookie-import-browser handler validates --domain against page hostname', async () => {
|
||||
const operation = await import('../src/cookie-import-operation');
|
||||
const { handleWriteCommand } = await import('../src/write-commands');
|
||||
const imported = spyOn(operation, 'runCookieImport').mockResolvedValue({
|
||||
browser: 'chromium', profile: 'Profile 2', imported: 2, failed: 0,
|
||||
domainCounts: { '.example.test': 2 }, failureReasons: {}, outcome: 'imported',
|
||||
reset: 'not_requested', verification: { verified: false, reason: 'not_requested' }, message: 'Cookie copy complete.',
|
||||
});
|
||||
let currentUrl = 'https://example.test';
|
||||
const page = { url: () => currentUrl, isClosed: () => false };
|
||||
const session = { getPage: () => page, getActiveFrameOrPage: () => page, getFrame: () => null } as any;
|
||||
const manager = { trackCookieImportDomains() {} } as any;
|
||||
try {
|
||||
for (const [target, domain] of [
|
||||
['https://example.test', 'unrelated.test'],
|
||||
['https://example.test.evil.invalid', 'example.test'],
|
||||
['https://badexample.test', 'example.test'],
|
||||
]) {
|
||||
currentUrl = target;
|
||||
await expect(handleWriteCommand('cookie-import-browser', ['chromium', '--domain', domain], session, manager))
|
||||
.rejects.toMatchObject({ code: 'target_mismatch' });
|
||||
}
|
||||
expect(imported).not.toHaveBeenCalled();
|
||||
currentUrl = 'https://sub.example.test/protected';
|
||||
const result = await handleWriteCommand('cookie-import-browser', ['chromium', '--domain', '.Example.Test.', '--profile', 'Profile 2'], session, manager);
|
||||
expect(imported).toHaveBeenCalledTimes(1);
|
||||
expect(imported.mock.calls[0][0]).toMatchObject({ browser: 'chromium', domains: ['example.test'], profile: 'Profile 2' });
|
||||
expect(imported.mock.calls[0][1]).toEqual({ page, url: currentUrl });
|
||||
expect(result).toContain('Imported 2 cookies from chromium (profile: Profile 2)');
|
||||
} finally {
|
||||
imported.mockRestore();
|
||||
}
|
||||
});
|
||||
});
|
||||
|
||||
|
||||
Reference in New Issue
Block a user