#include "net/cookies/cookie_monster.h"
#include <stdint.h>
#include <algorithm>
#include <array>
#include <cstddef>
#include <memory>
#include <optional>
#include <string>
#include <string_view>
#include <utility>
#include <vector>
#include "base/containers/queue.h"
#include "base/functional/bind.h"
#include "base/functional/callback.h"
#include "base/functional/callback_helpers.h"
#include "base/i18n/time_formatting.h"
#include "base/location.h"
#include "base/memory/raw_ptr.h"
#include "base/memory/ref_counted.h"
#include "base/metrics/histogram.h"
#include "base/metrics/histogram_samples.h"
#include "base/notreached.h"
#include "base/rand_util.h"
#include "base/run_loop.h"
#include "base/strings/strcat.h"
#include "base/strings/string_number_conversions.h"
#include "base/strings/string_split.h"
#include "base/strings/string_tokenizer.h"
#include "base/strings/string_util.h"
#include "base/strings/stringprintf.h"
#include "base/task/single_thread_task_runner.h"
#include "base/test/bind.h"
#include "base/test/metrics/histogram_tester.h"
#include "base/test/mock_callback.h"
#include "base/test/scoped_feature_list.h"
#include "base/test/test_future.h"
#include "base/threading/thread.h"
#include "base/time/time.h"
#include "cookie_partition_key.h"
#include "net/base/features.h"
#include "net/cookies/canonical_cookie.h"
#include "net/cookies/canonical_cookie_test_helpers.h"
#include "net/cookies/cookie_change_dispatcher.h"
#include "net/cookies/cookie_constants.h"
#include "net/cookies/cookie_inclusion_status.h"
#include "net/cookies/cookie_monster_store_test.h"
#include "net/cookies/cookie_partition_key.h"
#include "net/cookies/cookie_store.h"
#include "net/cookies/cookie_store_change_unittest.h"
#include "net/cookies/cookie_store_test_callbacks.h"
#include "net/cookies/cookie_store_test_helpers.h"
#include "net/cookies/cookie_store_unittest.h"
#include "net/cookies/cookie_util.h"
#include "net/cookies/parsed_cookie.h"
#include "net/cookies/test_cookie_access_delegate.h"
#include "net/cookies/unique_cookie_key.h"
#include "net/log/net_log_with_source.h"
#include "net/log/test_net_log.h"
#include "net/log/test_net_log_util.h"
#include "testing/gmock/include/gmock/gmock-matchers.h"
#include "testing/gmock/include/gmock/gmock.h"
#include "testing/gtest/include/gtest/gtest.h"
#include "url/gurl.h"
#include "url/third_party/mozilla/url_parse.h"
#include "url/url_constants.h"
namespace net {
using base::Time;
using CookieDeletionInfo = net::CookieDeletionInfo;
namespace {
using testing::_;
using testing::ElementsAre;
MATCHER_P(CookieEquals, expected, "") {
return !(arg.FullCompare(expected) || expected.FullCompare(arg));
}
MATCHER_P2(MatchesCookieNameDomain, name, domain, "") {
return testing::ExplainMatchResult(
testing::AllOf(testing::Property(&net::CanonicalCookie::Name, name),
testing::Property(&net::CanonicalCookie::Domain, domain)),
arg, result_listener);
}
MATCHER_P4(MatchesCookieNameValueCreationExpiry,
name,
value,
creation,
expiry,
"") {
return testing::ExplainMatchResult(
testing::AllOf(
testing::Property(&net::CanonicalCookie::Name, name),
testing::Property(&net::CanonicalCookie::Value, value),
testing::Property(&net::CanonicalCookie::CreationDate, creation),
testing::Property(&net::CanonicalCookie::ExpiryDate,
testing::Gt(expiry - base::Minutes(1))),
testing::Property(&net::CanonicalCookie::ExpiryDate,
testing::Lt(expiry + base::Minutes(1)))),
arg, result_listener);
}
const char kTopLevelDomainPlus1[] = "http://www.harvard.edu";
const char kTopLevelDomainPlus2[] = "http://www.math.harvard.edu";
const char kTopLevelDomainPlus2Secure[] = "https://www.math.harvard.edu";
const char kTopLevelDomainPlus3[] = "http://www.bourbaki.math.harvard.edu";
const char kOtherDomain[] = "http://www.mit.edu";
struct CookieMonsterTestTraits {
static std::unique_ptr<CookieStore> Create() {
return std::make_unique<CookieMonster>(nullptr ,
nullptr );
}
static void DeliverChangeNotifications() { base::RunLoop().RunUntilIdle(); }
static const bool supports_http_only = true;
static const bool supports_non_dotted_domains = true;
static const bool preserves_trailing_dots = true;
static const bool filters_schemes = true;
static const bool has_path_prefix_bug = false;
static const bool forbids_setting_empty_name = false;
static const bool supports_global_cookie_tracking = true;
static const bool supports_url_cookie_tracking = true;
static const bool supports_named_cookie_tracking = true;
static const bool supports_multiple_tracking_callbacks = true;
static const bool has_exact_change_cause = true;
static const bool has_exact_change_ordering = true;
static const int creation_time_granularity_in_ms = 0;
static const bool supports_cookie_access_semantics = true;
static const bool supports_partitioned_cookies = true;
static const bool dispatches_events_on_no_change_overwrite = true;
};
INSTANTIATE_TYPED_TEST_SUITE_P(CookieMonster,
CookieStoreTest,
CookieMonsterTestTraits);
INSTANTIATE_TYPED_TEST_SUITE_P(CookieMonster,
CookieStoreChangeGlobalTest,
CookieMonsterTestTraits);
INSTANTIATE_TYPED_TEST_SUITE_P(CookieMonster,
CookieStoreChangeUrlTest,
CookieMonsterTestTraits);
INSTANTIATE_TYPED_TEST_SUITE_P(CookieMonster,
CookieStoreChangeNamedTest,
CookieMonsterTestTraits);
template <typename T>
class CookieMonsterTestBase : public CookieStoreTest<T> {
public:
using CookieStoreTest<T>::SetCookie;
protected:
using CookieStoreTest<T>::http_www_foo_;
using CookieStoreTest<T>::https_www_foo_;
CookieList GetAllCookiesForURLWithOptions(
CookieMonster* cm,
const GURL& url,
const CookieOptions& options,
const CookiePartitionKeyCollection& cookie_partition_key_collection =
CookiePartitionKeyCollection()) {
DCHECK(cm);
GetCookieListCallback callback;
cm->GetCookieListWithOptionsAsync(
url, options, cookie_partition_key_collection, callback.MakeCallback());
callback.WaitUntilDone();
return callback.cookies();
}
CookieList GetAllCookies(CookieMonster* cm) {
DCHECK(cm);
GetAllCookiesCallback callback;
cm->GetAllCookiesAsync(callback.MakeCallback());
callback.WaitUntilDone();
return callback.cookies();
}
CookieAccessResultList GetExcludedCookiesForURLWithOptions(
CookieMonster* cm,
const GURL& url,
const CookieOptions& options,
const CookiePartitionKeyCollection& cookie_partition_key_collection =
CookiePartitionKeyCollection()) {
DCHECK(cm);
GetCookieListCallback callback;
cm->GetCookieListWithOptionsAsync(
url, options, cookie_partition_key_collection, callback.MakeCallback());
callback.WaitUntilDone();
return callback.excluded_cookies();
}
bool SetAllCookies(CookieMonster* cm, const CookieList& list) {
DCHECK(cm);
ResultSavingCookieCallback<CookieAccessResult> callback;
cm->SetAllCookiesAsync(list, callback.MakeCallback());
callback.WaitUntilDone();
return callback.result().status.IsInclude();
}
bool SetCookieWithCreationTime(
CookieMonster* cm,
const GURL& url,
const std::string& cookie_line,
base::Time creation_time,
std::optional<CookiePartitionKey> cookie_partition_key = std::nullopt) {
DCHECK(cm);
DCHECK(!creation_time.is_null());
ResultSavingCookieCallback<CookieAccessResult> callback;
cm->SetCanonicalCookieAsync(
CanonicalCookie::CreateForTesting(url, cookie_line, creation_time,
std::nullopt ,
cookie_partition_key),
url, CookieOptions::MakeAllInclusive(), callback.MakeCallback());
callback.WaitUntilDone();
return callback.result().status.IsInclude();
}
bool SetUnsafeCookieWithCreationTime(
CookieMonster* cm,
const GURL& url,
const std::string& cookie_line,
base::Time creation_time,
std::optional<CookiePartitionKey> cookie_partition_key = std::nullopt) {
DCHECK(cm);
DCHECK(!creation_time.is_null());
ResultSavingCookieCallback<CookieAccessResult> callback;
cm->SetUnsafeCanonicalCookieForTestAsync(
CanonicalCookie::CreateForTesting(url, cookie_line, creation_time,
std::nullopt ,
cookie_partition_key),
callback.MakeCallback());
callback.WaitUntilDone();
return callback.result().status.IsInclude();
}
uint32_t DeleteAllCreatedInTimeRange(CookieMonster* cm,
const TimeRange& creation_range) {
DCHECK(cm);
ResultSavingCookieCallback<uint32_t> callback;
cm->DeleteAllCreatedInTimeRangeAsync(creation_range,
callback.MakeCallback());
callback.WaitUntilDone();
return callback.result();
}
uint32_t DeleteAllMatchingInfo(CookieMonster* cm,
CookieDeletionInfo delete_info) {
DCHECK(cm);
ResultSavingCookieCallback<uint32_t> callback;
cm->DeleteAllMatchingInfoAsync(std::move(delete_info),
callback.MakeCallback());
callback.WaitUntilDone();
return callback.result();
}
uint32_t DeleteMatchingCookies(CookieMonster* cm,
CookieStore::DeletePredicate predicate) {
DCHECK(cm);
ResultSavingCookieCallback<uint32_t> callback;
cm->DeleteMatchingCookiesAsync(std::move(predicate),
callback.MakeCallback());
callback.WaitUntilDone();
return callback.result();
}
base::Time PopulateCmForPredicateCheck(CookieMonster* cm) {
std::string url_top_level_domain_plus_1(
GURL(kTopLevelDomainPlus1).GetHost());
std::string url_top_level_domain_plus_2(
GURL(kTopLevelDomainPlus2).GetHost());
std::string url_top_level_domain_plus_3(
GURL(kTopLevelDomainPlus3).GetHost());
std::string url_top_level_domain_secure(
GURL(kTopLevelDomainPlus2Secure).GetHost());
std::string url_other(GURL(kOtherDomain).GetHost());
this->DeleteAll(cm);
std::vector<std::unique_ptr<CanonicalCookie>> cookies;
const base::Time now = base::Time::Now();
cookies.push_back(CanonicalCookie::CreateUnsafeCookieForTesting(
"dom_1", "A", ".harvard.edu", "/", now, base::Time(), base::Time(),
base::Time(), false, false, CookieSameSite::LAX_MODE,
COOKIE_PRIORITY_DEFAULT));
cookies.push_back(CanonicalCookie::CreateUnsafeCookieForTesting(
"dom_2", "B", ".math.harvard.edu", "/", now, base::Time(), base::Time(),
base::Time(), false, false, CookieSameSite::LAX_MODE,
COOKIE_PRIORITY_DEFAULT));
cookies.push_back(CanonicalCookie::CreateUnsafeCookieForTesting(
"dom_3", "C", ".bourbaki.math.harvard.edu", "/", now, base::Time(),
base::Time(), base::Time(), false, false, CookieSameSite::LAX_MODE,
COOKIE_PRIORITY_DEFAULT));
cookies.push_back(CanonicalCookie::CreateUnsafeCookieForTesting(
"host_1", "A", url_top_level_domain_plus_1, "/", now, base::Time(),
base::Time(), base::Time(), false, false, CookieSameSite::LAX_MODE,
COOKIE_PRIORITY_DEFAULT));
cookies.push_back(CanonicalCookie::CreateUnsafeCookieForTesting(
"host_2", "B", url_top_level_domain_plus_2, "/", now, base::Time(),
base::Time(), base::Time(), false, false, CookieSameSite::LAX_MODE,
COOKIE_PRIORITY_DEFAULT));
cookies.push_back(CanonicalCookie::CreateUnsafeCookieForTesting(
"host_3", "C", url_top_level_domain_plus_3, "/", now, base::Time(),
base::Time(), base::Time(), false, false, CookieSameSite::LAX_MODE,
COOKIE_PRIORITY_DEFAULT));
cookies.push_back(CanonicalCookie::CreateUnsafeCookieForTesting(
"httpo_check", "A", url_top_level_domain_plus_2, "/", now, base::Time(),
base::Time(), base::Time(), false, true, CookieSameSite::LAX_MODE,
COOKIE_PRIORITY_DEFAULT));
cookies.push_back(CanonicalCookie::CreateUnsafeCookieForTesting(
"same_site_check", "A", url_top_level_domain_plus_2, "/", now,
base::Time(), base::Time(), base::Time(), false, false,
CookieSameSite::STRICT_MODE, COOKIE_PRIORITY_DEFAULT));
cookies.push_back(CanonicalCookie::CreateUnsafeCookieForTesting(
"sec_dom", "A", ".math.harvard.edu", "/", now, base::Time(),
base::Time(), base::Time(), true, false, CookieSameSite::NO_RESTRICTION,
COOKIE_PRIORITY_DEFAULT));
cookies.push_back(CanonicalCookie::CreateUnsafeCookieForTesting(
"sec_host", "B", url_top_level_domain_plus_2, "/", now, base::Time(),
base::Time(), base::Time(), true, false, CookieSameSite::NO_RESTRICTION,
COOKIE_PRIORITY_DEFAULT));
cookies.push_back(CanonicalCookie::CreateUnsafeCookieForTesting(
"dom_path_1", "A", ".math.harvard.edu", "/dir1", now, base::Time(),
base::Time(), base::Time(), false, false, CookieSameSite::LAX_MODE,
COOKIE_PRIORITY_DEFAULT));
cookies.push_back(CanonicalCookie::CreateUnsafeCookieForTesting(
"dom_path_2", "B", ".math.harvard.edu", "/dir1/dir2", now, base::Time(),
base::Time(), base::Time(), false, false, CookieSameSite::LAX_MODE,
COOKIE_PRIORITY_DEFAULT));
cookies.push_back(CanonicalCookie::CreateUnsafeCookieForTesting(
"host_path_1", "A", url_top_level_domain_plus_2, "/dir1", now,
base::Time(), base::Time(), base::Time(), false, false,
CookieSameSite::LAX_MODE, COOKIE_PRIORITY_DEFAULT));
cookies.push_back(CanonicalCookie::CreateUnsafeCookieForTesting(
"host_path_2", "B", url_top_level_domain_plus_2, "/dir1/dir2", now,
base::Time(), base::Time(), base::Time(), false, false,
CookieSameSite::LAX_MODE, COOKIE_PRIORITY_DEFAULT));
cookies.push_back(CanonicalCookie::CreateUnsafeCookieForTesting(
"__Host-pc_1", "A", url_top_level_domain_secure, "/", now, base::Time(),
base::Time(), base::Time(), true, false, CookieSameSite::NO_RESTRICTION,
CookiePriority::COOKIE_PRIORITY_DEFAULT,
CookiePartitionKey::FromURLForTesting(GURL(kTopLevelDomainPlus1))));
cookies.push_back(CanonicalCookie::CreateUnsafeCookieForTesting(
"__Host-pc_2", "B", url_top_level_domain_secure, "/", now, base::Time(),
base::Time(), base::Time(), true, false, CookieSameSite::NO_RESTRICTION,
CookiePriority::COOKIE_PRIORITY_DEFAULT,
CookiePartitionKey::FromURLForTesting(GURL(kTopLevelDomainPlus1))));
for (auto& cookie : cookies) {
GURL source_url = cookie_util::SimulatedCookieSource(
*cookie, cookie->SecureAttribute() ? "https" : "http");
EXPECT_TRUE(this->SetCanonicalCookie(cm, std::move(cookie), source_url,
true ));
}
EXPECT_EQ(cookies.size(), this->GetAllCookies(cm).size());
return now + base::Milliseconds(100);
}
Time GetFirstCookieAccessDate(CookieMonster* cm) {
const CookieList all_cookies(this->GetAllCookies(cm));
return all_cookies.front().LastAccessDate();
}
bool FindAndDeleteCookie(CookieMonster* cm,
const std::string& domain,
const std::string& name) {
CookieList cookies = this->GetAllCookies(cm);
for (auto& cookie : cookies)
if (cookie.Domain() == domain && cookie.Name() == name)
return this->DeleteCanonicalCookie(cm, cookie);
return false;
}
void TestHostGarbageCollectHelper() {
int domain_max_cookies = CookieMonster::kDomainMaxCookies;
int domain_purge_cookies = CookieMonster::kDomainPurgeCookies;
const int more_than_enough_cookies = domain_max_cookies + 10;
{
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
for (int i = 0; i < more_than_enough_cookies; ++i) {
std::string cookie = base::StringPrintf("a%03d=b", i);
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), cookie));
std::string cookies = this->GetCookies(cm.get(), http_www_foo_.url());
EXPECT_NE(cookies.find(cookie), std::string::npos);
EXPECT_LE(std::ranges::count(cookies, '='), domain_max_cookies);
}
}
GURL url_google_specific(http_www_foo_.Format("http://www.gmail.%D"));
{
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
for (int i = 0; i < more_than_enough_cookies; ++i) {
std::string cookie_general = base::StringPrintf("a%03d=b", i);
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), cookie_general));
std::string cookie_specific = base::StringPrintf("c%03d=b", i);
EXPECT_TRUE(SetCookie(cm.get(), url_google_specific, cookie_specific));
std::string cookies_general =
this->GetCookies(cm.get(), http_www_foo_.url());
EXPECT_NE(cookies_general.find(cookie_general), std::string::npos);
std::string cookies_specific =
this->GetCookies(cm.get(), url_google_specific);
EXPECT_NE(cookies_specific.find(cookie_specific), std::string::npos);
EXPECT_LE((std::ranges::count(cookies_general, '=') +
std::ranges::count(cookies_specific, '=')),
domain_max_cookies);
}
std::string cookies_general =
this->GetCookies(cm.get(), http_www_foo_.url());
std::string cookies_specific =
this->GetCookies(cm.get(), url_google_specific);
int total_cookies = (std::ranges::count(cookies_general, '=') +
std::ranges::count(cookies_specific, '='));
EXPECT_GE(total_cookies, domain_max_cookies - domain_purge_cookies);
EXPECT_LE(total_cookies, domain_max_cookies);
}
{
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
GURL url;
for (int domain_num = 0; domain_num < 3; ++domain_num) {
url = GURL(base::StringPrintf("http://domain%d.test", domain_num));
for (int i = 0; i < more_than_enough_cookies; ++i) {
std::string cookie = base::StringPrintf("a%03d=b", i);
EXPECT_TRUE(SetCookie(cm.get(), url, cookie));
std::string cookies = this->GetCookies(cm.get(), url);
EXPECT_NE(cookies.find(cookie), std::string::npos);
EXPECT_LE(std::ranges::count(cookies, '='), domain_max_cookies);
}
}
for (int i = 0; i < domain_purge_cookies * 2; ++i) {
std::string cookie = base::StringPrintf("b%03d=b", i);
EXPECT_TRUE(SetCookie(cm.get(), url, cookie));
std::string cookies = this->GetCookies(cm.get(), url);
EXPECT_NE(cookies.find(cookie), std::string::npos);
EXPECT_LE(std::ranges::count(cookies, '='), domain_max_cookies);
}
}
}
CookiePriority CharToPriority(char ch) {
switch (ch) {
case 'L':
return COOKIE_PRIORITY_LOW;
case 'M':
return COOKIE_PRIORITY_MEDIUM;
case 'H':
return COOKIE_PRIORITY_HIGH;
}
NOTREACHED();
}
void TestPriorityCookieCase(CookieMonster* cm,
const std::string& coded_priority_str,
size_t expected_low_count,
size_t expected_medium_count,
size_t expected_high_count,
size_t expected_nonsecure,
size_t expected_secure) {
SCOPED_TRACE(coded_priority_str);
this->DeleteAll(cm);
int next_cookie_id = 0;
std::array<std::array<std::vector<int>, 3>, 2> id_list;
std::vector<std::pair<bool, CookiePriority>> cookie_data;
for (const std::string& token :
base::SplitString(coded_priority_str, " ", base::TRIM_WHITESPACE,
base::SPLIT_WANT_ALL)) {
DCHECK(!token.empty());
bool is_secure = token.back() == 'S';
CookiePriority priority = CharToPriority(token[token.size() - 2]);
int rep = 1;
if (!token.empty()) {
bool result = base::StringToInt(
std::string_view(token.begin(), token.end() - 2), &rep);
DCHECK(result);
}
for (; rep > 0; --rep, ++next_cookie_id) {
std::string cookie =
base::StringPrintf("a%d=b;priority=%s;%s", next_cookie_id,
CookiePriorityToString(priority).c_str(),
is_secure ? "secure" : "");
EXPECT_TRUE(SetCookie(
cm, is_secure ? https_www_foo_.url() : http_www_foo_.url(),
cookie));
cookie_data.emplace_back(is_secure, priority);
id_list[is_secure][priority].push_back(next_cookie_id);
}
}
int num_cookies = static_cast<int>(cookie_data.size());
std::array<std::array<std::vector<int>, 3>, 2> surviving_id_list;
std::string cookie_str = this->GetCookies(cm, https_www_foo_.url());
if (cookie_util::IsOriginBoundCookiesPartiallyEnabled()) {
std::string cookie_str_insecure =
this->GetCookies(cm, http_www_foo_.url());
std::vector<std::string_view> to_be_combined;
if (!cookie_str.empty()) {
to_be_combined.push_back(cookie_str);
}
if (!cookie_str_insecure.empty()) {
to_be_combined.push_back(cookie_str_insecure);
}
cookie_str = base::JoinString(to_be_combined, "; ");
}
size_t num_nonsecure = 0;
size_t num_secure = 0;
for (const std::string& token : base::SplitString(
cookie_str, ";", base::TRIM_WHITESPACE, base::SPLIT_WANT_ALL)) {
int id = -1;
bool result = base::StringToInt(
std::string_view(token.begin() + 1, token.end() - 2), &id);
DCHECK(result);
DCHECK_GE(id, 0);
DCHECK_LT(id, num_cookies);
surviving_id_list[cookie_data[id].first][cookie_data[id].second]
.push_back(id);
if (cookie_data[id].first)
num_secure += 1;
else
num_nonsecure += 1;
}
EXPECT_EQ(expected_nonsecure, num_nonsecure);
EXPECT_EQ(expected_secure, num_secure);
std::array<size_t, 3> expected_count = {
expected_low_count,
expected_medium_count,
expected_high_count,
};
for (int i = 0; i < 3; ++i) {
size_t num_for_priority =
surviving_id_list[0][i].size() + surviving_id_list[1][i].size();
EXPECT_EQ(expected_count[i], num_for_priority);
if (expected_count[i] == num_for_priority) {
std::sort(surviving_id_list[0][i].begin(),
surviving_id_list[0][i].end());
EXPECT_TRUE(std::equal(
surviving_id_list[0][i].begin(), surviving_id_list[0][i].end(),
id_list[0][i].end() - surviving_id_list[0][i].size()));
std::sort(surviving_id_list[1][i].begin(),
surviving_id_list[1][i].end());
EXPECT_TRUE(std::equal(
surviving_id_list[1][i].begin(), surviving_id_list[1][i].end(),
id_list[1][i].end() - surviving_id_list[1][i].size()));
}
}
}
struct CookiesEntry {
size_t num_cookies;
bool is_secure;
};
typedef std::pair<size_t, size_t> AltHosts;
void TestSecureCookieEviction(base::span<const CookiesEntry> cookie_entries,
size_t expected_secure_cookies,
size_t expected_non_secure_cookies,
const AltHosts* alt_host_entries) {
std::unique_ptr<CookieMonster> cm;
if (alt_host_entries == nullptr) {
cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
} else {
cm = CreateMonsterFromStoreForGC(
alt_host_entries->first, alt_host_entries->first,
alt_host_entries->second, alt_host_entries->second, 60);
}
int next_cookie_id = 0;
for (const auto& cookie_entry : cookie_entries) {
for (size_t j = 0; j < cookie_entry.num_cookies; j++) {
std::string cookie;
if (cookie_entry.is_secure)
cookie = base::StringPrintf("a%d=b; Secure", next_cookie_id);
else
cookie = base::StringPrintf("a%d=b", next_cookie_id);
EXPECT_TRUE(SetCookie(cm.get(), https_www_foo_.url(), cookie));
++next_cookie_id;
}
}
CookieList cookies = this->GetAllCookies(cm.get());
EXPECT_EQ(expected_secure_cookies + expected_non_secure_cookies,
cookies.size());
size_t total_secure_cookies = 0;
size_t total_non_secure_cookies = 0;
for (const auto& cookie : cookies) {
if (cookie.SecureAttribute()) {
++total_secure_cookies;
} else {
++total_non_secure_cookies;
}
}
EXPECT_EQ(expected_secure_cookies, total_secure_cookies);
EXPECT_EQ(expected_non_secure_cookies, total_non_secure_cookies);
}
void TestPriorityAwareGarbageCollectHelperNonSecure() {
DCHECK_EQ(180U, CookieMonster::kDomainMaxCookies);
DCHECK_EQ(150U, CookieMonster::kDomainMaxCookies -
CookieMonster::kDomainPurgeCookies);
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
TestPriorityCookieCase(cm.get(), "181LN", 150U, 0U, 0U, 150U, 0U);
TestPriorityCookieCase(cm.get(), "181MN", 0U, 150U, 0U, 150U, 0U);
TestPriorityCookieCase(cm.get(), "181HN", 0U, 0U, 150U, 150U, 0U);
TestPriorityCookieCase(cm.get(), "10HN 171MN", 0U, 140U, 10U, 150U, 0U);
TestPriorityCookieCase(cm.get(), "141MN 40LN", 30U, 120U, 0U, 150U, 0U);
TestPriorityCookieCase(cm.get(), "101HN 80MN", 0U, 50U, 100U, 150U, 0U);
TestPriorityCookieCase(cm.get(), "31LN 50MN 100HN", 30U, 50U, 70U, 150U,
0U);
TestPriorityCookieCase(cm.get(), "51MN 100HN 30LN", 30U, 50U, 70U, 150U,
0U);
TestPriorityCookieCase(cm.get(), "101HN 50MN 30LN", 30U, 50U, 70U, 150U,
0U);
TestPriorityCookieCase(cm.get(), "81HN 60MN 40LN", 30U, 50U, 70U, 150U, 0U);
TestPriorityCookieCase(cm.get(), "21HN 60MN 40LN 60HN", 30U, 50U, 70U, 150U,
0U);
TestPriorityCookieCase(cm.get(), "11HN 10MN 20LN 110MN 20LN 10HN", 30U, 99U,
21U, 150U, 0U);
TestPriorityCookieCase(cm.get(), "11LN 10MN 140HN 10MN 10LN", 21U, 20U,
109U, 150U, 0U);
TestPriorityCookieCase(cm.get(), "11MN 10HN 10LN 60MN 90HN", 10U, 50U, 90U,
150U, 0U);
TestPriorityCookieCase(cm.get(), "11MN 10HN 10LN 90MN 60HN", 10U, 70U, 70U,
150U, 0U);
TestPriorityCookieCase(cm.get(), "50LN 131HN", 30U, 0U, 120U, 150U, 0U);
TestPriorityCookieCase(cm.get(), "131HN 50LN", 30U, 0U, 120U, 150U, 0U);
TestPriorityCookieCase(cm.get(), "50HN 50LN 81HN", 30U, 0U, 120U, 150U, 0U);
TestPriorityCookieCase(cm.get(), "81HN 50LN 50HN", 30U, 0U, 120U, 150U, 0U);
}
void TestPriorityAwareGarbageCollectHelperSecure() {
DCHECK_EQ(180U, CookieMonster::kDomainMaxCookies);
DCHECK_EQ(150U, CookieMonster::kDomainMaxCookies -
CookieMonster::kDomainPurgeCookies);
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
TestPriorityCookieCase(cm.get(), "181LS", 150U, 0U, 0U, 0U, 150U);
TestPriorityCookieCase(cm.get(), "181MS", 0U, 150U, 0U, 0U, 150U);
TestPriorityCookieCase(cm.get(), "181HS", 0U, 0U, 150U, 0U, 150U);
TestPriorityCookieCase(cm.get(), "10HS 171MS", 0U, 140U, 10U, 0U, 150U);
TestPriorityCookieCase(cm.get(), "141MS 40LS", 30U, 120U, 0U, 0U, 150U);
TestPriorityCookieCase(cm.get(), "101HS 80MS", 0U, 50U, 100U, 0U, 150U);
TestPriorityCookieCase(cm.get(), "31LS 50MS 100HS", 30U, 50U, 70U, 0U,
150U);
TestPriorityCookieCase(cm.get(), "51MS 100HS 30LS", 30U, 50U, 70U, 0U,
150U);
TestPriorityCookieCase(cm.get(), "101HS 50MS 30LS", 30U, 50U, 70U, 0U,
150U);
TestPriorityCookieCase(cm.get(), "81HS 60MS 40LS", 30U, 50U, 70U, 0U, 150U);
TestPriorityCookieCase(cm.get(), "21HS 60MS 40LS 60HS", 30U, 50U, 70U, 0U,
150U);
TestPriorityCookieCase(cm.get(), "11HS 10MS 20LS 110MS 20LS 10HS", 30U, 99U,
21U, 0U, 150U);
TestPriorityCookieCase(cm.get(), "11LS 10MS 140HS 10MS 10LS", 21U, 20U,
109U, 0U, 150U);
TestPriorityCookieCase(cm.get(), "11MS 10HS 10LS 60MS 90HS", 10U, 50U, 90U,
0U, 150U);
TestPriorityCookieCase(cm.get(), "11MS 10HS 10LS 90MS 60HS", 10U, 70U, 70U,
0U, 150U);
}
void TestPriorityAwareGarbageCollectHelperMixed() {
DCHECK_EQ(180U, CookieMonster::kDomainMaxCookies);
DCHECK_EQ(150U, CookieMonster::kDomainMaxCookies -
CookieMonster::kDomainPurgeCookies);
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
TestPriorityCookieCase(cm.get(), "1LN 180LS", 150U, 0U, 0U, 0U, 150U);
TestPriorityCookieCase(cm.get(), "1MN 180MS", 0U, 150U, 0U, 0U, 150U);
TestPriorityCookieCase(cm.get(), "1HN 180HS", 0U, 0U, 150U, 0U, 150U);
TestPriorityCookieCase(cm.get(), "180LS 1LN", 150U, 0U, 0U, 0U, 150U);
TestPriorityCookieCase(cm.get(), "180MS 1MN", 0U, 150U, 0U, 0U, 150U);
TestPriorityCookieCase(cm.get(), "180HS 1HN", 0U, 0U, 150U, 0U, 150U);
TestPriorityCookieCase(cm.get(), "39LN 1LS 141HN", 30U, 0U, 120U, 149U, 1U);
TestPriorityCookieCase(cm.get(), "29LN 1LS 59MN 1MS 91HS", 30U, 50U, 70U,
78U, 72U);
TestPriorityCookieCase(cm.get(), "180LS 1MN", 149U, 1U, 0U, 1U, 149U);
TestPriorityCookieCase(cm.get(), "180LS 1HN", 149U, 0U, 1U, 1U, 149U);
TestPriorityCookieCase(cm.get(), "1MN 180LS", 149U, 1U, 0U, 1U, 149U);
TestPriorityCookieCase(cm.get(), "1HN 180LS", 149U, 0U, 1U, 1U, 149U);
TestPriorityCookieCase(cm.get(), "180MS 1HN", 0U, 149U, 1U, 1U, 149U);
TestPriorityCookieCase(cm.get(), "1HN 180MS", 0U, 149U, 1U, 1U, 149U);
TestPriorityCookieCase(cm.get(), "1LS 180LN", 150U, 0U, 0U, 149U, 1U);
TestPriorityCookieCase(cm.get(), "100LS 81LN", 150U, 0U, 0U, 50U, 100U);
TestPriorityCookieCase(cm.get(), "150LS 31LN", 150U, 0U, 0U, 0U, 150U);
TestPriorityCookieCase(cm.get(), "1LS 180HN", 1U, 0U, 149U, 149U, 1U);
TestPriorityCookieCase(cm.get(), "100LS 81HN", 69U, 0U, 81U, 81U, 69U);
TestPriorityCookieCase(cm.get(), "150LS 31HN", 119U, 0U, 31U, 31U, 119U);
TestPriorityCookieCase(cm.get(), "50HN 50LS 81HS", 30U, 0U, 120U, 39U,
111U);
TestPriorityCookieCase(cm.get(), "11MS 10HN 10LS 90MN 60HN", 10U, 70U, 70U,
129U, 21U);
TestPriorityCookieCase(cm.get(), "40LS 40LN 101HS", 49U, 0U, 101U, 9U,
141U);
TestPriorityCookieCase(cm.get(), "100HS 100LN 100MN", 30U, 76U, 70U, 106U,
70U);
}
std::unique_ptr<CookieMonster> CreateMonsterForGC(int num_cookies) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
base::Time creation_time = base::Time::Now();
for (int i = 0; i < num_cookies; i++) {
std::unique_ptr<CanonicalCookie> cc(
CanonicalCookie::CreateUnsafeCookieForTesting(
"a", "1", base::StringPrintf("h%05d.izzle", i), "/",
creation_time, base::Time(),
creation_time, creation_time,
true,
false, CookieSameSite::NO_RESTRICTION,
COOKIE_PRIORITY_DEFAULT));
GURL source_url = cookie_util::SimulatedCookieSource(*cc, "https");
cm->SetCanonicalCookieAsync(std::move(cc), source_url,
CookieOptions::MakeAllInclusive(),
CookieStore::SetCookiesCallback());
}
return cm;
}
bool IsCookieInList(const CanonicalCookie& cookie, const CookieList& list) {
for (const auto& c : list) {
if (c.Name() == cookie.Name() && c.Value() == cookie.Value() &&
c.Domain() == cookie.Domain() && c.Path() == cookie.Path() &&
c.CreationDate() == cookie.CreationDate() &&
c.ExpiryDate() == cookie.ExpiryDate() &&
c.LastAccessDate() == cookie.LastAccessDate() &&
c.LastUpdateDate() == cookie.LastUpdateDate() &&
c.SecureAttribute() == cookie.SecureAttribute() &&
c.IsHttpOnly() == cookie.IsHttpOnly() &&
c.Priority() == cookie.Priority()) {
return true;
}
}
return false;
}
RecordingNetLogObserver net_log_;
};
using CookieMonsterTest = CookieMonsterTestBase<CookieMonsterTestTraits>;
class CookieMonsterTestGarbageCollectionObc
: public CookieMonsterTest,
public testing::WithParamInterface<std::tuple<bool, bool>> {
public:
CookieMonsterTestGarbageCollectionObc() {
scoped_feature_list_.InitWithFeatureStates(
{{net::features::kEnableSchemeBoundCookies, IsSchemeBoundEnabled()},
{net::features::kEnablePortBoundCookies, IsPortBoundEnabled()}});
}
bool IsSchemeBoundEnabled() const { return std::get<0>(GetParam()); }
bool IsPortBoundEnabled() const { return std::get<1>(GetParam()); }
private:
base::test::ScopedFeatureList scoped_feature_list_;
};
using CookieMonsterTestPriorityGarbageCollectionObc =
CookieMonsterTestGarbageCollectionObc;
struct CookiesInputInfo {
const GURL url;
const std::string name;
const std::string value;
const std::string domain;
const std::string path;
const base::Time expiration_time;
bool secure;
bool http_only;
CookieSameSite same_site;
CookiePriority priority;
};
}
class DeferredCookieTaskTest : public CookieMonsterTest {
protected:
DeferredCookieTaskTest() {
persistent_store_ = base::MakeRefCounted<MockPersistentCookieStore>();
persistent_store_->set_store_load_commands(true);
cookie_monster_ = std::make_unique<CookieMonster>(persistent_store_.get(),
net::NetLog::Get());
}
void DeclareLoadedCookie(const GURL& url,
const std::string& cookie_line,
base::Time creation_time) {
AddCookieToList(url, cookie_line, creation_time, &loaded_cookies_);
}
void ExecuteLoads(CookieStoreCommand::Type type) {
const auto& commands = persistent_store_->commands();
for (size_t i = 0; i < commands.size(); ++i) {
if (commands[i].type == type) {
persistent_store_->TakeCallbackAt(i).Run(std::move(loaded_cookies_));
}
}
}
std::string CommandSummary(
const MockPersistentCookieStore::CommandList& commands) {
std::string out;
for (const auto& command : commands) {
switch (command.type) {
case CookieStoreCommand::LOAD:
base::StrAppend(&out, {"LOAD; "});
break;
case CookieStoreCommand::LOAD_COOKIES_FOR_KEY:
base::StrAppend(&out, {"LOAD_FOR_KEY:", command.key, "; "});
break;
case CookieStoreCommand::ADD:
base::StrAppend(&out, {"ADD; "});
break;
case CookieStoreCommand::REMOVE:
base::StrAppend(&out, {"REMOVE; "});
break;
}
}
return out;
}
std::string TakeCommandSummary() {
return CommandSummary(persistent_store_->TakeCommands());
}
std::vector<std::unique_ptr<CanonicalCookie>> loaded_cookies_;
std::unique_ptr<CookieMonster> cookie_monster_;
scoped_refptr<MockPersistentCookieStore> persistent_store_;
};
class CookieMonsterLegacyScopeTest : public CookieMonsterTest {
public:
CookieMonsterLegacyScopeTest() {
scoped_feature_list_.InitWithFeatures(
{net::features::kEnableSchemeBoundCookies,
net::features::kEnablePortBoundCookies},
{});
access_delegate_ = std::make_unique<TestCookieAccessDelegate>();
}
protected:
GURL example_with_https_port_value_80_ = GURL("https://www.example.com:80/");
GURL example_with_https_port_value_800_ =
GURL("https://www.example.com:800/");
GURL example_with_https_port_value_8000_ =
GURL("https://www.example.com:8000/");
GURL example_with_https_port_value_10_ = GURL("https://www.example.com:10/");
std::unique_ptr<TestCookieAccessDelegate> access_delegate_;
private:
base::test::ScopedFeatureList scoped_feature_list_;
};
class TestPrefDelegate : public CookieMonster::PrefDelegate {
public:
const base::Value::Dict& GetLegacyDomains() const override {
return test_dict;
}
void SetLegacyDomains(base::Value::Dict dict) override {
test_dict = std::move(dict);
}
void WaitForPrefLoad(base::OnceClosure pref_loaded_callback) override {
NOTREACHED();
}
bool IsPrefReady() override { return true; }
base::Value::Dict test_dict;
};
TEST_F(DeferredCookieTaskTest, DeferredGetCookieList) {
DeclareLoadedCookie(http_www_foo_.url(),
"X=1; path=/" + FutureCookieExpirationString(),
Time::Now() + base::Days(3));
GetCookieListCallback call1;
cookie_monster_->GetCookieListWithOptionsAsync(
http_www_foo_.url(), CookieOptions::MakeAllInclusive(),
CookiePartitionKeyCollection(), call1.MakeCallback());
base::RunLoop().RunUntilIdle();
EXPECT_FALSE(call1.was_run());
ExecuteLoads(CookieStoreCommand::LOAD_COOKIES_FOR_KEY);
call1.WaitUntilDone();
EXPECT_THAT(call1.cookies(), MatchesCookieLine("X=1"));
EXPECT_EQ("LOAD; LOAD_FOR_KEY:foo.com; ", TakeCommandSummary());
GetCookieListCallback call2;
cookie_monster_->GetCookieListWithOptionsAsync(
http_www_foo_.url(), CookieOptions::MakeAllInclusive(),
CookiePartitionKeyCollection(), call2.MakeCallback());
EXPECT_THAT(call2.cookies(), MatchesCookieLine("X=1"));
EXPECT_EQ("", TakeCommandSummary());
}
TEST_F(DeferredCookieTaskTest, DeferredSetCookie) {
cookie_monster_->SetPersistSessionCookies(true);
ResultSavingCookieCallback<CookieAccessResult> call1;
cookie_monster_->SetCanonicalCookieAsync(
CanonicalCookie::CreateForTesting(http_www_foo_.url(), "A=B",
base::Time::Now()),
http_www_foo_.url(), CookieOptions::MakeAllInclusive(),
call1.MakeCallback());
base::RunLoop().RunUntilIdle();
EXPECT_FALSE(call1.was_run());
ExecuteLoads(CookieStoreCommand::LOAD_COOKIES_FOR_KEY);
call1.WaitUntilDone();
EXPECT_TRUE(call1.result().status.IsInclude());
EXPECT_EQ("LOAD; LOAD_FOR_KEY:foo.com; ADD; ", TakeCommandSummary());
ResultSavingCookieCallback<CookieAccessResult> call2;
cookie_monster_->SetCanonicalCookieAsync(
CanonicalCookie::CreateForTesting(http_www_foo_.url(), "X=Y",
base::Time::Now()),
http_www_foo_.url(), CookieOptions::MakeAllInclusive(),
call2.MakeCallback());
ASSERT_TRUE(call2.was_run());
EXPECT_TRUE(call2.result().status.IsInclude());
EXPECT_EQ("ADD; ", TakeCommandSummary());
}
TEST_F(DeferredCookieTaskTest, DeferredSetAllCookies) {
cookie_monster_->SetPersistSessionCookies(true);
CookieList list;
list.push_back(*CanonicalCookie::CreateUnsafeCookieForTesting(
"A", "B", "." + http_www_foo_.domain(), "/", base::Time::Now(),
base::Time(), base::Time(), base::Time(), false, true,
CookieSameSite::NO_RESTRICTION, COOKIE_PRIORITY_DEFAULT));
list.push_back(*CanonicalCookie::CreateUnsafeCookieForTesting(
"C", "D", "." + http_www_foo_.domain(), "/", base::Time::Now(),
base::Time(), base::Time(), base::Time(), false, true,
CookieSameSite::NO_RESTRICTION, COOKIE_PRIORITY_DEFAULT));
ResultSavingCookieCallback<CookieAccessResult> call1;
cookie_monster_->SetAllCookiesAsync(list, call1.MakeCallback());
base::RunLoop().RunUntilIdle();
EXPECT_FALSE(call1.was_run());
ExecuteLoads(CookieStoreCommand::LOAD);
call1.WaitUntilDone();
EXPECT_TRUE(call1.result().status.IsInclude());
EXPECT_EQ("LOAD; ADD; ADD; ", TakeCommandSummary());
ResultSavingCookieCallback<CookieAccessResult> call2;
cookie_monster_->SetAllCookiesAsync(list, call2.MakeCallback());
ASSERT_TRUE(call2.was_run());
EXPECT_TRUE(call2.result().status.IsInclude());
EXPECT_EQ("REMOVE; REMOVE; ADD; ADD; ", TakeCommandSummary());
}
TEST_F(DeferredCookieTaskTest, DeferredGetAllCookies) {
DeclareLoadedCookie(http_www_foo_.url(),
"X=1; path=/" + FutureCookieExpirationString(),
Time::Now() + base::Days(3));
GetAllCookiesCallback call1;
cookie_monster_->GetAllCookiesAsync(call1.MakeCallback());
base::RunLoop().RunUntilIdle();
EXPECT_FALSE(call1.was_run());
ExecuteLoads(CookieStoreCommand::LOAD);
call1.WaitUntilDone();
EXPECT_THAT(call1.cookies(), MatchesCookieLine("X=1"));
EXPECT_EQ("LOAD; ", TakeCommandSummary());
GetAllCookiesCallback call2;
cookie_monster_->GetAllCookiesAsync(call2.MakeCallback());
EXPECT_TRUE(call2.was_run());
EXPECT_THAT(call2.cookies(), MatchesCookieLine("X=1"));
EXPECT_EQ("", TakeCommandSummary());
}
TEST_F(DeferredCookieTaskTest, DeferredGetAllForUrlCookies) {
DeclareLoadedCookie(http_www_foo_.url(),
"X=1; path=/" + FutureCookieExpirationString(),
Time::Now() + base::Days(3));
GetCookieListCallback call1;
cookie_monster_->GetCookieListWithOptionsAsync(
http_www_foo_.url(), CookieOptions::MakeAllInclusive(),
CookiePartitionKeyCollection(), call1.MakeCallback());
base::RunLoop().RunUntilIdle();
EXPECT_FALSE(call1.was_run());
ExecuteLoads(CookieStoreCommand::LOAD_COOKIES_FOR_KEY);
call1.WaitUntilDone();
EXPECT_THAT(call1.cookies(), MatchesCookieLine("X=1"));
EXPECT_EQ("LOAD; LOAD_FOR_KEY:foo.com; ", TakeCommandSummary());
GetCookieListCallback call2;
cookie_monster_->GetCookieListWithOptionsAsync(
http_www_foo_.url(), CookieOptions::MakeAllInclusive(),
CookiePartitionKeyCollection(), call2.MakeCallback());
EXPECT_TRUE(call2.was_run());
EXPECT_THAT(call2.cookies(), MatchesCookieLine("X=1"));
EXPECT_EQ("", TakeCommandSummary());
}
TEST_F(DeferredCookieTaskTest, DeferredGetAllForUrlWithOptionsCookies) {
DeclareLoadedCookie(http_www_foo_.url(),
"X=1; path=/" + FutureCookieExpirationString(),
Time::Now() + base::Days(3));
GetCookieListCallback call1;
cookie_monster_->GetCookieListWithOptionsAsync(
http_www_foo_.url(), CookieOptions::MakeAllInclusive(),
CookiePartitionKeyCollection(), call1.MakeCallback());
base::RunLoop().RunUntilIdle();
EXPECT_FALSE(call1.was_run());
ExecuteLoads(CookieStoreCommand::LOAD_COOKIES_FOR_KEY);
call1.WaitUntilDone();
EXPECT_THAT(call1.cookies(), MatchesCookieLine("X=1"));
EXPECT_EQ("LOAD; LOAD_FOR_KEY:foo.com; ", TakeCommandSummary());
GetCookieListCallback call2;
cookie_monster_->GetCookieListWithOptionsAsync(
http_www_foo_.url(), CookieOptions::MakeAllInclusive(),
CookiePartitionKeyCollection(), call2.MakeCallback());
EXPECT_TRUE(call2.was_run());
EXPECT_THAT(call2.cookies(), MatchesCookieLine("X=1"));
EXPECT_EQ("", TakeCommandSummary());
}
TEST_F(DeferredCookieTaskTest, DeferredDeleteAllCookies) {
DeclareLoadedCookie(http_www_foo_.url(),
"X=1; path=/" + FutureCookieExpirationString(),
Time::Now() + base::Days(3));
ResultSavingCookieCallback<uint32_t> call1;
cookie_monster_->DeleteAllAsync(call1.MakeCallback());
base::RunLoop().RunUntilIdle();
EXPECT_FALSE(call1.was_run());
ExecuteLoads(CookieStoreCommand::LOAD);
call1.WaitUntilDone();
EXPECT_EQ(1u, call1.result());
EXPECT_EQ("LOAD; REMOVE; ", TakeCommandSummary());
ResultSavingCookieCallback<uint32_t> call2;
cookie_monster_->DeleteAllAsync(call2.MakeCallback());
call2.WaitUntilDone();
EXPECT_EQ(0u, call2.result());
EXPECT_EQ("", TakeCommandSummary());
}
TEST_F(DeferredCookieTaskTest, DeferredDeleteAllCreatedInTimeRangeCookies) {
const TimeRange time_range(base::Time(), base::Time::Now());
ResultSavingCookieCallback<uint32_t> call1;
cookie_monster_->DeleteAllCreatedInTimeRangeAsync(time_range,
call1.MakeCallback());
base::RunLoop().RunUntilIdle();
EXPECT_FALSE(call1.was_run());
ExecuteLoads(CookieStoreCommand::LOAD);
call1.WaitUntilDone();
EXPECT_EQ(0u, call1.result());
EXPECT_EQ("LOAD; ", TakeCommandSummary());
ResultSavingCookieCallback<uint32_t> call2;
cookie_monster_->DeleteAllCreatedInTimeRangeAsync(time_range,
call2.MakeCallback());
call2.WaitUntilDone();
EXPECT_EQ(0u, call2.result());
EXPECT_EQ("", TakeCommandSummary());
}
TEST_F(DeferredCookieTaskTest,
DeferredDeleteAllWithPredicateCreatedInTimeRangeCookies) {
ResultSavingCookieCallback<uint32_t> call1;
cookie_monster_->DeleteAllMatchingInfoAsync(
CookieDeletionInfo(Time(), Time::Now()), call1.MakeCallback());
base::RunLoop().RunUntilIdle();
EXPECT_FALSE(call1.was_run());
ExecuteLoads(CookieStoreCommand::LOAD);
call1.WaitUntilDone();
EXPECT_EQ(0u, call1.result());
EXPECT_EQ("LOAD; ", TakeCommandSummary());
ResultSavingCookieCallback<uint32_t> call2;
cookie_monster_->DeleteAllMatchingInfoAsync(
CookieDeletionInfo(Time(), Time::Now()), call2.MakeCallback());
call2.WaitUntilDone();
EXPECT_EQ(0u, call2.result());
EXPECT_EQ("", TakeCommandSummary());
}
TEST_F(DeferredCookieTaskTest, DeferredDeleteMatchingCookies) {
ResultSavingCookieCallback<uint32_t> call1;
cookie_monster_->DeleteMatchingCookiesAsync(
base::BindRepeating(
[](const net::CanonicalCookie& cookie) { return true; }),
call1.MakeCallback());
base::RunLoop().RunUntilIdle();
EXPECT_FALSE(call1.was_run());
ExecuteLoads(CookieStoreCommand::LOAD);
call1.WaitUntilDone();
EXPECT_EQ(0u, call1.result());
EXPECT_EQ("LOAD; ", TakeCommandSummary());
ResultSavingCookieCallback<uint32_t> call2;
cookie_monster_->DeleteMatchingCookiesAsync(
base::BindRepeating(
[](const net::CanonicalCookie& cookie) { return true; }),
call2.MakeCallback());
call2.WaitUntilDone();
EXPECT_EQ(0u, call2.result());
EXPECT_EQ("", TakeCommandSummary());
}
TEST_F(DeferredCookieTaskTest, DeferredDeleteCanonicalCookie) {
std::unique_ptr<CanonicalCookie> cookie = BuildCanonicalCookie(
http_www_foo_.url(), "X=1; path=/", base::Time::Now());
ResultSavingCookieCallback<uint32_t> call1;
cookie_monster_->DeleteCanonicalCookieAsync(*cookie, call1.MakeCallback());
base::RunLoop().RunUntilIdle();
EXPECT_FALSE(call1.was_run());
ExecuteLoads(CookieStoreCommand::LOAD);
call1.WaitUntilDone();
EXPECT_EQ(0u, call1.result());
EXPECT_EQ("LOAD; ", TakeCommandSummary());
ResultSavingCookieCallback<uint32_t> call2;
cookie_monster_->DeleteCanonicalCookieAsync(*cookie, call2.MakeCallback());
call2.WaitUntilDone();
EXPECT_EQ(0u, call2.result());
EXPECT_EQ("", TakeCommandSummary());
}
TEST_F(DeferredCookieTaskTest, DeferredDeleteSessionCookies) {
ResultSavingCookieCallback<uint32_t> call1;
cookie_monster_->DeleteSessionCookiesAsync(call1.MakeCallback());
base::RunLoop().RunUntilIdle();
EXPECT_FALSE(call1.was_run());
ExecuteLoads(CookieStoreCommand::LOAD);
call1.WaitUntilDone();
EXPECT_EQ(0u, call1.result());
EXPECT_EQ("LOAD; ", TakeCommandSummary());
ResultSavingCookieCallback<uint32_t> call2;
cookie_monster_->DeleteSessionCookiesAsync(call2.MakeCallback());
call2.WaitUntilDone();
EXPECT_EQ(0u, call2.result());
EXPECT_EQ("", TakeCommandSummary());
}
TEST_F(DeferredCookieTaskTest, DeferredTaskOrder) {
cookie_monster_->SetPersistSessionCookies(true);
DeclareLoadedCookie(http_www_foo_.url(),
"X=1; path=/" + FutureCookieExpirationString(),
Time::Now() + base::Days(3));
bool get_cookie_list_callback_was_run = false;
GetCookieListCallback get_cookie_list_callback_deferred;
ResultSavingCookieCallback<CookieAccessResult> set_cookies_callback;
base::RunLoop run_loop;
cookie_monster_->GetCookieListWithOptionsAsync(
http_www_foo_.url(), CookieOptions::MakeAllInclusive(),
CookiePartitionKeyCollection(),
base::BindLambdaForTesting(
[&](const CookieAccessResultList& cookies,
const CookieAccessResultList& excluded_list) {
get_cookie_list_callback_was_run = true;
EXPECT_FALSE(set_cookies_callback.was_run());
EXPECT_THAT(cookies, MatchesCookieLine("X=1"));
EXPECT_EQ("LOAD; LOAD_FOR_KEY:foo.com; ",
CommandSummary(persistent_store_->commands()));
cookie_monster_->GetCookieListWithOptionsAsync(
http_www_foo_.url(), CookieOptions::MakeAllInclusive(),
CookiePartitionKeyCollection(),
get_cookie_list_callback_deferred.MakeCallback());
run_loop.Quit();
}));
cookie_monster_->SetCanonicalCookieAsync(
CanonicalCookie::CreateForTesting(http_www_foo_.url(), "A=B",
base::Time::Now()),
http_www_foo_.url(), CookieOptions::MakeAllInclusive(),
set_cookies_callback.MakeCallback());
base::RunLoop().RunUntilIdle();
EXPECT_FALSE(get_cookie_list_callback_was_run);
EXPECT_FALSE(set_cookies_callback.was_run());
ExecuteLoads(CookieStoreCommand::LOAD_COOKIES_FOR_KEY);
run_loop.Run();
EXPECT_EQ("LOAD; LOAD_FOR_KEY:foo.com; ADD; ", TakeCommandSummary());
EXPECT_TRUE(get_cookie_list_callback_was_run);
ASSERT_TRUE(set_cookies_callback.was_run());
EXPECT_TRUE(set_cookies_callback.result().status.IsInclude());
ASSERT_TRUE(get_cookie_list_callback_deferred.was_run());
EXPECT_THAT(get_cookie_list_callback_deferred.cookies(),
MatchesCookieLine("A=B; X=1"));
}
TEST_F(CookieMonsterTest, TestCookieDeleteAll) {
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
CookieOptions options = CookieOptions::MakeAllInclusive();
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), kValidCookieLine));
EXPECT_EQ("A=B", GetCookies(cm.get(), http_www_foo_.url()));
EXPECT_TRUE(CreateAndSetCookie(cm.get(), http_www_foo_.url(), "C=D; httponly",
options));
EXPECT_EQ("A=B; C=D",
GetCookiesWithOptions(cm.get(), http_www_foo_.url(), options));
EXPECT_EQ(2u, DeleteAll(cm.get()));
EXPECT_EQ("", GetCookiesWithOptions(cm.get(), http_www_foo_.url(), options));
EXPECT_EQ(0u, store->commands().size());
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(),
kValidCookieLine + FutureCookieExpirationString()));
ASSERT_EQ(1u, store->commands().size());
EXPECT_EQ(CookieStoreCommand::ADD, store->commands()[0].type);
EXPECT_EQ(1u, DeleteAll(cm.get()));
ASSERT_EQ(2u, store->commands().size());
EXPECT_EQ(CookieStoreCommand::REMOVE, store->commands()[1].type);
EXPECT_EQ("", GetCookiesWithOptions(cm.get(), http_www_foo_.url(), options));
auto cookie_partition_key =
CookiePartitionKey::FromURLForTesting(GURL("https://toplevelsite.com"));
EXPECT_TRUE(SetCookie(
cm.get(), https_www_foo_.url(),
"__Host-" + std::string(kValidCookieLine) + "; partitioned; secure",
cookie_partition_key));
EXPECT_EQ(1u, DeleteAll(cm.get()));
EXPECT_EQ("", GetCookiesWithOptions(
cm.get(), http_www_foo_.url(), options,
CookiePartitionKeyCollection(cookie_partition_key)));
EXPECT_EQ(2u, store->commands().size());
}
TEST_F(CookieMonsterTest, TestCookieDeleteAllCreatedInTimeRangeTimestamps) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
Time now = Time::Now();
EXPECT_EQ(0u, DeleteAllCreatedInTimeRange(
cm.get(), TimeRange(now - base::Days(99), Time())));
EXPECT_TRUE(
SetCookieWithCreationTime(cm.get(), http_www_foo_.url(), "T-0=Now", now));
EXPECT_TRUE(SetCookieWithCreationTime(cm.get(), http_www_foo_.url(),
"T-1=Yesterday", now - base::Days(1)));
EXPECT_TRUE(SetCookieWithCreationTime(cm.get(), http_www_foo_.url(),
"T-2=DayBefore", now - base::Days(2)));
EXPECT_TRUE(SetCookieWithCreationTime(cm.get(), http_www_foo_.url(),
"T-3=ThreeDays", now - base::Days(3)));
EXPECT_TRUE(SetCookieWithCreationTime(cm.get(), http_www_foo_.url(),
"T-7=LastWeek", now - base::Days(7)));
EXPECT_EQ(2u,
DeleteAllCreatedInTimeRange(
cm.get(), TimeRange(now - base::Days(3), now - base::Days(1))));
EXPECT_EQ(1u, DeleteAllCreatedInTimeRange(
cm.get(), TimeRange(now - base::Days(2), now)));
EXPECT_EQ(1u, DeleteAllCreatedInTimeRange(
cm.get(), TimeRange(now - base::Days(7), now)));
EXPECT_EQ(1u, DeleteAllCreatedInTimeRange(cm.get(), TimeRange()));
EXPECT_EQ(0u, DeleteAll(cm.get()));
EXPECT_TRUE(
SetCookieWithCreationTime(cm.get(), http_www_foo_.url(), "T-0=Now", now,
CookiePartitionKey::FromURLForTesting(
GURL("https://toplevelsite0.com"))));
EXPECT_TRUE(SetCookieWithCreationTime(
cm.get(), https_www_foo_.url(), "T-1=Yesterday", now - base::Days(1),
CookiePartitionKey::FromURLForTesting(
GURL("https://toplevelsite1.com"))));
EXPECT_TRUE(SetCookieWithCreationTime(
cm.get(), http_www_foo_.url(), "T-2=DayBefore", now - base::Days(2),
CookiePartitionKey::FromURLForTesting(
GURL("https://toplevelsite1.com"))));
EXPECT_TRUE(SetCookieWithCreationTime(
cm.get(), http_www_foo_.url(), "T-3=ThreeDays", now - base::Days(3),
CookiePartitionKey::FromURLForTesting(
GURL("https://toplevelsite2.com"))));
EXPECT_TRUE(SetCookieWithCreationTime(
cm.get(), http_www_foo_.url(), "T-7=LastWeek", now - base::Days(7),
CookiePartitionKey::FromURLForTesting(
GURL("https://toplevelsite3.com"))));
EXPECT_EQ(2u,
DeleteAllCreatedInTimeRange(
cm.get(), TimeRange(now - base::Days(3), now - base::Days(1))));
EXPECT_EQ(1u, DeleteAllCreatedInTimeRange(
cm.get(), TimeRange(now - base::Days(2), now)));
EXPECT_EQ(1u, DeleteAllCreatedInTimeRange(
cm.get(), TimeRange(now - base::Days(7), now)));
EXPECT_EQ(1u, DeleteAllCreatedInTimeRange(cm.get(), TimeRange()));
EXPECT_EQ(0u, DeleteAll(cm.get()));
}
TEST_F(CookieMonsterTest,
TestCookieDeleteAllCreatedInTimeRangeTimestampsWithInfo) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
Time now = Time::Now();
CanonicalCookie test_cookie;
EXPECT_EQ(0u,
DeleteAllMatchingInfo(
cm.get(), CookieDeletionInfo(now - base::Days(99), Time())));
EXPECT_TRUE(
SetCookieWithCreationTime(cm.get(), http_www_foo_.url(), "T-0=Now", now));
EXPECT_TRUE(SetCookieWithCreationTime(cm.get(), http_www_foo_.url(),
"T-1=Yesterday", now - base::Days(1)));
EXPECT_TRUE(SetCookieWithCreationTime(cm.get(), http_www_foo_.url(),
"T-2=DayBefore", now - base::Days(2)));
EXPECT_TRUE(SetCookieWithCreationTime(cm.get(), http_www_foo_.url(),
"T-3=ThreeDays", now - base::Days(3)));
EXPECT_TRUE(SetCookieWithCreationTime(cm.get(), http_www_foo_.url(),
"T-7=LastWeek", now - base::Days(7)));
EXPECT_EQ(2u, DeleteAllMatchingInfo(cm.get(),
CookieDeletionInfo(now - base::Days(3),
now - base::Days(1))));
EXPECT_EQ(1u, DeleteAllMatchingInfo(
cm.get(), CookieDeletionInfo(now - base::Days(2), now)));
EXPECT_EQ(1u, DeleteAllMatchingInfo(
cm.get(), CookieDeletionInfo(now - base::Days(7), now)));
EXPECT_EQ(1u, DeleteAllMatchingInfo(cm.get(), CookieDeletionInfo()));
EXPECT_EQ(0u, DeleteAll(cm.get()));
EXPECT_TRUE(
SetCookieWithCreationTime(cm.get(), http_www_foo_.url(), "T-0=Now", now,
CookiePartitionKey::FromURLForTesting(
GURL("https://toplevelsite0.com"))));
EXPECT_TRUE(SetCookieWithCreationTime(
cm.get(), https_www_foo_.url(), "T-1=Yesterday", now - base::Days(1),
CookiePartitionKey::FromURLForTesting(
GURL("https://toplevelsite1.com"))));
EXPECT_TRUE(SetCookieWithCreationTime(
cm.get(), http_www_foo_.url(), "T-2=DayBefore", now - base::Days(2),
CookiePartitionKey::FromURLForTesting(
GURL("https://toplevelsite1.com"))));
EXPECT_TRUE(SetCookieWithCreationTime(
cm.get(), http_www_foo_.url(), "T-3=ThreeDays", now - base::Days(3),
CookiePartitionKey::FromURLForTesting(
GURL("https://toplevelsite2.com"))));
EXPECT_TRUE(SetCookieWithCreationTime(
cm.get(), http_www_foo_.url(), "T-7=LastWeek", now - base::Days(7),
CookiePartitionKey::FromURLForTesting(
GURL("https://toplevelsite3.com"))));
EXPECT_EQ(2u, DeleteAllMatchingInfo(cm.get(),
CookieDeletionInfo(now - base::Days(3),
now - base::Days(1))));
EXPECT_EQ(1u, DeleteAllMatchingInfo(
cm.get(), CookieDeletionInfo(now - base::Days(2), now)));
EXPECT_EQ(1u, DeleteAllMatchingInfo(
cm.get(), CookieDeletionInfo(now - base::Days(7), now)));
EXPECT_EQ(1u, DeleteAllMatchingInfo(cm.get(), CookieDeletionInfo()));
EXPECT_EQ(0u, DeleteAll(cm.get()));
}
TEST_F(CookieMonsterTest, TestCookieDeleteMatchingCookies) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
Time now = Time::Now();
EXPECT_EQ(0u, DeleteMatchingCookies(
cm.get(),
base::BindRepeating([](const net::CanonicalCookie& cookie) {
return true;
})));
EXPECT_TRUE(SetCookieWithCreationTime(cm.get(), GURL("https://a.com"),
"a1=1;Secure", now));
EXPECT_TRUE(
SetCookieWithCreationTime(cm.get(), GURL("https://a.com"), "a2=2", now));
EXPECT_TRUE(SetCookieWithCreationTime(cm.get(), GURL("https://b.com"),
"b1=1;Secure", now));
EXPECT_TRUE(
SetCookieWithCreationTime(cm.get(), GURL("http://b.com"), "b2=2", now));
EXPECT_TRUE(SetCookieWithCreationTime(cm.get(), GURL("https://c.com"),
"c1=1;Secure", now));
EXPECT_TRUE(SetCookieWithCreationTime(
cm.get(), GURL("https://d.com"),
"__Host-pc=123; path=/; secure; partitioned", now,
CookiePartitionKey::FromURLForTesting(GURL("https://e.com"))));
EXPECT_EQ(2u, DeleteMatchingCookies(
cm.get(),
base::BindRepeating([](const net::CanonicalCookie& cookie) {
return !cookie.SecureAttribute();
})));
EXPECT_THAT(GetAllCookies(cm.get()),
ElementsAre(MatchesCookieNameDomain("a1", "a.com"),
MatchesCookieNameDomain("b1", "b.com"),
MatchesCookieNameDomain("c1", "c.com"),
MatchesCookieNameDomain("__Host-pc", "d.com")));
EXPECT_EQ(1u, DeleteMatchingCookies(
cm.get(),
base::BindRepeating([](const net::CanonicalCookie& cookie) {
return cookie.Domain() == "a.com";
})));
EXPECT_THAT(GetAllCookies(cm.get()),
ElementsAre(MatchesCookieNameDomain("b1", "b.com"),
MatchesCookieNameDomain("c1", "c.com"),
MatchesCookieNameDomain("__Host-pc", "d.com")));
EXPECT_EQ(1u, DeleteMatchingCookies(
cm.get(),
base::BindRepeating([](const net::CanonicalCookie& cookie) {
return cookie.IsPartitioned();
})));
EXPECT_EQ(2u, DeleteMatchingCookies(
cm.get(),
base::BindRepeating([](const net::CanonicalCookie& cookie) {
return true;
})));
EXPECT_TRUE(GetAllCookies(cm.get()).empty());
}
static const base::TimeDelta kLastAccessThreshold = base::Milliseconds(200);
static const base::TimeDelta kAccessDelay =
kLastAccessThreshold + base::Milliseconds(20);
TEST_F(CookieMonsterTest, TestLastAccess) {
auto cm = std::make_unique<CookieMonster>(
nullptr, kLastAccessThreshold, net::NetLog::Get(),
nullptr);
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), "A=B"));
const Time last_access_date(GetFirstCookieAccessDate(cm.get()));
EXPECT_EQ("A=B", GetCookies(cm.get(), http_www_foo_.url()));
EXPECT_EQ(last_access_date, GetFirstCookieAccessDate(cm.get()));
base::PlatformThread::Sleep(kAccessDelay);
CookieOptions options = CookieOptions::MakeAllInclusive();
options.set_do_not_update_access_time();
EXPECT_EQ("A=B",
GetCookiesWithOptions(cm.get(), http_www_foo_.url(), options));
EXPECT_EQ(last_access_date, GetFirstCookieAccessDate(cm.get()));
CookieList cookies = GetAllCookiesForURL(cm.get(), http_www_foo_.url());
auto it = cookies.begin();
ASSERT_TRUE(it != cookies.end());
EXPECT_EQ(http_www_foo_.host(), it->Domain());
EXPECT_EQ("A", it->Name());
EXPECT_EQ("B", it->Value());
EXPECT_EQ(last_access_date, GetFirstCookieAccessDate(cm.get()));
EXPECT_TRUE(++it == cookies.end());
options.set_update_access_time();
EXPECT_EQ("A=B",
GetCookiesWithOptions(cm.get(), http_www_foo_.url(), options));
EXPECT_FALSE(last_access_date == GetFirstCookieAccessDate(cm.get()));
}
TEST_P(CookieMonsterTestPriorityGarbageCollectionObc,
TestHostGarbageCollection) {
TestHostGarbageCollectHelper();
}
TEST_P(CookieMonsterTestPriorityGarbageCollectionObc,
TestPriorityAwareGarbageCollectionNonSecure) {
TestPriorityAwareGarbageCollectHelperNonSecure();
}
TEST_P(CookieMonsterTestPriorityGarbageCollectionObc,
TestPriorityAwareGarbageCollectionSecure) {
TestPriorityAwareGarbageCollectHelperSecure();
}
TEST_P(CookieMonsterTestPriorityGarbageCollectionObc,
TestPriorityAwareGarbageCollectionMixed) {
TestPriorityAwareGarbageCollectHelperMixed();
}
TEST_P(CookieMonsterTestGarbageCollectionObc, DomainCookiesPreferred) {
ASSERT_TRUE(cookie_util::IsOriginBoundCookiesPartiallyEnabled());
ASSERT_EQ(180U, CookieMonster::kDomainMaxCookies);
ASSERT_EQ(150U, CookieMonster::kDomainMaxCookies -
CookieMonster::kDomainPurgeCookies);
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
for (int i = 0; i < 151; i++) {
std::string cookie = "host_" + base::NumberToString(i) + "=foo; Secure";
EXPECT_TRUE(SetCookie(cm.get(), https_www_foo_.url(), cookie));
}
for (int i = 0; i < 30; i++) {
std::string cookie = "domain_" + base::NumberToString(i) +
"=foo; Secure; Domain=" + https_www_foo_.domain();
EXPECT_TRUE(SetCookie(cm.get(), https_www_foo_.url(), cookie));
}
auto cookie_list = this->GetAllCookiesForURL(cm.get(), https_www_foo_.url());
int domain_count = 0;
int host_count = 0;
for (const auto& cookie : cookie_list) {
if (cookie.IsHostCookie()) {
host_count++;
} else {
domain_count++;
}
}
EXPECT_EQ(host_count, 150);
EXPECT_EQ(domain_count, 0);
}
TEST_P(CookieMonsterTestGarbageCollectionObc,
DomainPartitionedCookiesPreferred) {
ASSERT_TRUE(cookie_util::IsOriginBoundCookiesPartiallyEnabled());
ASSERT_EQ(180U, CookieMonster::kPerPartitionDomainMaxCookies);
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
auto cookie_partition_key =
CookiePartitionKey::FromURLForTesting(GURL("https://www.example.com"));
for (int i = 0; i < 150; i++) {
std::string cookie =
"host_" + base::NumberToString(i) + "=foo; Secure; Partitioned";
ASSERT_TRUE(SetCookie(cm.get(), https_www_foo_.url(), cookie,
cookie_partition_key));
}
for (int i = 0; i < 31; i++) {
std::string cookie =
"domain_" + base::NumberToString(i) +
"=foo; Secure; Partitioned; Domain=" + https_www_foo_.domain();
ASSERT_TRUE(SetCookie(cm.get(), https_www_foo_.url(), cookie,
cookie_partition_key));
}
auto cookie_list = this->GetAllCookiesForURL(
cm.get(), https_www_foo_.url(),
CookiePartitionKeyCollection(cookie_partition_key));
int domain_count = 0;
int host_count = 0;
for (const auto& cookie : cookie_list) {
if (cookie.IsHostCookie()) {
host_count++;
} else {
domain_count++;
}
}
EXPECT_EQ(host_count, 150);
EXPECT_EQ(domain_count, 30);
for (int i = 0; i < 31; i++) {
std::string cookie =
"host_" + base::NumberToString(i + 150) + "=foo; Secure; Partitioned";
ASSERT_TRUE(SetCookie(cm.get(), https_www_foo_.url(), cookie,
cookie_partition_key));
}
cookie_list = this->GetAllCookiesForURL(
cm.get(), https_www_foo_.url(),
CookiePartitionKeyCollection(cookie_partition_key));
domain_count = 0;
host_count = 0;
for (const auto& cookie : cookie_list) {
if (cookie.IsHostCookie()) {
host_count++;
} else {
domain_count++;
}
}
EXPECT_EQ(host_count, 180);
EXPECT_EQ(domain_count, 0);
}
TEST_P(CookieMonsterTestGarbageCollectionObc, SecureCookiesPreferred) {
ASSERT_TRUE(cookie_util::IsOriginBoundCookiesPartiallyEnabled());
ASSERT_EQ(180U, CookieMonster::kDomainMaxCookies);
ASSERT_EQ(150U, CookieMonster::kDomainMaxCookies -
CookieMonster::kDomainPurgeCookies);
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
std::string secure_attr =
cookie_util::IsSchemeBoundCookiesEnabled() ? "" : "; Secure";
for (int i = 0; i < 151; i++) {
std::string cookie = "domain_" + base::NumberToString(i) +
"=foo; Domain=" + https_www_foo_.domain() +
secure_attr;
EXPECT_TRUE(SetCookie(cm.get(), https_www_foo_.url(), cookie));
}
for (int i = 0; i < 30; i++) {
std::string cookie = "host_" + base::NumberToString(i) + "=foo";
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), cookie));
}
auto secure_cookie_list =
this->GetAllCookiesForURL(cm.get(), https_www_foo_.url());
auto insecure_cookie_list =
this->GetAllCookiesForURL(cm.get(), http_www_foo_.url());
int domain_count = 0;
int host_count = 0;
for (const auto& cookie : secure_cookie_list) {
if (cookie.IsHostCookie()) {
host_count++;
} else {
domain_count++;
}
}
for (const auto& cookie : insecure_cookie_list) {
if (cookie.IsHostCookie()) {
host_count++;
} else {
domain_count++;
}
}
EXPECT_EQ(host_count, 0);
EXPECT_EQ(domain_count, 150);
}
TEST_P(CookieMonsterTestGarbageCollectionObc, LegacyModeGarbageCollection) {
ASSERT_TRUE(cookie_util::IsOriginBoundCookiesPartiallyEnabled());
ASSERT_EQ(180U, CookieMonster::kDomainMaxCookies);
ASSERT_EQ(150U, CookieMonster::kDomainMaxCookies -
CookieMonster::kDomainPurgeCookies);
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
GURL example_with_https_port_value_80 = GURL("https://www.example.com:80/");
std::unique_ptr<TestCookieAccessDelegate> access_delegate =
std::make_unique<TestCookieAccessDelegate>();
access_delegate->SetExpectationForCookieScope("example.com",
CookieScopeSemantics::LEGACY);
cm->SetCookieAccessDelegate(std::move(access_delegate));
for (int i = 0; i < 151; i++) {
std::string cookie = "host_" + base::NumberToString(i) + "=foo; Secure";
ASSERT_TRUE(SetCookie(cm.get(), example_with_https_port_value_80, cookie));
}
for (int i = 0; i < 30; i++) {
std::string cookie = "domain_" + base::NumberToString(i) +
"=foo; Secure; Domain=www.example.com";
ASSERT_TRUE(SetCookie(cm.get(), example_with_https_port_value_80, cookie));
}
auto cookie_list =
this->GetAllCookiesForURL(cm.get(), example_with_https_port_value_80);
int host_count = 0;
for (const auto& cookie : cookie_list) {
if (cookie.IsHostCookie()) {
++host_count;
}
}
EXPECT_EQ(cookie_list.size(), 150UL);
EXPECT_EQ(host_count, 120);
}
TEST_P(CookieMonsterTestGarbageCollectionObc,
LegacyModeParitionedGarbageCollection) {
ASSERT_TRUE(cookie_util::IsOriginBoundCookiesPartiallyEnabled());
ASSERT_EQ(180U, CookieMonster::kPerPartitionDomainMaxCookies);
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
auto cookie_partition_key =
CookiePartitionKey::FromURLForTesting(GURL("https://www.example.com"));
GURL example_with_https_port_value_80 = GURL("https://www.example.com:80/");
std::unique_ptr<TestCookieAccessDelegate> access_delegate =
std::make_unique<TestCookieAccessDelegate>();
access_delegate->SetExpectationForCookieScope("example.com",
CookieScopeSemantics::LEGACY);
cm->SetCookieAccessDelegate(std::move(access_delegate));
for (int i = 0; i < 150; i++) {
std::string cookie =
"host_" + base::NumberToString(i) + "=foo; Secure; Partitioned";
ASSERT_TRUE(SetCookie(cm.get(), example_with_https_port_value_80, cookie,
cookie_partition_key));
}
for (int i = 0; i < 31; i++) {
std::string cookie = "domain_" + base::NumberToString(i) +
"=foo; Secure; Partitioned; Domain=www.example.com";
ASSERT_TRUE(SetCookie(cm.get(), example_with_https_port_value_80, cookie,
cookie_partition_key));
}
auto cookie_list = this->GetAllCookiesForURL(
cm.get(), example_with_https_port_value_80,
CookiePartitionKeyCollection(cookie_partition_key));
int host_count = 0;
for (const auto& cookie : cookie_list) {
ASSERT_TRUE(cookie.IsPartitioned());
if (cookie.IsHostCookie()) {
++host_count;
}
}
EXPECT_EQ(cookie_list.size(), 180UL);
EXPECT_EQ(host_count, 149);
}
TEST_F(CookieMonsterTest, TestPartitionedCookiesGarbageCollection_Memory) {
DCHECK_EQ(1024u * 10u, CookieMonster::kPerPartitionDomainMaxCookieBytes);
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
auto cookie_partition_key =
CookiePartitionKey::FromURLForTesting(GURL("https://toplevelsite1.com"));
for (size_t i = 0; i < 41; ++i) {
std::string cookie_value((10240 / 40) - (i < 10 ? 1 : 2), '0');
std::string cookie =
base::StrCat({base::NumberToString(i), "=", cookie_value});
EXPECT_TRUE(SetCookie(cm.get(), https_www_foo_.url(),
cookie + "; secure; path=/; partitioned",
cookie_partition_key))
<< "Failed to set cookie " << i;
}
std::string cookies =
this->GetCookies(cm.get(), https_www_foo_.url(),
CookiePartitionKeyCollection(cookie_partition_key));
EXPECT_THAT(cookies, CookieStringIs(
testing::Not(testing::Contains(testing::Key("0")))));
for (size_t i = 1; i < 41; ++i) {
EXPECT_THAT(cookies, CookieStringIs(testing::Contains(
testing::Key(base::NumberToString(i)))))
<< "Failed to find cookie " << i;
}
}
TEST_F(CookieMonsterTest, TestPartitionedCookiesGarbageCollection_MaxCookies) {
DCHECK_EQ(180u, CookieMonster::kPerPartitionDomainMaxCookies);
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
auto cookie_partition_key =
CookiePartitionKey::FromURLForTesting(GURL("https://toplevelsite.com"));
for (size_t i = 0; i < 181; ++i) {
std::string cookie = base::StrCat({base::NumberToString(i), "=0"});
EXPECT_TRUE(SetCookie(cm.get(), https_www_foo_.url(),
cookie + "; secure; path=/; partitioned",
cookie_partition_key))
<< "Failed to set cookie " << i;
}
std::string cookies =
this->GetCookies(cm.get(), https_www_foo_.url(),
CookiePartitionKeyCollection(cookie_partition_key));
EXPECT_THAT(cookies, CookieStringIs(
testing::Not(testing::Contains(testing::Key("0")))));
for (size_t i = 1; i < 181; ++i) {
std::string cookie = base::StrCat({base::NumberToString(i), "=0"});
EXPECT_THAT(cookies, CookieStringIs(testing::Contains(
testing::Key(base::NumberToString(i)))))
<< "Failed to find cookie " << i;
}
}
TEST_F(CookieMonsterTest, SetCookieableSchemes) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
auto cm_foo = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
std::vector<std::string> schemes;
schemes.push_back("foo");
ResultSavingCookieCallback<bool> cookie_scheme_callback;
cm_foo->SetCookieableSchemes(schemes, cookie_scheme_callback.MakeCallback());
cookie_scheme_callback.WaitUntilDone();
EXPECT_TRUE(cookie_scheme_callback.result());
GURL foo_url("foo://host/path");
GURL http_url("http://host/path");
base::Time now = base::Time::Now();
std::optional<base::Time> server_time = std::nullopt;
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(cm.get(), http_url, "x=1").IsInclude());
EXPECT_TRUE(
SetCanonicalCookieReturnAccessResult(
cm.get(),
CanonicalCookie::CreateForTesting(http_url, "y=1", now, server_time),
http_url, false )
.status.IsInclude());
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), foo_url, "x=1")
.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_NONCOOKIEABLE_SCHEME}));
EXPECT_TRUE(
SetCanonicalCookieReturnAccessResult(
cm.get(),
CanonicalCookie::CreateForTesting(foo_url, "y=1", now, server_time),
foo_url, false )
.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_NONCOOKIEABLE_SCHEME}));
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(cm_foo.get(), foo_url, "x=1").IsInclude());
EXPECT_TRUE(
SetCanonicalCookieReturnAccessResult(
cm_foo.get(),
CanonicalCookie::CreateForTesting(foo_url, "y=1", now, server_time),
foo_url, false )
.status.IsInclude());
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm_foo.get(), http_url, "x=1")
.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_NONCOOKIEABLE_SCHEME}));
EXPECT_TRUE(
SetCanonicalCookieReturnAccessResult(
cm_foo.get(),
CanonicalCookie::CreateForTesting(http_url, "y=1", now, server_time),
http_url, false )
.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_NONCOOKIEABLE_SCHEME}));
}
TEST_F(CookieMonsterTest, SetCookieableSchemes_StoreInitialized) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
this->GetCookies(cm.get(), https_www_foo_.url(),
CookiePartitionKeyCollection());
std::vector<std::string> schemes;
schemes.push_back("foo");
ResultSavingCookieCallback<bool> cookie_scheme_callback;
cm->SetCookieableSchemes(schemes, cookie_scheme_callback.MakeCallback());
cookie_scheme_callback.WaitUntilDone();
EXPECT_FALSE(cookie_scheme_callback.result());
base::Time now = base::Time::Now();
std::optional<base::Time> server_time = std::nullopt;
GURL foo_url("foo://host/path");
EXPECT_TRUE(
SetCanonicalCookieReturnAccessResult(
cm.get(),
CanonicalCookie::CreateForTesting(foo_url, "y=1", now, server_time),
foo_url, false )
.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_NONCOOKIEABLE_SCHEME}));
}
TEST_F(CookieMonsterTest, GetAllCookiesForURL) {
auto cm = std::make_unique<CookieMonster>(
nullptr, kLastAccessThreshold, net::NetLog::Get(),
nullptr);
CookieOptions options = CookieOptions::MakeAllInclusive();
EXPECT_TRUE(CreateAndSetCookie(cm.get(), http_www_foo_.url(), "A=B; httponly",
options));
EXPECT_TRUE(CreateAndSetCookie(cm.get(), http_www_foo_.url(),
http_www_foo_.Format("C=D; domain=.%D"),
options));
EXPECT_TRUE(CreateAndSetCookie(
cm.get(), https_www_foo_.url(),
http_www_foo_.Format("E=F; domain=.%D; secure"), options));
EXPECT_TRUE(CreateAndSetCookie(cm.get(), http_www_bar_.url(),
http_www_bar_.Format("G=H; domain=.%D"),
options));
EXPECT_TRUE(CreateAndSetCookie(
cm.get(), https_www_foo_.url(),
https_www_foo_.Format("I=J; domain=.%D; secure"), options));
auto cookie_partition_key1 =
CookiePartitionKey::FromURLForTesting(GURL("https://toplevelsite1.com"));
auto cookie_partition_key2 =
CookiePartitionKey::FromURLForTesting(GURL("https://toplevelsite2.com"));
auto cookie_partition_key3 =
CookiePartitionKey::FromURLForTesting(GURL("https://toplevelsite3.com"));
EXPECT_TRUE(CreateAndSetCookie(
cm.get(), https_www_bar_.url(), "__Host-K=L; secure; path=/; partitioned",
options, std::nullopt, std::nullopt, cookie_partition_key1));
EXPECT_TRUE(CreateAndSetCookie(
cm.get(), https_www_bar_.url(), "__Host-M=N; secure; path=/; partitioned",
options, std::nullopt, std::nullopt, cookie_partition_key2));
EXPECT_TRUE(CreateAndSetCookie(
cm.get(), https_www_bar_.url(), "__Host-O=P; secure; path=/; partitioned",
options, std::nullopt, std::nullopt, cookie_partition_key3));
const Time last_access_date(GetFirstCookieAccessDate(cm.get()));
base::PlatformThread::Sleep(kAccessDelay);
EXPECT_THAT(
GetAllCookiesForURL(cm.get(), http_www_foo_.url()),
ElementsAre(MatchesCookieNameDomain("A", http_www_foo_.host()),
MatchesCookieNameDomain("C", http_www_foo_.Format(".%D"))));
CookieOptions exclude_httponly = options;
exclude_httponly.set_exclude_httponly();
EXPECT_THAT(
GetAllCookiesForURLWithOptions(cm.get(), http_www_foo_.url(),
exclude_httponly),
ElementsAre(MatchesCookieNameDomain("C", http_www_foo_.Format(".%D"))));
EXPECT_THAT(
GetAllCookiesForURL(cm.get(), https_www_foo_.url()),
ElementsAre(MatchesCookieNameDomain("A", http_www_foo_.host()),
MatchesCookieNameDomain("C", http_www_foo_.Format(".%D")),
MatchesCookieNameDomain("E", http_www_foo_.Format(".%D")),
MatchesCookieNameDomain("I", http_www_foo_.Format(".%D"))));
EXPECT_THAT(
GetAllCookiesForURL(cm.get(), https_www_bar_.url(),
CookiePartitionKeyCollection(cookie_partition_key1)),
ElementsAre(MatchesCookieNameDomain("G", https_www_bar_.Format(".%D")),
MatchesCookieNameDomain("__Host-K", https_www_bar_.host())));
EXPECT_THAT(
GetAllCookiesForURL(cm.get(), https_www_bar_.url(),
CookiePartitionKeyCollection(cookie_partition_key2)),
ElementsAre(MatchesCookieNameDomain("G", https_www_bar_.Format(".%D")),
MatchesCookieNameDomain("__Host-M", https_www_bar_.host())));
EXPECT_THAT(
GetAllCookiesForURL(cm.get(), https_www_bar_.url(),
CookiePartitionKeyCollection(
{cookie_partition_key1, cookie_partition_key2})),
ElementsAre(MatchesCookieNameDomain("G", https_www_bar_.Format(".%D")),
MatchesCookieNameDomain("__Host-K", https_www_bar_.host()),
MatchesCookieNameDomain("__Host-M", https_www_bar_.host())));
EXPECT_THAT(
GetAllCookiesForURL(cm.get(), https_www_bar_.url(),
CookiePartitionKeyCollection::ContainsAll()),
ElementsAre(MatchesCookieNameDomain("G", https_www_bar_.Format(".%D")),
MatchesCookieNameDomain("__Host-K", https_www_bar_.host()),
MatchesCookieNameDomain("__Host-M", https_www_bar_.host()),
MatchesCookieNameDomain("__Host-O", https_www_bar_.host())));
EXPECT_THAT(
GetAllCookiesForURL(cm.get(), https_www_bar_.url(),
CookiePartitionKeyCollection()),
ElementsAre(MatchesCookieNameDomain("G", https_www_bar_.Format(".%D"))));
EXPECT_EQ(last_access_date, GetFirstCookieAccessDate(cm.get()));
}
TEST_F(CookieMonsterTest, GetExcludedCookiesForURL) {
auto cm = std::make_unique<CookieMonster>(
nullptr, kLastAccessThreshold, net::NetLog::Get(),
nullptr);
CookieOptions options = CookieOptions::MakeAllInclusive();
EXPECT_TRUE(CreateAndSetCookie(cm.get(), http_www_foo_.url(), "A=B; httponly",
options));
EXPECT_TRUE(CreateAndSetCookie(cm.get(), http_www_foo_.url(),
http_www_foo_.Format("C=D; domain=.%D"),
options));
EXPECT_TRUE(CreateAndSetCookie(
cm.get(), https_www_foo_.url(),
http_www_foo_.Format("E=F; domain=.%D; secure"), options));
base::PlatformThread::Sleep(kAccessDelay);
CookieOptions do_not_return_excluded;
do_not_return_excluded.unset_return_excluded_cookies();
CookieAccessResultList excluded_cookies = GetExcludedCookiesForURLWithOptions(
cm.get(), http_www_foo_.url(), do_not_return_excluded);
auto iter = excluded_cookies.begin();
EXPECT_TRUE(excluded_cookies.empty());
excluded_cookies = GetExcludedCookiesForURL(cm.get(), http_www_foo_.url(),
CookiePartitionKeyCollection());
iter = excluded_cookies.begin();
ASSERT_TRUE(iter != excluded_cookies.end());
EXPECT_EQ(http_www_foo_.Format(".%D"), iter->cookie.Domain());
EXPECT_EQ("E", iter->cookie.Name());
EXPECT_TRUE(iter->access_result.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_SECURE_ONLY}));
ASSERT_TRUE(++iter == excluded_cookies.end());
CookieOptions return_excluded;
return_excluded.set_return_excluded_cookies();
return_excluded.set_exclude_httponly();
return_excluded.set_same_site_cookie_context(
CookieOptions::SameSiteCookieContext(
CookieOptions::SameSiteCookieContext::ContextType::SAME_SITE_STRICT));
excluded_cookies = GetExcludedCookiesForURLWithOptions(
cm.get(), http_www_foo_.url(), return_excluded);
iter = excluded_cookies.begin();
ASSERT_TRUE(iter != excluded_cookies.end());
EXPECT_EQ(http_www_foo_.host(), iter->cookie.Domain());
EXPECT_EQ("A", iter->cookie.Name());
EXPECT_TRUE(iter->access_result.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_HTTP_ONLY}));
ASSERT_TRUE(++iter != excluded_cookies.end());
EXPECT_EQ(http_www_foo_.Format(".%D"), iter->cookie.Domain());
EXPECT_EQ("E", iter->cookie.Name());
EXPECT_TRUE(iter->access_result.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_SECURE_ONLY}));
ASSERT_TRUE(++iter == excluded_cookies.end());
excluded_cookies = GetExcludedCookiesForURL(cm.get(), https_www_foo_.url(),
CookiePartitionKeyCollection());
iter = excluded_cookies.begin();
EXPECT_TRUE(excluded_cookies.empty());
}
TEST_F(CookieMonsterTest, GetAllCookiesForURLPathMatching) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
CookieOptions options = CookieOptions::MakeAllInclusive();
EXPECT_TRUE(CreateAndSetCookie(cm.get(), www_foo_foo_.url(),
"A=B; path=/foo;", options));
EXPECT_TRUE(CreateAndSetCookie(cm.get(), www_foo_bar_.url(),
"C=D; path=/bar;", options));
EXPECT_TRUE(
CreateAndSetCookie(cm.get(), http_www_foo_.url(), "E=F;", options));
CookieList cookies = GetAllCookiesForURL(cm.get(), www_foo_foo_.url());
auto it = cookies.begin();
ASSERT_TRUE(it != cookies.end());
EXPECT_EQ("A", it->Name());
EXPECT_EQ("/foo", it->Path());
ASSERT_TRUE(++it != cookies.end());
EXPECT_EQ("E", it->Name());
EXPECT_EQ("/", it->Path());
ASSERT_TRUE(++it == cookies.end());
cookies = GetAllCookiesForURL(cm.get(), www_foo_bar_.url());
it = cookies.begin();
ASSERT_TRUE(it != cookies.end());
EXPECT_EQ("C", it->Name());
EXPECT_EQ("/bar", it->Path());
ASSERT_TRUE(++it != cookies.end());
EXPECT_EQ("E", it->Name());
EXPECT_EQ("/", it->Path());
ASSERT_TRUE(++it == cookies.end());
}
TEST_F(CookieMonsterTest, GetExcludedCookiesForURLPathMatching) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
CookieOptions options = CookieOptions::MakeAllInclusive();
EXPECT_TRUE(CreateAndSetCookie(cm.get(), www_foo_foo_.url(),
"A=B; path=/foo;", options));
EXPECT_TRUE(CreateAndSetCookie(cm.get(), www_foo_bar_.url(),
"C=D; path=/bar;", options));
EXPECT_TRUE(
CreateAndSetCookie(cm.get(), http_www_foo_.url(), "E=F;", options));
CookieAccessResultList excluded_cookies = GetExcludedCookiesForURL(
cm.get(), www_foo_foo_.url(), CookiePartitionKeyCollection());
auto it = excluded_cookies.begin();
ASSERT_TRUE(it != excluded_cookies.end());
EXPECT_EQ("C", it->cookie.Name());
EXPECT_EQ("/bar", it->cookie.Path());
EXPECT_TRUE(it->access_result.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_NOT_ON_PATH}));
ASSERT_TRUE(++it == excluded_cookies.end());
excluded_cookies = GetExcludedCookiesForURL(cm.get(), www_foo_bar_.url(),
CookiePartitionKeyCollection());
it = excluded_cookies.begin();
ASSERT_TRUE(it != excluded_cookies.end());
EXPECT_EQ("A", it->cookie.Name());
EXPECT_EQ("/foo", it->cookie.Path());
EXPECT_TRUE(it->access_result.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_NOT_ON_PATH}));
ASSERT_TRUE(++it == excluded_cookies.end());
}
TEST_F(CookieMonsterTest, CookieSorting) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
base::Time system_time = base::Time::Now();
for (const char* cookie_line :
{"B=B1; path=/", "B=B2; path=/foo", "B=B3; path=/foo/bar",
"A=A1; path=/", "A=A2; path=/foo", "A=A3; path=/foo/bar"}) {
EXPECT_TRUE(SetCookieWithSystemTime(cm.get(), http_www_foo_.url(),
cookie_line, system_time));
system_time += base::Milliseconds(100);
}
EXPECT_TRUE(SetCookieWithSystemTime(cm.get(), http_www_foo_.url(),
"B=B3; path=/foo/bar", system_time));
CookieList cookies = GetAllCookies(cm.get());
ASSERT_EQ(6u, cookies.size());
EXPECT_EQ("B3", cookies[0].Value());
EXPECT_EQ("A3", cookies[1].Value());
EXPECT_EQ("B2", cookies[2].Value());
EXPECT_EQ("A2", cookies[3].Value());
EXPECT_EQ("B1", cookies[4].Value());
EXPECT_EQ("A1", cookies[5].Value());
}
TEST_F(CookieMonsterTest, InheritCreationDate) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
base::Time the_not_so_distant_past(base::Time::Now() - base::Seconds(1000));
EXPECT_TRUE(SetCookieWithCreationTime(cm.get(), http_www_foo_.url(),
"Name=Value; path=/",
the_not_so_distant_past));
CookieList cookies = GetAllCookies(cm.get());
ASSERT_EQ(1u, cookies.size());
EXPECT_EQ(the_not_so_distant_past, cookies[0].CreationDate());
base::Time last_update = cookies[0].LastUpdateDate();
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), "Name=Value; path=/"));
cookies = GetAllCookies(cm.get());
ASSERT_EQ(1u, cookies.size());
EXPECT_EQ(the_not_so_distant_past, cookies[0].CreationDate());
EXPECT_LT(last_update, cookies[0].LastUpdateDate());
last_update = cookies[0].LastUpdateDate();
EXPECT_TRUE(
SetCookie(cm.get(), http_www_foo_.url(), "Name=NewValue; path=/"));
cookies = GetAllCookies(cm.get());
ASSERT_EQ(1u, cookies.size());
EXPECT_NE(the_not_so_distant_past, cookies[0].CreationDate());
EXPECT_LT(last_update, cookies[0].LastUpdateDate());
}
TEST_F(CookieMonsterTest, OverwriteSource) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), "A=0", std::nullopt,
CookieSourceType::kUnknown));
CookieList cookies = GetAllCookies(cm.get());
ASSERT_EQ(1u, cookies.size());
EXPECT_EQ("0", cookies[0].Value());
EXPECT_EQ(CookieSourceType::kUnknown, cookies[0].SourceType());
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), "A=0", std::nullopt,
CookieSourceType::kHTTP));
cookies = GetAllCookies(cm.get());
ASSERT_EQ(1u, cookies.size());
EXPECT_EQ("0", cookies[0].Value());
EXPECT_EQ(CookieSourceType::kHTTP, cookies[0].SourceType());
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), "A=1", std::nullopt,
CookieSourceType::kScript));
cookies = GetAllCookies(cm.get());
ASSERT_EQ(1u, cookies.size());
EXPECT_EQ("1", cookies[0].Value());
EXPECT_EQ(CookieSourceType::kScript, cookies[0].SourceType());
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), "A=1", std::nullopt,
CookieSourceType::kOther));
cookies = GetAllCookies(cm.get());
ASSERT_EQ(1u, cookies.size());
EXPECT_EQ("1", cookies[0].Value());
EXPECT_EQ(CookieSourceType::kOther, cookies[0].SourceType());
}
TEST_F(CookieMonsterTest, DeleteExpiredCookiesOnGet) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), "A=B;"));
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), "C=D;"));
CookieList cookies = GetAllCookiesForURL(cm.get(), http_www_foo_.url());
EXPECT_EQ(2u, cookies.size());
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(),
"C=D; expires=Thu, 01-Jan-1970 00:00:00 GMT"));
cookies = GetAllCookiesForURL(cm.get(), http_www_foo_.url());
EXPECT_EQ(1u, cookies.size());
auto cookie_partition_key =
CookiePartitionKey::FromURLForTesting(GURL("https://toplevelsite.com"));
EXPECT_TRUE(SetCookie(cm.get(), https_www_bar_.url(),
"__Host-A=B; secure; path=/; partitioned",
cookie_partition_key));
EXPECT_TRUE(SetCookie(cm.get(), https_www_bar_.url(),
"__Host-C=D; secure; path=/; partitioned",
cookie_partition_key));
cookies =
GetAllCookiesForURL(cm.get(), https_www_bar_.url(),
CookiePartitionKeyCollection(cookie_partition_key));
EXPECT_EQ(2u, cookies.size());
EXPECT_TRUE(SetCookie(cm.get(), https_www_bar_.url(),
"__Host-C=D; secure; path=/; partitioned; expires=Thu, "
"01-Jan-1970 00:00:00 GMT",
cookie_partition_key));
cookies =
GetAllCookiesForURL(cm.get(), https_www_bar_.url(),
CookiePartitionKeyCollection(cookie_partition_key));
EXPECT_EQ(1u, cookies.size());
}
TEST_F(CookieMonsterTest, DeleteExpiredCookiesAfterTimeElapsed) {
auto cm = std::make_unique<CookieMonster>(
nullptr, net::NetLog::Get());
EXPECT_TRUE(SetCookie(cm.get(), https_www_bar_.url(),
"__Host-A=B; secure; path=/",
std::nullopt));
EXPECT_TRUE(SetCookie(cm.get(), https_www_bar_.url(),
"__Host-C=D; secure; path=/; max-age=1",
std::nullopt));
CookieList cookies = GetAllCookiesForURL(cm.get(), https_www_bar_.url(),
CookiePartitionKeyCollection());
EXPECT_EQ(2u, cookies.size());
base::PlatformThread::Sleep(base::Seconds(1));
cookies = GetAllCookiesForURL(cm.get(), https_www_bar_.url(),
CookiePartitionKeyCollection());
EXPECT_EQ(1u, cookies.size());
EXPECT_EQ("__Host-A", cookies[0].Name());
}
TEST_F(CookieMonsterTest, DeleteExpiredPartitionedCookiesAfterTimeElapsed) {
auto cm = std::make_unique<CookieMonster>(
nullptr, net::NetLog::Get());
auto cookie_partition_key =
CookiePartitionKey::FromURLForTesting(GURL("https://toplevelsite.com"));
EXPECT_TRUE(SetCookie(cm.get(), https_www_bar_.url(),
"__Host-A=B; secure; path=/; partitioned",
cookie_partition_key));
EXPECT_TRUE(SetCookie(cm.get(), https_www_bar_.url(),
"__Host-C=D; secure; path=/; partitioned; max-age=1",
cookie_partition_key));
CookieList cookies =
GetAllCookiesForURL(cm.get(), https_www_bar_.url(),
CookiePartitionKeyCollection(cookie_partition_key));
EXPECT_EQ(2u, cookies.size());
base::PlatformThread::Sleep(base::Seconds(1));
cookies =
GetAllCookiesForURL(cm.get(), https_www_bar_.url(),
CookiePartitionKeyCollection(cookie_partition_key));
EXPECT_EQ(1u, cookies.size());
EXPECT_EQ("__Host-A", cookies[0].Name());
}
TEST_F(CookieMonsterLegacyScopeTest, DeleteAllAliasCookies) {
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
base::Time now = Time::Now();
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_80_,
"A=1;", now - base::Days(5)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_800_,
"A=2;", now - base::Days(6)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_8000_,
"A=3;", now - base::Days(7)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_10_,
"A=4;", now - base::Days(2)));
ASSERT_TRUE(SetCookie(cm.get(), example_with_https_port_value_800_, "B=1;"));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_8000_,
"B=2;", now - base::Days(7)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_80_,
"B=3;", now - base::Days(6)));
ASSERT_TRUE(SetCookie(cm.get(), example_with_https_port_value_80_, "C=1;"));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_800_,
"C=2;", now - base::Days(7)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_8000_,
"C=3;", now - base::Days(7)));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), GURL("http://www.test.com:80/withDomain"), "D=1;",
now - base::Days(6)));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), GURL("https://www.test.com:100/withDomain"), "D=2;",
now - base::Days(1)));
CookieList cookies = GetAllCookies(cm.get());
ASSERT_THAT(
cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "1"), MatchesCookieNameValue("A", "2"),
MatchesCookieNameValue("A", "3"), MatchesCookieNameValue("A", "4"),
MatchesCookieNameValue("B", "1"), MatchesCookieNameValue("B", "2"),
MatchesCookieNameValue("B", "3"), MatchesCookieNameValue("C", "1"),
MatchesCookieNameValue("C", "2"), MatchesCookieNameValue("C", "3"),
MatchesCookieNameValue("D", "1"), MatchesCookieNameValue("D", "2")));
cm->DeleteAllAliasingCookies(cm->GetKey("example.com"));
cookies = GetAllCookies(cm.get());
EXPECT_THAT(cookies,
testing::UnorderedElementsAre(MatchesCookieNameValue("A", "4"),
MatchesCookieNameValue("B", "1"),
MatchesCookieNameValue("C", "1"),
MatchesCookieNameValue("D", "1"),
MatchesCookieNameValue("D", "2")));
}
TEST_F(CookieMonsterLegacyScopeTest, DeleteAllAliasPartitionedCookies) {
auto cm = std::make_unique<CookieMonster>(
nullptr, net::NetLog::Get());
base::Time now = Time::Now();
auto cookie_partition_key =
CookiePartitionKey::FromURLForTesting(GURL("https://toplevelsite.com"));
auto cookie_partition_key2 =
CookiePartitionKey::FromURLForTesting(GURL("https://example.com"));
auto cookie_partition_key3 =
CookiePartitionKey::FromURLForTesting(GURL("https://foo.com"));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_80_,
"__Host-A-1=1; secure; path=/; partitioned;",
now - base::Days(6), cookie_partition_key));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_800_,
"__Host-A-2=1; secure; path=/; partitioned;",
now - base::Days(7), cookie_partition_key2));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_8000_,
"__Host-A-2=2; secure; path=/; partitioned;",
now - base::Days(8), cookie_partition_key2));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_8000_,
"__Host-A-3=1; secure; path=/; partitioned;",
now - base::Days(10), cookie_partition_key3));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_10_,
"__Host-A-1=2; secure; path=/; partitioned;",
now - base::Days(4), cookie_partition_key));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_8000_,
"__Host-B=1; secure; path=/; partitioned;",
now - base::Days(6), cookie_partition_key));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_80_,
"__Host-C=1; secure; path=/; partitioned;",
now - base::Days(6), cookie_partition_key));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_80_,
"__Host-C=2; secure; path=/; partitioned;",
now - base::Days(6), cookie_partition_key3));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), GURL("https://www.test.com:10/withDomain"),
"__Host-D=1; secure; path=/; partitioned;", now - base::Days(4),
cookie_partition_key2));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), GURL("https://www.test.com:80/withDomain"),
"__Host-D=2; secure; path=/; partitioned;", now - base::Days(1),
cookie_partition_key2));
CookieList cookies = GetAllCookies(cm.get());
ASSERT_THAT(cookies, testing::UnorderedElementsAre(
MatchesCookieNameValue("__Host-A-1", "1"),
MatchesCookieNameValue("__Host-A-1", "2"),
MatchesCookieNameValue("__Host-A-2", "1"),
MatchesCookieNameValue("__Host-A-2", "2"),
MatchesCookieNameValue("__Host-A-3", "1"),
MatchesCookieNameValue("__Host-B", "1"),
MatchesCookieNameValue("__Host-C", "1"),
MatchesCookieNameValue("__Host-C", "2"),
MatchesCookieNameValue("__Host-D", "1"),
MatchesCookieNameValue("__Host-D", "2")));
for (auto cookie : cookies) {
ASSERT_TRUE(cookie.IsPartitioned());
}
cm->DeleteAllAliasingCookies(cm->GetKey("example.com"));
cookies = GetAllCookies(cm.get());
EXPECT_THAT(cookies, testing::UnorderedElementsAre(
MatchesCookieNameValue("__Host-A-1", "2"),
MatchesCookieNameValue("__Host-A-2", "1"),
MatchesCookieNameValue("__Host-A-3", "1"),
MatchesCookieNameValue("__Host-B", "1"),
MatchesCookieNameValue("__Host-C", "1"),
MatchesCookieNameValue("__Host-C", "2"),
MatchesCookieNameValue("__Host-D", "1"),
MatchesCookieNameValue("__Host-D", "2")));
}
TEST_F(CookieMonsterLegacyScopeTest, CheckAndActivateLegacyScopeBehavior) {
auto pref_delegate = std::make_unique<TestPrefDelegate>();
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get(),
std::move(pref_delegate));
base::Time now = Time::Now();
std::optional<base::Time> server_time;
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_80_,
"A=1;", now - base::Days(5)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_800_,
"A=2;", now - base::Days(6)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_8000_,
"A=3;", now - base::Days(7)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_10_,
"A=4;", now - base::Days(2)));
ASSERT_TRUE(SetCookie(cm.get(), example_with_https_port_value_800_, "B=1;"));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_8000_,
"B=2;", now - base::Days(7)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_80_,
"B=3;", now - base::Days(6)));
ASSERT_TRUE(SetCookie(cm.get(), example_with_https_port_value_80_, "C=1;"));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_800_,
"C=2;", now - base::Days(7)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_8000_,
"C=3;", now - base::Days(7)));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), GURL("http://www.test.com:80/withDomain"), "D=1;",
now - base::Days(6)));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), GURL("https://www.test.com:100/withDomain"), "D=2;",
now - base::Days(1)));
CookieList cookies = GetAllCookies(cm.get());
ASSERT_THAT(
cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "1"), MatchesCookieNameValue("A", "2"),
MatchesCookieNameValue("A", "3"), MatchesCookieNameValue("A", "4"),
MatchesCookieNameValue("B", "1"), MatchesCookieNameValue("B", "2"),
MatchesCookieNameValue("B", "3"), MatchesCookieNameValue("C", "1"),
MatchesCookieNameValue("C", "2"), MatchesCookieNameValue("C", "3"),
MatchesCookieNameValue("D", "1"), MatchesCookieNameValue("D", "2")));
auto cookie = CanonicalCookie::CreateForTesting(
example_with_https_port_value_80_, "B=D; Path=/withDomain", now,
server_time);
EXPECT_EQ(cm->CheckAndActivateLegacyScopeBehavior(cookie->Domain()),
CookieScopeSemantics::UNKNOWN);
cookies = GetAllCookies(cm.get());
EXPECT_THAT(
cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "1"), MatchesCookieNameValue("A", "2"),
MatchesCookieNameValue("A", "3"), MatchesCookieNameValue("A", "4"),
MatchesCookieNameValue("B", "1"), MatchesCookieNameValue("B", "2"),
MatchesCookieNameValue("B", "3"), MatchesCookieNameValue("C", "1"),
MatchesCookieNameValue("C", "2"), MatchesCookieNameValue("C", "3"),
MatchesCookieNameValue("D", "1"), MatchesCookieNameValue("D", "2")));
access_delegate_->SetExpectationForCookieScope("example.com",
CookieScopeSemantics::LEGACY);
cm->SetCookieAccessDelegate(std::move(access_delegate_));
EXPECT_EQ(cm->CheckAndActivateLegacyScopeBehavior(cookie->Domain()),
CookieScopeSemantics::LEGACY);
cookies = GetAllCookies(cm.get());
EXPECT_THAT(cookies,
testing::UnorderedElementsAre(MatchesCookieNameValue("A", "4"),
MatchesCookieNameValue("B", "1"),
MatchesCookieNameValue("C", "1"),
MatchesCookieNameValue("D", "1"),
MatchesCookieNameValue("D", "2")));
ASSERT_TRUE(SetUnsafeCookieWithCreationTime(cm.get(),
example_with_https_port_value_80_,
"A=1;", now - base::Days(5)));
EXPECT_EQ(cm->CheckAndActivateLegacyScopeBehavior(cookie->Domain()),
CookieScopeSemantics::LEGACY);
cookies = GetAllCookies(cm.get());
EXPECT_THAT(
cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "1"), MatchesCookieNameValue("A", "4"),
MatchesCookieNameValue("B", "1"), MatchesCookieNameValue("C", "1"),
MatchesCookieNameValue("D", "1"), MatchesCookieNameValue("D", "2")));
}
TEST_F(CookieMonsterLegacyScopeTest,
CheckAndActivateLegacyScopeBehaviorNullPrefDelegate) {
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get(),
nullptr);
base::Time now = Time::Now();
std::optional<base::Time> server_time;
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_80_,
"A=1;", now - base::Days(5)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_800_,
"A=2;", now - base::Days(6)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_8000_,
"A=3;", now - base::Days(7)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_10_,
"A=4;", now - base::Days(2)));
ASSERT_TRUE(SetCookie(cm.get(), example_with_https_port_value_800_, "B=1;"));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_8000_,
"B=2;", now - base::Days(7)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_80_,
"B=3;", now - base::Days(6)));
ASSERT_TRUE(SetCookie(cm.get(), example_with_https_port_value_80_, "C=1;"));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_800_,
"C=2;", now - base::Days(7)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_8000_,
"C=3;", now - base::Days(7)));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), GURL("http://www.test.com:80/withDomain"), "D=1;",
now - base::Days(6)));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), GURL("https://www.test.com:100/withDomain"), "D=2;",
now - base::Days(1)));
CookieList cookies = GetAllCookies(cm.get());
ASSERT_THAT(
cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "1"), MatchesCookieNameValue("A", "2"),
MatchesCookieNameValue("A", "3"), MatchesCookieNameValue("A", "4"),
MatchesCookieNameValue("B", "1"), MatchesCookieNameValue("B", "2"),
MatchesCookieNameValue("B", "3"), MatchesCookieNameValue("C", "1"),
MatchesCookieNameValue("C", "2"), MatchesCookieNameValue("C", "3"),
MatchesCookieNameValue("D", "1"), MatchesCookieNameValue("D", "2")));
auto cookie = CanonicalCookie::CreateForTesting(
example_with_https_port_value_80_, "B=D; Path=/withDomain", now,
server_time);
EXPECT_EQ(cm->CheckAndActivateLegacyScopeBehavior(cookie->Domain()),
CookieScopeSemantics::UNKNOWN);
cookies = GetAllCookies(cm.get());
EXPECT_THAT(
cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "1"), MatchesCookieNameValue("A", "2"),
MatchesCookieNameValue("A", "3"), MatchesCookieNameValue("A", "4"),
MatchesCookieNameValue("B", "1"), MatchesCookieNameValue("B", "2"),
MatchesCookieNameValue("B", "3"), MatchesCookieNameValue("C", "1"),
MatchesCookieNameValue("C", "2"), MatchesCookieNameValue("C", "3"),
MatchesCookieNameValue("D", "1"), MatchesCookieNameValue("D", "2")));
access_delegate_->SetExpectationForCookieScope("example.com",
CookieScopeSemantics::LEGACY);
cm->SetCookieAccessDelegate(std::move(access_delegate_));
cm->CheckAndActivateLegacyScopeBehavior(cookie->Domain());
cookies = GetAllCookies(cm.get());
EXPECT_THAT(cookies,
testing::UnorderedElementsAre(MatchesCookieNameValue("A", "4"),
MatchesCookieNameValue("B", "1"),
MatchesCookieNameValue("C", "1"),
MatchesCookieNameValue("D", "1"),
MatchesCookieNameValue("D", "2")));
ASSERT_TRUE(SetUnsafeCookieWithCreationTime(cm.get(),
example_with_https_port_value_80_,
"A=1;", now - base::Days(5)));
EXPECT_EQ(cm->CheckAndActivateLegacyScopeBehavior(cookie->Domain()),
CookieScopeSemantics::LEGACY);
cookies = GetAllCookies(cm.get());
EXPECT_THAT(
cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "1"), MatchesCookieNameValue("A", "4"),
MatchesCookieNameValue("B", "1"), MatchesCookieNameValue("C", "1"),
MatchesCookieNameValue("D", "1"), MatchesCookieNameValue("D", "2")));
}
TEST_F(CookieMonsterLegacyScopeTest, UpdateMostRecentlyCreatedCookie) {
using CookieMap =
std::multimap<std::string, std::unique_ptr<CanonicalCookie>>;
using CookieMapItPair = std::pair<CookieMap::iterator, CookieMap::iterator>;
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
std::map<UniqueCookieKey, std::pair<base::Time, UniqueCookieKey>>
most_recent_cookies;
base::Time four_days_ago = base::Time::Now() - base::Days(4);
base::Time three_days_ago = base::Time::Now() - base::Days(3);
base::Time two_days_ago = base::Time::Now() - base::Days(2);
base::Time one_day_ago = base::Time::Now() - base::Days(1);
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), example_with_https_port_value_80_, "A=1;", four_days_ago));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), example_with_https_port_value_800_, "A=2;", three_days_ago));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), example_with_https_port_value_8000_, "A=3;", two_days_ago));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), example_with_https_port_value_10_, "A=4;", one_day_ago));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), example_with_https_port_value_80_, "B=1;", four_days_ago));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), example_with_https_port_value_800_, "B=2;", three_days_ago));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), example_with_https_port_value_8000_, "B=3;", two_days_ago));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), example_with_https_port_value_10_, "B=4;", one_day_ago));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), example_with_https_port_value_80_, "C=1;", four_days_ago));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), example_with_https_port_value_800_, "C=2;", three_days_ago));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), example_with_https_port_value_8000_, "C=3;", two_days_ago));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), example_with_https_port_value_10_, "C=4;", one_day_ago));
auto cookies = GetAllCookies(cm.get());
CookieMap cookies_map;
for (const auto& cookie : cookies) {
cookies_map.emplace("example.com",
std::make_unique<CanonicalCookie>(cookie));
}
cm->UpdateMostRecentCookie(
CookieMapItPair(cookies_map.begin(), cookies_map.end()),
most_recent_cookies);
for (const auto& [key, value] : most_recent_cookies) {
EXPECT_EQ(value.first, one_day_ago);
}
EXPECT_EQ(most_recent_cookies.size(), 3UL);
}
TEST_F(CookieMonsterLegacyScopeTest,
DeleteAliasCookiesGetCookieListWithOptions) {
auto pref_delegate = std::make_unique<TestPrefDelegate>();
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get(),
std::move(pref_delegate));
base::Time now = Time::Now();
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_80_,
"A=1;", now - base::Days(5)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_800_,
"A=2;", now - base::Days(6)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_8000_,
"A=3;", now - base::Days(7)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_10_,
"A=4;", now - base::Days(2)));
ASSERT_TRUE(SetCookie(cm.get(), example_with_https_port_value_800_, "B=1;"));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_8000_,
"B=2;", now - base::Days(7)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_80_,
"B=3;", now - base::Days(6)));
ASSERT_TRUE(SetCookie(cm.get(), example_with_https_port_value_80_, "C=1;"));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_800_,
"C=2;", now - base::Days(7)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_8000_,
"C=3;", now - base::Days(7)));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), GURL("http://www.test.com:80/withDomain"), "D=1;",
now - base::Days(6)));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), GURL("https://www.test.com:100/withDomain"), "D=2;",
now - base::Days(1)));
CookieList cookies =
GetAllCookiesForURL(cm.get(), example_with_https_port_value_80_);
cookies = GetAllCookies(cm.get());
ASSERT_THAT(
cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "1"), MatchesCookieNameValue("A", "2"),
MatchesCookieNameValue("A", "3"), MatchesCookieNameValue("A", "4"),
MatchesCookieNameValue("B", "1"), MatchesCookieNameValue("B", "2"),
MatchesCookieNameValue("B", "3"), MatchesCookieNameValue("C", "1"),
MatchesCookieNameValue("C", "2"), MatchesCookieNameValue("C", "3"),
MatchesCookieNameValue("D", "1"), MatchesCookieNameValue("D", "2")));
access_delegate_->SetExpectationForCookieScope("example.com",
CookieScopeSemantics::LEGACY);
cm->SetCookieAccessDelegate(std::move(access_delegate_));
GetAllCookiesForURL(cm.get(), example_with_https_port_value_80_);
cookies = GetAllCookies(cm.get());
EXPECT_THAT(cookies,
testing::UnorderedElementsAre(MatchesCookieNameValue("A", "4"),
MatchesCookieNameValue("B", "1"),
MatchesCookieNameValue("C", "1"),
MatchesCookieNameValue("D", "1"),
MatchesCookieNameValue("D", "2")));
ASSERT_TRUE(SetUnsafeCookieWithCreationTime(cm.get(),
example_with_https_port_value_80_,
"A=1;", now - base::Days(5)));
GetAllCookiesForURL(cm.get(), example_with_https_port_value_80_);
cookies = GetAllCookies(cm.get());
EXPECT_THAT(
cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "1"), MatchesCookieNameValue("A", "4"),
MatchesCookieNameValue("B", "1"), MatchesCookieNameValue("C", "1"),
MatchesCookieNameValue("D", "1"), MatchesCookieNameValue("D", "2")));
}
TEST_F(CookieMonsterLegacyScopeTest,
DeleteAliasPartitionedCookiesGetCookieListWithOptions) {
auto pref_delegate = std::make_unique<TestPrefDelegate>();
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get(),
std::move(pref_delegate));
base::Time now = Time::Now();
auto cookie_partition_key =
CookiePartitionKey::FromURLForTesting(GURL("https://toplevelsite.com"));
auto cookie_partition_key2 =
CookiePartitionKey::FromURLForTesting(GURL("https://example.com"));
auto cookie_partition_key3 =
CookiePartitionKey::FromURLForTesting(GURL("https://foo.com"));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_80_,
"__Host-A-1=1; secure; path=/; partitioned;",
now - base::Days(6), cookie_partition_key));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_800_,
"__Host-A-2=1; secure; path=/; partitioned;",
now - base::Days(7), cookie_partition_key2));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_8000_,
"__Host-A-2=2; secure; path=/; partitioned;",
now - base::Days(8), cookie_partition_key2));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_8000_,
"__Host-A-3=1; secure; path=/; partitioned;",
now - base::Days(10), cookie_partition_key3));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_10_,
"__Host-A-1=2; secure; path=/; partitioned;",
now - base::Days(4), cookie_partition_key));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_8000_,
"__Host-B=1; secure; path=/; partitioned;",
now - base::Days(6), cookie_partition_key));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_80_,
"__Host-C=1; secure; path=/; partitioned;",
now - base::Days(6), cookie_partition_key));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), GURL("https://www.test.com:10/withDomain"),
"__Host-D=1; secure; path=/; partitioned;", now - base::Days(4),
cookie_partition_key2));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), GURL("https://www.test.com:80/withDomain"),
"__Host-D=2; secure; path=/; partitioned;", now - base::Days(1),
cookie_partition_key2));
CookieList cookies =
GetAllCookiesForURL(cm.get(), example_with_https_port_value_80_,
CookiePartitionKeyCollection(cookie_partition_key));
cookies = GetAllCookies(cm.get());
ASSERT_THAT(cookies, testing::UnorderedElementsAre(
MatchesCookieNameValue("__Host-A-1", "1"),
MatchesCookieNameValue("__Host-A-1", "2"),
MatchesCookieNameValue("__Host-A-2", "1"),
MatchesCookieNameValue("__Host-A-2", "2"),
MatchesCookieNameValue("__Host-A-3", "1"),
MatchesCookieNameValue("__Host-B", "1"),
MatchesCookieNameValue("__Host-C", "1"),
MatchesCookieNameValue("__Host-D", "1"),
MatchesCookieNameValue("__Host-D", "2")));
for (auto cookie : cookies) {
ASSERT_TRUE(cookie.IsPartitioned());
}
access_delegate_->SetExpectationForCookieScope("example.com",
CookieScopeSemantics::LEGACY);
cm->SetCookieAccessDelegate(std::move(access_delegate_));
GetAllCookiesForURL(cm.get(), example_with_https_port_value_80_,
CookiePartitionKeyCollection(cookie_partition_key));
cookies = GetAllCookies(cm.get());
EXPECT_THAT(cookies, testing::UnorderedElementsAre(
MatchesCookieNameValue("__Host-A-1", "2"),
MatchesCookieNameValue("__Host-A-2", "1"),
MatchesCookieNameValue("__Host-A-3", "1"),
MatchesCookieNameValue("__Host-B", "1"),
MatchesCookieNameValue("__Host-C", "1"),
MatchesCookieNameValue("__Host-D", "1"),
MatchesCookieNameValue("__Host-D", "2")));
ASSERT_TRUE(SetUnsafeCookieWithCreationTime(
cm.get(), example_with_https_port_value_80_,
"__Host-A-1=1; secure; path=/; partitioned;", now - base::Days(6),
cookie_partition_key));
GetAllCookiesForURL(cm.get(), example_with_https_port_value_80_,
CookiePartitionKeyCollection(cookie_partition_key));
cookies = GetAllCookies(cm.get());
EXPECT_THAT(cookies, testing::UnorderedElementsAre(
MatchesCookieNameValue("__Host-A-1", "1"),
MatchesCookieNameValue("__Host-A-1", "2"),
MatchesCookieNameValue("__Host-A-2", "1"),
MatchesCookieNameValue("__Host-A-3", "1"),
MatchesCookieNameValue("__Host-B", "1"),
MatchesCookieNameValue("__Host-C", "1"),
MatchesCookieNameValue("__Host-D", "1"),
MatchesCookieNameValue("__Host-D", "2")));
}
TEST_F(CookieMonsterLegacyScopeTest, DeleteAliasCookiesSetCanonicalCookie) {
auto pref_delegate = std::make_unique<TestPrefDelegate>();
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get(),
std::move(pref_delegate));
base::Time now = Time::Now();
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_80_,
"A=1;", now - base::Days(5)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_800_,
"A=2;", now - base::Days(6)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_8000_,
"A=3;", now - base::Days(7)));
ASSERT_TRUE(SetCookie(cm.get(), example_with_https_port_value_800_, "B=1;"));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_8000_,
"B=2;", now - base::Days(7)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_80_,
"B=3;", now - base::Days(6)));
ASSERT_TRUE(SetCookie(cm.get(), example_with_https_port_value_80_, "C=1;"));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_800_,
"C=2;", now - base::Days(7)));
ASSERT_TRUE(SetCookieWithCreationTime(cm.get(),
example_with_https_port_value_8000_,
"C=3;", now - base::Days(7)));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), GURL("http://www.test.com:80/withDomain"), "D=1;",
now - base::Days(6)));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), GURL("https://www.test.com:100/withDomain"), "D=2;",
now - base::Days(1)));
CookieList cookies = GetAllCookies(cm.get());
ASSERT_THAT(
cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "1"), MatchesCookieNameValue("A", "2"),
MatchesCookieNameValue("A", "3"), MatchesCookieNameValue("B", "1"),
MatchesCookieNameValue("B", "2"), MatchesCookieNameValue("B", "3"),
MatchesCookieNameValue("C", "1"), MatchesCookieNameValue("C", "2"),
MatchesCookieNameValue("C", "3"), MatchesCookieNameValue("D", "1"),
MatchesCookieNameValue("D", "2")));
access_delegate_->SetExpectationForCookieScope("example.com",
CookieScopeSemantics::LEGACY);
cm->SetCookieAccessDelegate(std::move(access_delegate_));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), example_with_https_port_value_10_, "A=4;", now));
cookies = GetAllCookies(cm.get());
EXPECT_THAT(cookies,
testing::UnorderedElementsAre(MatchesCookieNameValue("A", "4"),
MatchesCookieNameValue("B", "1"),
MatchesCookieNameValue("C", "1"),
MatchesCookieNameValue("D", "1"),
MatchesCookieNameValue("D", "2")));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), example_with_https_port_value_80_, "A=5;", now));
cookies = GetAllCookies(cm.get());
EXPECT_THAT(cookies,
testing::UnorderedElementsAre(MatchesCookieNameValue("A", "5"),
MatchesCookieNameValue("B", "1"),
MatchesCookieNameValue("C", "1"),
MatchesCookieNameValue("D", "1"),
MatchesCookieNameValue("D", "2")));
}
TEST_F(CookieMonsterLegacyScopeTest,
DeleteAliasPartitionedCookiesSetCanonicalCookies) {
auto pref_delegate = std::make_unique<TestPrefDelegate>();
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get(),
std::move(pref_delegate));
base::Time now = Time::Now();
auto cookie_partition_key =
CookiePartitionKey::FromURLForTesting(GURL("https://toplevelsite.com"));
auto cookie_partition_key2 =
CookiePartitionKey::FromURLForTesting(GURL("https://example.com"));
auto cookie_partition_key3 =
CookiePartitionKey::FromURLForTesting(GURL("https://foo.com"));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_80_,
"__Host-A-1=1; secure; path=/; partitioned;",
now - base::Days(6), cookie_partition_key));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_800_,
"__Host-A-2=1; secure; path=/; partitioned;",
now - base::Days(7), cookie_partition_key2));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_8000_,
"__Host-A-2=2; secure; path=/; partitioned;",
now - base::Days(8), cookie_partition_key2));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_8000_,
"__Host-A-3=1; secure; path=/; partitioned;",
now - base::Days(10), cookie_partition_key3));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_8000_,
"__Host-B=1; secure; path=/; partitioned;",
now - base::Days(6), cookie_partition_key));
ASSERT_TRUE(
SetCookieWithCreationTime(cm.get(), example_with_https_port_value_80_,
"__Host-C=1; secure; path=/; partitioned;",
now - base::Days(6), cookie_partition_key));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), GURL("https://www.test.com:10/withDomain"),
"__Host-D=1; secure; path=/; partitioned;", now - base::Days(4),
cookie_partition_key2));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), GURL("https://www.test.com:80/withDomain"),
"__Host-D=2; secure; path=/; partitioned;", now - base::Days(1),
cookie_partition_key2));
CookieList cookies = GetAllCookies(cm.get());
ASSERT_THAT(cookies, testing::UnorderedElementsAre(
MatchesCookieNameValue("__Host-A-1", "1"),
MatchesCookieNameValue("__Host-A-2", "1"),
MatchesCookieNameValue("__Host-A-2", "2"),
MatchesCookieNameValue("__Host-A-3", "1"),
MatchesCookieNameValue("__Host-B", "1"),
MatchesCookieNameValue("__Host-C", "1"),
MatchesCookieNameValue("__Host-D", "1"),
MatchesCookieNameValue("__Host-D", "2")));
for (auto cookie : cookies) {
ASSERT_TRUE(cookie.IsPartitioned());
}
access_delegate_->SetExpectationForCookieScope("example.com",
CookieScopeSemantics::LEGACY);
cm->SetCookieAccessDelegate(std::move(access_delegate_));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), example_with_https_port_value_10_,
"__Host-A-1=2; secure; path=/; partitioned;", now, cookie_partition_key));
cookies = GetAllCookies(cm.get());
EXPECT_THAT(cookies, testing::UnorderedElementsAre(
MatchesCookieNameValue("__Host-A-1", "2"),
MatchesCookieNameValue("__Host-A-2", "1"),
MatchesCookieNameValue("__Host-A-3", "1"),
MatchesCookieNameValue("__Host-B", "1"),
MatchesCookieNameValue("__Host-C", "1"),
MatchesCookieNameValue("__Host-D", "1"),
MatchesCookieNameValue("__Host-D", "2")));
ASSERT_TRUE(SetCookieWithCreationTime(
cm.get(), example_with_https_port_value_80_,
"__Host-A-1=3; secure; path=/; partitioned;", now, cookie_partition_key));
cookies = GetAllCookies(cm.get());
EXPECT_THAT(cookies, testing::UnorderedElementsAre(
MatchesCookieNameValue("__Host-A-1", "3"),
MatchesCookieNameValue("__Host-A-2", "1"),
MatchesCookieNameValue("__Host-A-3", "1"),
MatchesCookieNameValue("__Host-B", "1"),
MatchesCookieNameValue("__Host-C", "1"),
MatchesCookieNameValue("__Host-D", "1"),
MatchesCookieNameValue("__Host-D", "2")));
}
TEST_F(CookieMonsterTest, ExpireSinglePartitionedCookie) {
auto cm = std::make_unique<CookieMonster>(
nullptr, net::NetLog::Get());
auto cookie_partition_key =
CookiePartitionKey::FromURLForTesting(GURL("https://toplevelsite.com"));
ASSERT_TRUE(SetCookie(cm.get(), https_www_bar_.url(),
"__Host-A=1; secure; path=/; partitioned; max-age=1",
cookie_partition_key));
CookieList cookies =
GetAllCookiesForURL(cm.get(), https_www_bar_.url(),
CookiePartitionKeyCollection(cookie_partition_key));
ASSERT_EQ(1u, cookies.size());
base::PlatformThread::Sleep(base::Seconds(1));
cookies = GetAllCookiesForURL(cm.get(), https_www_bar_.url(),
CookiePartitionKeyCollection::ContainsAll());
EXPECT_EQ(0u, cookies.size());
}
TEST_F(CookieMonsterTest, DeleteExpiredAfterTimeElapsed_GetAllCookies) {
auto cm = std::make_unique<CookieMonster>(
nullptr, net::NetLog::Get());
EXPECT_TRUE(SetCookie(cm.get(), https_www_bar_.url(),
"__Host-A=B; secure; path=/",
std::nullopt));
EXPECT_TRUE(SetCookie(cm.get(), https_www_bar_.url(),
"__Host-C=D; secure; path=/; max-age=1",
std::nullopt));
GetAllCookiesCallback get_cookies_callback1;
cm->GetAllCookiesAsync(get_cookies_callback1.MakeCallback());
get_cookies_callback1.WaitUntilDone();
ASSERT_EQ(2u, get_cookies_callback1.cookies().size());
base::PlatformThread::Sleep(base::Seconds(1));
GetAllCookiesCallback get_cookies_callback2;
cm->GetAllCookiesAsync(get_cookies_callback2.MakeCallback());
get_cookies_callback2.WaitUntilDone();
ASSERT_EQ(1u, get_cookies_callback2.cookies().size());
EXPECT_EQ("__Host-A", get_cookies_callback2.cookies()[0].Name());
}
TEST_F(CookieMonsterTest,
DeleteExpiredPartitionedCookiesAfterTimeElapsed_GetAllCookies) {
auto cm = std::make_unique<CookieMonster>(
nullptr, net::NetLog::Get());
auto cookie_partition_key =
CookiePartitionKey::FromURLForTesting(GURL("https://toplevelsite.com"));
EXPECT_TRUE(SetCookie(cm.get(), https_www_bar_.url(),
"__Host-A=B; secure; path=/; partitioned",
cookie_partition_key));
EXPECT_TRUE(SetCookie(cm.get(), https_www_bar_.url(),
"__Host-C=D; secure; path=/; max-age=1; partitioned",
cookie_partition_key));
GetAllCookiesCallback get_cookies_callback1;
cm->GetAllCookiesAsync(get_cookies_callback1.MakeCallback());
get_cookies_callback1.WaitUntilDone();
ASSERT_EQ(2u, get_cookies_callback1.cookies().size());
base::PlatformThread::Sleep(base::Seconds(1));
GetAllCookiesCallback get_cookies_callback2;
cm->GetAllCookiesAsync(get_cookies_callback2.MakeCallback());
get_cookies_callback2.WaitUntilDone();
ASSERT_EQ(1u, get_cookies_callback2.cookies().size());
EXPECT_EQ("__Host-A", get_cookies_callback2.cookies()[0].Name());
}
TEST_F(CookieMonsterTest, DeletePartitionedCookie) {
auto cm = std::make_unique<CookieMonster>(
nullptr, net::NetLog::Get());
auto cookie_partition_key =
CookiePartitionKey::FromURLForTesting(GURL("https://toplevelsite.com"));
EXPECT_TRUE(SetCookie(cm.get(), https_www_bar_.url(),
"__Host-A=B; secure; path=/; partitioned",
cookie_partition_key));
EXPECT_TRUE(SetCookie(cm.get(), https_www_bar_.url(),
"__Host-C=D; secure; path=/; partitioned",
cookie_partition_key));
EXPECT_TRUE(SetCookie(cm.get(), https_www_bar_.url(),
"__Host-E=F; secure; path=/", std::nullopt));
auto cookie = CanonicalCookie::CreateForTesting(
https_www_bar_.url(), "__Host-A=B; secure; path=/; partitioned",
Time::Now(), std::nullopt,
cookie_partition_key);
ASSERT_TRUE(cookie);
ResultSavingCookieCallback<unsigned int> delete_callback;
cm->DeleteCanonicalCookieAsync(*cookie, delete_callback.MakeCallback());
delete_callback.WaitUntilDone();
CookieList cookies =
GetAllCookiesForURL(cm.get(), https_www_bar_.url(),
CookiePartitionKeyCollection(cookie_partition_key));
EXPECT_EQ(2u, cookies.size());
EXPECT_EQ(cookies[0].Name(), "__Host-C");
EXPECT_EQ(cookies[1].Name(), "__Host-E");
}
TEST_F(CookieMonsterTest, DontImportDuplicateCookies) {
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
std::vector<std::unique_ptr<CanonicalCookie>> initial_cookies;
AddCookieToList(GURL("http://www.foo.com"),
"X=1; path=/" + FutureCookieExpirationString(),
Time::Now() + base::Days(3), &initial_cookies);
AddCookieToList(GURL("http://www.foo.com"),
"X=2; path=/" + FutureCookieExpirationString(),
Time::Now() + base::Days(1), &initial_cookies);
AddCookieToList(GURL("http://www.foo.com"),
"X=3; path=/" + FutureCookieExpirationString(),
Time::Now() + base::Days(4), &initial_cookies);
AddCookieToList(GURL("http://www.foo.com"),
"X=4; path=/" + FutureCookieExpirationString(), Time::Now(),
&initial_cookies);
AddCookieToList(GURL("http://www.foo.com"),
"X=a1; path=/2" + FutureCookieExpirationString(),
Time::Now() + base::Days(9), &initial_cookies);
AddCookieToList(GURL("http://www.foo.com"),
"X=a2; path=/2" + FutureCookieExpirationString(),
Time::Now() + base::Days(2), &initial_cookies);
AddCookieToList(GURL("http://www.foo.com"),
"Y=a; path=/" + FutureCookieExpirationString(),
Time::Now() + base::Days(10), &initial_cookies);
store->SetLoadExpectation(true, std::move(initial_cookies));
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
EXPECT_EQ("X=3; Y=a", GetCookies(cm.get(), GURL("http://www.foo.com/")));
EXPECT_EQ("X=a1; X=3; Y=a",
GetCookies(cm.get(), GURL("http://www.foo.com/2/x")));
ASSERT_EQ(4u, store->commands().size());
EXPECT_EQ(CookieStoreCommand::REMOVE, store->commands()[0].type);
EXPECT_EQ(CookieStoreCommand::REMOVE, store->commands()[1].type);
EXPECT_EQ(CookieStoreCommand::REMOVE, store->commands()[2].type);
EXPECT_EQ(CookieStoreCommand::REMOVE, store->commands()[3].type);
}
TEST_F(CookieMonsterTest, DontImportDuplicateCookies_PartitionedCookies) {
std::vector<std::unique_ptr<CanonicalCookie>> initial_cookies;
auto cookie_partition_key =
CookiePartitionKey::FromURLForTesting(GURL("https://www.foo.com"));
GURL cookie_url("https://www.bar.com");
auto cc = CanonicalCookie::CreateForTesting(
cookie_url, "__Host-Z=a; Secure; Path=/; Partitioned; Max-Age=3456000",
Time::Now() + base::Days(2), std::nullopt, cookie_partition_key);
initial_cookies.push_back(std::move(cc));
cc = CanonicalCookie::CreateForTesting(
cookie_url, "__Host-Z=b; Secure; Path=/; Partitioned; Max-Age=3456000",
Time::Now(), std::nullopt, cookie_partition_key);
initial_cookies.push_back(std::move(cc));
cc = CanonicalCookie::CreateForTesting(
cookie_url, "__Host-Z=c; Secure; Path=/; Partitioned; Max-Age=3456000",
Time::Now() + base::Days(1), std::nullopt, cookie_partition_key);
initial_cookies.push_back(std::move(cc));
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
store->SetLoadExpectation(true, std::move(initial_cookies));
EXPECT_EQ("__Host-Z=a",
GetCookies(cm.get(), GURL("https://www.bar.com/"),
CookiePartitionKeyCollection(cookie_partition_key)));
ASSERT_EQ(2u, store->commands().size());
EXPECT_EQ(CookieStoreCommand::REMOVE, store->commands()[0].type);
EXPECT_EQ(CookieStoreCommand::REMOVE, store->commands()[1].type);
}
TEST_F(CookieMonsterTest, ImportDuplicateCreationTimes) {
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
Time now(Time::Now());
Time earlier(now - base::Days(1));
std::vector<std::unique_ptr<CanonicalCookie>> initial_cookies;
AddCookieToList(GURL("http://www.foo.com"), "X=1; path=/", now,
&initial_cookies);
AddCookieToList(GURL("http://www.foo.com"), "X=2; path=/", now,
&initial_cookies);
AddCookieToList(GURL("http://www.foo.com"), "X=3; path=/", now,
&initial_cookies);
AddCookieToList(GURL("http://www.foo.com"), "X=4; path=/", now,
&initial_cookies);
AddCookieToList(GURL("http://www.foo.com"), "Y=1; path=/", earlier,
&initial_cookies);
AddCookieToList(GURL("http://www.foo.com"), "Y=2; path=/", earlier,
&initial_cookies);
AddCookieToList(GURL("http://www.foo.com"), "Y=3; path=/", earlier,
&initial_cookies);
AddCookieToList(GURL("http://www.foo.com"), "Y=4; path=/", earlier,
&initial_cookies);
store->SetLoadExpectation(true, std::move(initial_cookies));
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
CookieList list(GetAllCookies(cm.get()));
EXPECT_EQ(2U, list.size());
std::string name1(list[0].Name());
std::string name2(list[1].Name());
EXPECT_TRUE(name1 == "X" || name2 == "X");
EXPECT_TRUE(name1 == "Y" || name2 == "Y");
EXPECT_NE(name1, name2);
}
TEST_F(CookieMonsterTest, ImportDuplicateCreationTimes_PartitionedCookies) {
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
Time now(Time::Now());
Time earlier(now - base::Days(1));
GURL cookie_url("https://www.foo.com");
auto cookie_partition_key =
CookiePartitionKey::FromURLForTesting(GURL("https://www.bar.com"));
std::vector<std::unique_ptr<CanonicalCookie>> initial_cookies;
auto cc = CanonicalCookie::CreateForTesting(
cookie_url, "__Host-X=1; Secure; Path=/; Partitioned; Max-Age=3456000",
now, std::nullopt, cookie_partition_key);
initial_cookies.push_back(std::move(cc));
cc = CanonicalCookie::CreateForTesting(
cookie_url, "__Host-X=2; Secure; Path=/; Partitioned; Max-Age=3456000",
now, std::nullopt, cookie_partition_key);
initial_cookies.push_back(std::move(cc));
cc = CanonicalCookie::CreateForTesting(
cookie_url, "__Host-X=3; Secure; Path=/; Partitioned; Max-Age=3456000",
now, std::nullopt, cookie_partition_key);
initial_cookies.push_back(std::move(cc));
cc = CanonicalCookie::CreateForTesting(
cookie_url, "__Host-Y=1; Secure; Path=/; Partitioned; Max-Age=3456000",
earlier, std::nullopt, cookie_partition_key);
initial_cookies.push_back(std::move(cc));
cc = CanonicalCookie::CreateForTesting(
cookie_url, "__Host-Y=2; Secure; Path=/; Partitioned; Max-Age=3456000",
earlier, std::nullopt, cookie_partition_key);
initial_cookies.push_back(std::move(cc));
cc = CanonicalCookie::CreateForTesting(
cookie_url, "__Host-Y=3; Secure; Path=/; Partitioned; Max-Age=3456000",
earlier, std::nullopt, cookie_partition_key);
initial_cookies.push_back(std::move(cc));
store->SetLoadExpectation(true, std::move(initial_cookies));
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
CookieList list(GetAllCookies(cm.get()));
EXPECT_EQ(2U, list.size());
std::string name1(list[0].Name());
std::string name2(list[1].Name());
EXPECT_TRUE(name1 == "__Host-X" || name2 == "__Host-X");
EXPECT_TRUE(name1 == "__Host-Y" || name2 == "__Host-Y");
EXPECT_NE(name1, name2);
}
TEST_F(CookieMonsterTest, PredicateSeesAllCookies) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
const base::Time now = PopulateCmForPredicateCheck(cm.get());
CookieDeletionInfo delete_info(base::Time(), now);
delete_info.value_for_testing = "A";
EXPECT_EQ(8u, DeleteAllMatchingInfo(cm.get(), std::move(delete_info)));
EXPECT_EQ("dom_2=B; dom_3=C; host_3=C",
GetCookies(cm.get(), GURL(kTopLevelDomainPlus3)));
EXPECT_EQ("dom_2=B; host_2=B; sec_host=B",
GetCookies(cm.get(), GURL(kTopLevelDomainPlus2Secure)));
EXPECT_EQ("", GetCookies(cm.get(), GURL(kTopLevelDomainPlus1)));
EXPECT_EQ("dom_path_2=B; host_path_2=B; dom_2=B; host_2=B; sec_host=B",
GetCookies(cm.get(), GURL(kTopLevelDomainPlus2Secure +
std::string("/dir1/dir2/xxx"))));
EXPECT_EQ("dom_2=B; host_2=B; sec_host=B; __Host-pc_2=B",
GetCookies(cm.get(), GURL(kTopLevelDomainPlus2Secure),
CookiePartitionKeyCollection(
CookiePartitionKey::FromURLForTesting(
GURL(kTopLevelDomainPlus1)))));
}
TEST_F(CookieMonsterTest, GetKey) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
EXPECT_EQ("foo.com", cm->GetKey("www.foo.com"));
EXPECT_EQ("google.izzie", cm->GetKey("www.google.izzie"));
EXPECT_EQ("google.izzie", cm->GetKey(".google.izzie"));
EXPECT_EQ("bbc.co.uk", cm->GetKey("bbc.co.uk"));
EXPECT_EQ("bbc.co.uk", cm->GetKey("a.b.c.d.bbc.co.uk"));
EXPECT_EQ("apple.com", cm->GetKey("a.b.c.d.apple.com"));
EXPECT_EQ("apple.izzie", cm->GetKey("a.b.c.d.apple.izzie"));
EXPECT_EQ("co.uk", cm->GetKey("co.uk"));
const std::string extension_name("iehocdgbbocmkdidlbnnfbmbinnahbae");
EXPECT_EQ(extension_name, cm->GetKey(extension_name));
EXPECT_EQ("com", cm->GetKey("com"));
EXPECT_EQ("hostalias", cm->GetKey("hostalias"));
EXPECT_EQ("localhost", cm->GetKey("localhost"));
}
TEST_F(CookieMonsterTest, BackingStoreCommunication) {
base::Time current(base::Time::Now());
auto store = base::MakeRefCounted<MockSimplePersistentCookieStore>();
base::Time expires(base::Time::Now() + base::Seconds(100));
const auto input_info = std::to_array<CookiesInputInfo>({
{GURL("https://a.b.foo.com"), "a", "1", "a.b.foo.com", "/path/to/cookie",
expires, true , false, CookieSameSite::NO_RESTRICTION,
COOKIE_PRIORITY_DEFAULT},
{GURL("https://www.foo.com"), "b", "2", ".foo.com", "/path/from/cookie",
expires + base::Seconds(10), true, true, CookieSameSite::NO_RESTRICTION,
COOKIE_PRIORITY_DEFAULT},
{GURL("https://foo.com"), "c", "3", "foo.com", "/another/path/to/cookie",
base::Time::Now() + base::Seconds(100), false, false,
CookieSameSite::STRICT_MODE, COOKIE_PRIORITY_DEFAULT},
});
const int INPUT_DELETE = 1;
{
auto cmout =
std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
for (const auto& cookie : input_info) {
EXPECT_TRUE(SetCanonicalCookie(
cmout.get(),
CanonicalCookie::CreateUnsafeCookieForTesting(
cookie.name, cookie.value, cookie.domain, cookie.path,
base::Time(), cookie.expiration_time, base::Time(), base::Time(),
cookie.secure, cookie.http_only, cookie.same_site,
cookie.priority),
cookie.url, true ));
}
EXPECT_TRUE(FindAndDeleteCookie(cmout.get(),
input_info[INPUT_DELETE].domain,
input_info[INPUT_DELETE].name));
}
{
auto cmin =
std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
CookieList cookies(GetAllCookies(cmin.get()));
ASSERT_EQ(2u, cookies.size());
std::swap(cookies[0], cookies[1]);
for (int output_index = 0; output_index < 2; output_index++) {
int input_index = output_index * 2;
const CookiesInputInfo* input = &input_info[input_index];
const CanonicalCookie* output = &cookies[output_index];
EXPECT_EQ(input->name, output->Name());
EXPECT_EQ(input->value, output->Value());
EXPECT_EQ(input->url.GetHost(), output->Domain());
EXPECT_EQ(input->path, output->Path());
EXPECT_LE(current.ToInternalValue(),
output->CreationDate().ToInternalValue());
EXPECT_EQ(input->secure, output->SecureAttribute());
EXPECT_EQ(input->http_only, output->IsHttpOnly());
EXPECT_EQ(input->same_site, output->SameSite());
EXPECT_TRUE(output->IsPersistent());
EXPECT_EQ(input->expiration_time.ToInternalValue(),
output->ExpiryDate().ToInternalValue());
}
}
}
TEST_F(CookieMonsterTest, RestoreDifferentCookieSameCreationTime) {
base::Time current(base::Time::Now());
scoped_refptr<MockPersistentCookieStore> store =
base::MakeRefCounted<MockPersistentCookieStore>();
{
CookieMonster cmout(store.get(), net::NetLog::Get());
GURL url("http://www.example.com/");
EXPECT_TRUE(
SetCookieWithCreationTime(&cmout, url, "A=1; max-age=600", current));
EXPECT_TRUE(
SetCookieWithCreationTime(&cmout, url, "B=2; max-age=600", current));
}
scoped_refptr<MockPersistentCookieStore> store2 =
base::MakeRefCounted<MockPersistentCookieStore>();
std::vector<std::unique_ptr<CanonicalCookie>> load_expectation;
EXPECT_EQ(2u, store->commands().size());
for (const CookieStoreCommand& command : store->commands()) {
ASSERT_EQ(command.type, CookieStoreCommand::ADD);
load_expectation.push_back(
std::make_unique<CanonicalCookie>(command.cookie));
}
store2->SetLoadExpectation(true, std::move(load_expectation));
{
CookieMonster cmin(store2.get(), net::NetLog::Get());
CookieList cookies(GetAllCookies(&cmin));
ASSERT_EQ(2u, cookies.size());
}
}
TEST_F(CookieMonsterTest, CookieListOrdering) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
EXPECT_TRUE(
SetCookie(cm.get(), GURL("http://d.c.b.a.foo.com/aa/x.html"), "c=1"));
EXPECT_TRUE(SetCookie(cm.get(), GURL("http://b.a.foo.com/aa/bb/cc/x.html"),
"d=1; domain=b.a.foo.com"));
EXPECT_TRUE(SetCookie(cm.get(), GURL("http://b.a.foo.com/aa/bb/cc/x.html"),
"a=4; domain=b.a.foo.com"));
EXPECT_TRUE(SetCookie(cm.get(), GURL("http://c.b.a.foo.com/aa/bb/cc/x.html"),
"e=1; domain=c.b.a.foo.com"));
EXPECT_TRUE(
SetCookie(cm.get(), GURL("http://d.c.b.a.foo.com/aa/bb/x.html"), "b=1"));
EXPECT_TRUE(SetCookie(cm.get(), GURL("http://news.bbc.co.uk/midpath/x.html"),
"g=10"));
{
unsigned int i = 0;
CookieList cookies(GetAllCookiesForURL(
cm.get(), GURL("http://d.c.b.a.foo.com/aa/bb/cc/dd")));
ASSERT_EQ(5u, cookies.size());
EXPECT_EQ("d", cookies[i++].Name());
EXPECT_EQ("a", cookies[i++].Name());
EXPECT_EQ("e", cookies[i++].Name());
EXPECT_EQ("b", cookies[i++].Name());
EXPECT_EQ("c", cookies[i++].Name());
}
{
unsigned int i = 0;
CookieList cookies(GetAllCookies(cm.get()));
ASSERT_EQ(6u, cookies.size());
EXPECT_EQ("d", cookies[i++].Name());
EXPECT_EQ("a", cookies[i++].Name());
EXPECT_EQ("e", cookies[i++].Name());
EXPECT_EQ("g", cookies[i++].Name());
EXPECT_EQ("b", cookies[i++].Name());
EXPECT_EQ("c", cookies[i++].Name());
}
}
TEST_F(CookieMonsterTest, GarbageCollectionKeepsRecentEphemeralCookies) {
std::unique_ptr<CookieMonster> cm(
CreateMonsterForGC(CookieMonster::kMaxCookies * 2 ));
EXPECT_EQ(CookieMonster::kMaxCookies * 2, GetAllCookies(cm.get()).size());
SetCookie(cm.get(), GURL("http://newdomain.com"), "b=2");
EXPECT_EQ(CookieMonster::kMaxCookies * 2 + 1, GetAllCookies(cm.get()).size());
}
TEST_F(CookieMonsterTest, GarbageCollectionKeepsRecentCookies) {
std::unique_ptr<CookieMonster> cm = CreateMonsterFromStoreForGC(
CookieMonster::kMaxCookies * 2 , 0 ,
0, 0, CookieMonster::kSafeFromGlobalPurgeDays * 2);
EXPECT_EQ(CookieMonster::kMaxCookies * 2, GetAllCookies(cm.get()).size());
SetCookie(cm.get(), GURL("http://newdomain.com"), "b=2");
EXPECT_EQ(CookieMonster::kMaxCookies * 2 + 1, GetAllCookies(cm.get()).size());
}
TEST_F(CookieMonsterTest, GarbageCollectionKeepsOnlyRecentCookies) {
std::unique_ptr<CookieMonster> cm = CreateMonsterFromStoreForGC(
CookieMonster::kMaxCookies * 2 ,
CookieMonster::kMaxCookies / 2 , 0, 0,
CookieMonster::kSafeFromGlobalPurgeDays * 2);
EXPECT_EQ(CookieMonster::kMaxCookies * 2, GetAllCookies(cm.get()).size());
SetCookie(cm.get(), GURL("http://newdomain.com"), "b=2");
EXPECT_EQ(CookieMonster::kMaxCookies * 2 - CookieMonster::kMaxCookies / 2 + 1,
GetAllCookies(cm.get()).size());
}
TEST_F(CookieMonsterTest, GarbageCollectionExactlyAllOldCookiesDeleted) {
std::unique_ptr<CookieMonster> cm = CreateMonsterFromStoreForGC(
CookieMonster::kMaxCookies * 2 ,
CookieMonster::kMaxCookies + CookieMonster::kPurgeCookies +
1 ,
0, 0, CookieMonster::kSafeFromGlobalPurgeDays * 2);
EXPECT_EQ(CookieMonster::kMaxCookies * 2, GetAllCookies(cm.get()).size());
SetCookie(cm.get(), GURL("http://newdomain.com"), "b=2");
EXPECT_EQ(CookieMonster::kMaxCookies - CookieMonster::kPurgeCookies,
GetAllCookies(cm.get()).size());
}
TEST_F(CookieMonsterTest, GarbageCollectionTriggers5) {
std::unique_ptr<CookieMonster> cm = CreateMonsterFromStoreForGC(
CookieMonster::kMaxCookies * 2 ,
CookieMonster::kMaxCookies * 3 / 2 , 0, 0,
CookieMonster::kSafeFromGlobalPurgeDays * 2);
EXPECT_EQ(CookieMonster::kMaxCookies * 2, GetAllCookies(cm.get()).size());
SetCookie(cm.get(), GURL("http://newdomain.com"), "b=2");
EXPECT_EQ(CookieMonster::kMaxCookies - CookieMonster::kPurgeCookies,
GetAllCookies(cm.get()).size());
}
TEST_F(CookieMonsterTest, GarbageCollectWithSecureCookiesOnly) {
std::unique_ptr<CookieMonster> cm = CreateMonsterFromStoreForGC(
CookieMonster::kMaxCookies ,
CookieMonster::kMaxCookies ,
0 , 0 ,
CookieMonster::kSafeFromGlobalPurgeDays * 2 );
EXPECT_EQ(CookieMonster::kMaxCookies, GetAllCookies(cm.get()).size());
SetCookie(cm.get(), GURL("https://newdomain.com"), "b=2; Secure");
EXPECT_EQ(CookieMonster::kMaxCookies - CookieMonster::kPurgeCookies,
GetAllCookies(cm.get()).size());
}
TEST_F(CookieMonsterTest, WhileLoadingLoadCompletesBeforeKeyLoadCompletes) {
const GURL kUrl = GURL(kTopLevelDomainPlus1);
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
store->set_store_load_commands(true);
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
auto cookie =
CanonicalCookie::CreateForTesting(kUrl, "a=b", base::Time::Now());
ResultSavingCookieCallback<CookieAccessResult> set_cookie_callback;
cm->SetCanonicalCookieAsync(std::move(cookie), kUrl,
CookieOptions::MakeAllInclusive(),
set_cookie_callback.MakeCallback());
GetAllCookiesCallback get_cookies_callback1;
cm->GetAllCookiesAsync(get_cookies_callback1.MakeCallback());
ASSERT_EQ(2u, store->commands().size());
ASSERT_EQ(CookieStoreCommand::LOAD, store->commands()[0].type);
ASSERT_EQ(CookieStoreCommand::LOAD_COOKIES_FOR_KEY,
store->commands()[1].type);
store->TakeCallbackAt(0).Run(std::vector<std::unique_ptr<CanonicalCookie>>());
set_cookie_callback.WaitUntilDone();
EXPECT_TRUE(set_cookie_callback.result().status.IsInclude());
get_cookies_callback1.WaitUntilDone();
EXPECT_EQ(1u, get_cookies_callback1.cookies().size());
store->TakeCallbackAt(1).Run(std::vector<std::unique_ptr<CanonicalCookie>>());
GetAllCookiesCallback get_cookies_callback2;
cm->GetAllCookiesAsync(get_cookies_callback2.MakeCallback());
get_cookies_callback2.WaitUntilDone();
EXPECT_EQ(1u, get_cookies_callback2.cookies().size());
}
TEST_F(CookieMonsterTest, WhileLoadingDeleteAllGetForURL) {
const GURL kUrl = GURL(kTopLevelDomainPlus1);
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
store->set_store_load_commands(true);
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
ResultSavingCookieCallback<uint32_t> delete_callback;
cm->DeleteAllAsync(delete_callback.MakeCallback());
GetCookieListCallback get_cookie_list_callback;
cm->GetCookieListWithOptionsAsync(kUrl, CookieOptions::MakeAllInclusive(),
CookiePartitionKeyCollection(),
get_cookie_list_callback.MakeCallback());
ASSERT_EQ(1u, store->commands().size());
ASSERT_EQ(CookieStoreCommand::LOAD, store->commands()[0].type);
std::vector<std::unique_ptr<CanonicalCookie>> cookies;
cookies.push_back(
CanonicalCookie::CreateForTesting(kUrl, "a=b", base::Time::Now()));
ASSERT_TRUE(cookies[0]);
store->TakeCallbackAt(0).Run(std::move(cookies));
delete_callback.WaitUntilDone();
EXPECT_EQ(1u, delete_callback.result());
get_cookie_list_callback.WaitUntilDone();
EXPECT_EQ(0u, get_cookie_list_callback.cookies().size());
}
TEST_F(CookieMonsterTest, WhileLoadingGetAllSetGetAll) {
const GURL kUrl = GURL(kTopLevelDomainPlus1);
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
store->set_store_load_commands(true);
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
GetAllCookiesCallback get_cookies_callback1;
cm->GetAllCookiesAsync(get_cookies_callback1.MakeCallback());
auto cookie =
CanonicalCookie::CreateForTesting(kUrl, "a=b", base::Time::Now());
ResultSavingCookieCallback<CookieAccessResult> set_cookie_callback;
cm->SetCanonicalCookieAsync(std::move(cookie), kUrl,
CookieOptions::MakeAllInclusive(),
set_cookie_callback.MakeCallback());
GetAllCookiesCallback get_cookies_callback2;
cm->GetAllCookiesAsync(get_cookies_callback2.MakeCallback());
ASSERT_EQ(1u, store->commands().size());
ASSERT_EQ(CookieStoreCommand::LOAD, store->commands()[0].type);
store->TakeCallbackAt(0).Run(std::vector<std::unique_ptr<CanonicalCookie>>());
get_cookies_callback1.WaitUntilDone();
EXPECT_EQ(0u, get_cookies_callback1.cookies().size());
set_cookie_callback.WaitUntilDone();
EXPECT_TRUE(set_cookie_callback.result().status.IsInclude());
get_cookies_callback2.WaitUntilDone();
EXPECT_EQ(1u, get_cookies_callback2.cookies().size());
}
namespace {
void RunClosureOnAllCookiesReceived(base::OnceClosure closure,
const CookieList& cookie_list) {
std::move(closure).Run();
}
}
TEST_F(CookieMonsterTest, CheckOrderOfCookieTaskQueueWhenLoadingCompletes) {
const GURL kUrl = GURL(kTopLevelDomainPlus1);
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
store->set_store_load_commands(true);
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
auto cookie =
CanonicalCookie::CreateForTesting(kUrl, "a=b", base::Time::Now());
ResultSavingCookieCallback<CookieAccessResult> set_cookie_callback;
cm->GetAllCookiesAsync(base::BindOnce(
&RunClosureOnAllCookiesReceived,
base::BindOnce(&CookieStore::SetCanonicalCookieAsync,
base::Unretained(cm.get()), std::move(cookie), kUrl,
CookieOptions::MakeAllInclusive(),
set_cookie_callback.MakeCallback(), std::nullopt)));
GetAllCookiesCallback get_cookies_callback1;
cm->GetAllCookiesAsync(get_cookies_callback1.MakeCallback());
ASSERT_EQ(1u, store->commands().size());
ASSERT_EQ(CookieStoreCommand::LOAD, store->commands()[0].type);
store->TakeCallbackAt(0).Run(std::vector<std::unique_ptr<CanonicalCookie>>());
get_cookies_callback1.WaitUntilDone();
EXPECT_EQ(0u, get_cookies_callback1.cookies().size());
set_cookie_callback.WaitUntilDone();
EXPECT_TRUE(set_cookie_callback.result().status.IsInclude());
GetAllCookiesCallback get_cookies_callback2;
cm->GetAllCookiesAsync(get_cookies_callback2.MakeCallback());
get_cookies_callback2.WaitUntilDone();
EXPECT_EQ(1u, get_cookies_callback2.cookies().size());
}
TEST_F(CookieMonsterTest, FlushStore) {
auto counter = base::MakeRefCounted<CallbackCounter>();
auto store = base::MakeRefCounted<FlushablePersistentStore>();
auto cm = std::make_unique<CookieMonster>(store, net::NetLog::Get());
ASSERT_EQ(0, store->flush_count());
ASSERT_EQ(0, counter->callback_count());
cm->FlushStore(base::BindOnce(&CallbackCounter::Callback, counter));
base::RunLoop().RunUntilIdle();
ASSERT_EQ(0, store->flush_count());
ASSERT_EQ(1, counter->callback_count());
cm->FlushStore(base::OnceClosure());
base::RunLoop().RunUntilIdle();
ASSERT_EQ(0, store->flush_count());
ASSERT_EQ(1, counter->callback_count());
GetAllCookies(cm.get());
cm->FlushStore(base::BindOnce(&CallbackCounter::Callback, counter));
base::RunLoop().RunUntilIdle();
ASSERT_EQ(1, store->flush_count());
ASSERT_EQ(2, counter->callback_count());
cm->FlushStore(base::DoNothing());
base::RunLoop().RunUntilIdle();
ASSERT_EQ(2, store->flush_count());
ASSERT_EQ(2, counter->callback_count());
cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
GetAllCookies(cm.get());
cm->FlushStore(base::DoNothing());
base::RunLoop().RunUntilIdle();
ASSERT_EQ(2, counter->callback_count());
cm->FlushStore(base::BindOnce(&CallbackCounter::Callback, counter));
base::RunLoop().RunUntilIdle();
ASSERT_EQ(3, counter->callback_count());
}
TEST_F(CookieMonsterTest, SetAllCookies) {
auto store = base::MakeRefCounted<FlushablePersistentStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
cm->SetPersistSessionCookies(true);
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), "U=V; path=/"));
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), "W=X; path=/foo"));
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), "Y=Z; path=/"));
CookieList list;
list.push_back(*CanonicalCookie::CreateUnsafeCookieForTesting(
"A", "B", "." + http_www_foo_.url().GetHost(), "/", base::Time::Now(),
base::Time(), base::Time(), base::Time(), false, false,
CookieSameSite::NO_RESTRICTION, COOKIE_PRIORITY_DEFAULT));
list.push_back(*CanonicalCookie::CreateUnsafeCookieForTesting(
"C", "D", "." + http_www_foo_.url().GetHost(), "/bar", base::Time::Now(),
base::Time(), base::Time(), base::Time(), false, false,
CookieSameSite::NO_RESTRICTION, COOKIE_PRIORITY_DEFAULT));
list.push_back(*CanonicalCookie::CreateUnsafeCookieForTesting(
"W", "X", "." + http_www_foo_.url().GetHost(), "/", base::Time::Now(),
base::Time(), base::Time(), base::Time(), false, false,
CookieSameSite::NO_RESTRICTION, COOKIE_PRIORITY_DEFAULT));
list.push_back(*CanonicalCookie::CreateUnsafeCookieForTesting(
"__Host-Y", "Z", https_www_foo_.url().GetHost(), "/", base::Time::Now(),
base::Time(), base::Time(), base::Time(), true, false,
CookieSameSite::NO_RESTRICTION, CookiePriority::COOKIE_PRIORITY_DEFAULT,
CookiePartitionKey::FromURLForTesting(GURL("https://toplevelsite.com"))));
list.push_back(*CanonicalCookie::CreateUnsafeCookieForTesting(
"expired", "foobar", https_www_foo_.url().GetHost(), "/",
base::Time::Now() - base::Days(1), base::Time::Now() - base::Days(2),
base::Time(), base::Time(), true, false,
CookieSameSite::NO_RESTRICTION, CookiePriority::COOKIE_PRIORITY_DEFAULT));
ASSERT_EQ(0, store->flush_count());
EXPECT_TRUE(SetAllCookies(cm.get(), list));
EXPECT_EQ(0, store->flush_count());
CookieList cookies = GetAllCookies(cm.get());
size_t expected_size = 4;
EXPECT_EQ(expected_size, cookies.size());
auto it = cookies.begin();
ASSERT_TRUE(it != cookies.end());
EXPECT_EQ("C", it->Name());
EXPECT_EQ("D", it->Value());
EXPECT_EQ("/bar", it->Path());
ASSERT_TRUE(++it != cookies.end());
EXPECT_EQ("A", it->Name());
EXPECT_EQ("B", it->Value());
ASSERT_TRUE(++it != cookies.end());
EXPECT_EQ("W", it->Name());
EXPECT_EQ("X", it->Value());
ASSERT_TRUE(++it != cookies.end());
EXPECT_EQ("__Host-Y", it->Name());
EXPECT_EQ("Z", it->Value());
cm = nullptr;
auto entries = net_log_.GetEntries();
size_t pos = ExpectLogContainsSomewhere(
entries, 0, NetLogEventType::COOKIE_STORE_ALIVE, NetLogEventPhase::BEGIN);
pos = ExpectLogContainsSomewhere(
entries, pos, NetLogEventType::COOKIE_STORE_SESSION_PERSISTENCE,
NetLogEventPhase::NONE);
pos = ExpectLogContainsSomewhere(entries, pos,
NetLogEventType::COOKIE_STORE_COOKIE_ADDED,
NetLogEventPhase::NONE);
ExpectLogContainsSomewhere(entries, pos, NetLogEventType::COOKIE_STORE_ALIVE,
NetLogEventPhase::END);
}
TEST_F(CookieMonsterTest, DeleteAll) {
auto store = base::MakeRefCounted<FlushablePersistentStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
cm->SetPersistSessionCookies(true);
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), "X=Y; path=/"));
ASSERT_EQ(0, store->flush_count());
EXPECT_EQ(1u, DeleteAll(cm.get()));
EXPECT_EQ(1, store->flush_count());
cm = nullptr;
auto entries = net_log_.GetEntries();
size_t pos = ExpectLogContainsSomewhere(
entries, 0, NetLogEventType::COOKIE_STORE_ALIVE, NetLogEventPhase::BEGIN);
pos = ExpectLogContainsSomewhere(
entries, pos, NetLogEventType::COOKIE_STORE_SESSION_PERSISTENCE,
NetLogEventPhase::NONE);
pos = ExpectLogContainsSomewhere(entries, pos,
NetLogEventType::COOKIE_STORE_COOKIE_ADDED,
NetLogEventPhase::NONE);
pos = ExpectLogContainsSomewhere(entries, pos,
NetLogEventType::COOKIE_STORE_COOKIE_DELETED,
NetLogEventPhase::NONE);
ExpectLogContainsSomewhere(entries, pos, NetLogEventType::COOKIE_STORE_ALIVE,
NetLogEventPhase::END);
}
TEST_F(CookieMonsterTest, HistogramCheck) {
base::MetricsSubSampler::ScopedAlwaysSampleForTesting always_sample;
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
base::HistogramBase* expired_histogram = base::Histogram::FactoryGet(
"Cookie.ExpirationDurationMinutesSecure.Subsampled2", 1, 400 * 24 * 60,
100, base::Histogram::kUmaTargetedHistogramFlag);
base::HistogramBase* persistance_histogram =
base::BooleanHistogram::FactoryGet(
"Cookie.IsPersistentWhenSet.Subsampled",
base::HistogramBase::kUmaTargetedHistogramFlag);
std::unique_ptr<base::HistogramSamples> expired_samples1(
expired_histogram->SnapshotSamples());
std::unique_ptr<base::HistogramSamples> persistance_samples1(
persistance_histogram->SnapshotSamples());
auto cookie = CanonicalCookie::CreateUnsafeCookieForTesting(
"a", "b", "a.url", "/", base::Time(),
base::Time::Now() + base::Minutes(59), base::Time(), base::Time(),
true,
false, CookieSameSite::NO_RESTRICTION,
COOKIE_PRIORITY_DEFAULT);
GURL source_url = cookie_util::SimulatedCookieSource(*cookie, "https");
ASSERT_TRUE(SetCanonicalCookie(cm.get(), std::move(cookie), source_url,
true));
std::unique_ptr<base::HistogramSamples> expired_samples2(
expired_histogram->SnapshotSamples());
std::unique_ptr<base::HistogramSamples> persistance_samples2(
persistance_histogram->SnapshotSamples());
EXPECT_EQ(expired_samples1->TotalCount() + 1, expired_samples2->TotalCount());
EXPECT_EQ(persistance_samples1->TotalCount() + 1,
persistance_samples2->TotalCount());
EXPECT_EQ(1, persistance_samples2->sum());
ASSERT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), kValidCookieLine));
std::unique_ptr<base::HistogramSamples> expired_samples3(
expired_histogram->SnapshotSamples());
std::unique_ptr<base::HistogramSamples> persistance_samples3(
persistance_histogram->SnapshotSamples());
EXPECT_EQ(expired_samples2->TotalCount(), expired_samples3->TotalCount());
EXPECT_EQ(persistance_samples2->TotalCount() + 1,
persistance_samples3->TotalCount());
EXPECT_EQ(1, persistance_samples3->sum());
}
TEST_F(CookieMonsterTest, InvalidExpiryTime) {
std::string cookie_line =
std::string(kValidCookieLine) + "; expires=Blarg arg arg";
std::unique_ptr<CanonicalCookie> cookie(CanonicalCookie::CreateForTesting(
http_www_foo_.url(), cookie_line, Time::Now()));
ASSERT_FALSE(cookie->IsPersistent());
}
TEST_F(CookieMonsterTest, PersistSessionCookies) {
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
cm->SetPersistSessionCookies(true);
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), "A=B"));
EXPECT_EQ("A=B", GetCookies(cm.get(), http_www_foo_.url()));
EXPECT_EQ(1u, store->commands().size());
EXPECT_EQ(CookieStoreCommand::ADD, store->commands()[0].type);
EXPECT_EQ("A", store->commands()[0].cookie.Name());
EXPECT_EQ("B", store->commands()[0].cookie.Value());
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), "A=C"));
EXPECT_EQ("A=C", GetCookies(cm.get(), http_www_foo_.url()));
EXPECT_EQ(3u, store->commands().size());
EXPECT_EQ(CookieStoreCommand::REMOVE, store->commands()[1].type);
EXPECT_EQ("A", store->commands()[1].cookie.Name());
EXPECT_EQ("B", store->commands()[1].cookie.Value());
EXPECT_EQ(CookieStoreCommand::ADD, store->commands()[2].type);
EXPECT_EQ("A", store->commands()[2].cookie.Name());
EXPECT_EQ("C", store->commands()[2].cookie.Value());
EXPECT_TRUE(FindAndDeleteCookie(cm.get(), http_www_foo_.host(), "A"));
EXPECT_EQ("", GetCookies(cm.get(), http_www_foo_.url()));
ASSERT_EQ(4u, store->commands().size());
EXPECT_EQ(CookieStoreCommand::REMOVE, store->commands()[3].type);
EXPECT_EQ("A", store->commands()[3].cookie.Name());
EXPECT_EQ("C", store->commands()[3].cookie.Value());
}
TEST_F(CookieMonsterTest, PersisentCookieStorageTest) {
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(),
"A=B" + FutureCookieExpirationString()));
this->MatchCookieLines("A=B", GetCookies(cm.get(), http_www_foo_.url()));
ASSERT_EQ(1u, store->commands().size());
EXPECT_EQ(CookieStoreCommand::ADD, store->commands()[0].type);
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), "A=B; max-age=0"));
this->MatchCookieLines(std::string(),
GetCookies(cm.get(), http_www_foo_.url()));
ASSERT_EQ(2u, store->commands().size());
EXPECT_EQ(CookieStoreCommand::REMOVE, store->commands()[1].type);
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(),
"A=B" + FutureCookieExpirationString()));
this->MatchCookieLines("A=B", GetCookies(cm.get(), http_www_foo_.url()));
ASSERT_EQ(3u, store->commands().size());
EXPECT_EQ(CookieStoreCommand::ADD, store->commands()[2].type);
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(),
"A=Foo" + FutureCookieExpirationString()));
this->MatchCookieLines("A=Foo", GetCookies(cm.get(), http_www_foo_.url()));
ASSERT_EQ(5u, store->commands().size());
EXPECT_EQ(CookieStoreCommand::REMOVE, store->commands()[3].type);
EXPECT_EQ(CookieStoreCommand::ADD, store->commands()[4].type);
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), "B=Bar"));
this->MatchCookieLines("A=Foo; B=Bar",
GetCookies(cm.get(), http_www_foo_.url()));
EXPECT_EQ(5u, store->commands().size());
}
TEST_F(CookieMonsterTest, ControlCharacterPurge) {
const Time now1(Time::Now());
const Time now2(Time::Now() + base::Seconds(1));
const Time now3(Time::Now() + base::Seconds(2));
const Time now4(Time::Now() + base::Seconds(3));
const Time later(now1 + base::Days(1));
const GURL url("https://host/path");
const std::string domain("host");
const std::string path("/path");
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
std::vector<std::unique_ptr<CanonicalCookie>> initial_cookies;
AddCookieToList(url, "foo=bar; path=" + path, now1, &initial_cookies);
std::unique_ptr<CanonicalCookie> cc =
CanonicalCookie::CreateUnsafeCookieForTesting(
"baz",
"\x05"
"boo",
"." + domain, path, now2, later, base::Time(), base::Time(),
true , false ,
CookieSameSite::NO_RESTRICTION, COOKIE_PRIORITY_DEFAULT);
initial_cookies.push_back(std::move(cc));
std::unique_ptr<CanonicalCookie> cc2 =
CanonicalCookie::CreateUnsafeCookieForTesting(
"baz",
"\x7F"
"boo",
"." + domain, path, now3, later, base::Time(), base::Time(),
true , false ,
CookieSameSite::NO_RESTRICTION, COOKIE_PRIORITY_DEFAULT);
initial_cookies.push_back(std::move(cc2));
auto cookie_partition_key =
CookiePartitionKey::FromURLForTesting(GURL("https://toplevelsite.com"));
std::unique_ptr<CanonicalCookie> cc3 =
CanonicalCookie::CreateUnsafeCookieForTesting(
"__Host-baz",
"\x7F"
"boo",
domain, "/", now3, later, base::Time(), base::Time(),
true , false ,
CookieSameSite::NO_RESTRICTION, COOKIE_PRIORITY_DEFAULT,
cookie_partition_key);
initial_cookies.push_back(std::move(cc3));
AddCookieToList(url, "hello=world; path=" + path, now4, &initial_cookies);
store->SetLoadExpectation(true, std::move(initial_cookies));
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
EXPECT_EQ("foo=bar; hello=world",
GetCookies(cm.get(), url,
CookiePartitionKeyCollection(cookie_partition_key)));
}
TEST_F(CookieMonsterTest, NumKeysHistogram) {
const char kHistogramName[] = "Cookie.NumKeys";
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
std::vector<std::unique_ptr<CanonicalCookie>> initial_cookies;
initial_cookies.push_back(CanonicalCookie::CreateForTesting(
GURL("http://domain1.test"), "A=1", base::Time::Now()));
initial_cookies.push_back(CanonicalCookie::CreateForTesting(
GURL("http://domain2.test"), "A=1", base::Time::Now()));
initial_cookies.push_back(CanonicalCookie::CreateForTesting(
GURL("http://sub.domain2.test"), "A=1", base::Time::Now()));
initial_cookies.push_back(CanonicalCookie::CreateForTesting(
GURL("http://domain3.test"), "A=1", base::Time::Now()));
initial_cookies.push_back(CanonicalCookie::CreateForTesting(
GURL("http://domain3.test"), "B=1", base::Time::Now()));
store->SetLoadExpectation(true ,
std::move(initial_cookies));
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
{
base::HistogramTester histogram_tester;
EXPECT_EQ(5u, this->GetAllCookies(cm.get()).size());
EXPECT_TRUE(cm->DoRecordPeriodicStatsForTesting());
histogram_tester.ExpectUniqueSample(kHistogramName, 3 ,
1 );
}
{
base::HistogramTester histogram_tester;
EXPECT_TRUE(CreateAndSetCookie(cm.get(), GURL("https://domain1.test"),
"B=1", CookieOptions::MakeAllInclusive()));
EXPECT_TRUE(CreateAndSetCookie(cm.get(), GURL("http://sub.domain1.test"),
"B=1", CookieOptions::MakeAllInclusive()));
EXPECT_TRUE(cm->DoRecordPeriodicStatsForTesting());
histogram_tester.ExpectUniqueSample(kHistogramName, 3 ,
1 );
}
{
base::HistogramTester histogram_tester;
EXPECT_TRUE(CreateAndSetCookie(cm.get(), GURL("https://domain4.test"),
"A=1", CookieOptions::MakeAllInclusive()));
EXPECT_TRUE(cm->DoRecordPeriodicStatsForTesting());
histogram_tester.ExpectUniqueSample(kHistogramName, 4 ,
1 );
}
{
base::HistogramTester histogram_tester;
EXPECT_TRUE(CreateAndSetCookie(cm.get(), GURL("https://domain4.test"),
"A=2", CookieOptions::MakeAllInclusive()));
EXPECT_TRUE(cm->DoRecordPeriodicStatsForTesting());
histogram_tester.ExpectUniqueSample(kHistogramName, 4 ,
1 );
}
{
base::HistogramTester histogram_tester;
EXPECT_TRUE(CreateAndSetCookie(cm.get(), GURL("https://domain2.test"),
"A=1; Max-Age=0",
CookieOptions::MakeAllInclusive()));
EXPECT_TRUE(cm->DoRecordPeriodicStatsForTesting());
histogram_tester.ExpectUniqueSample(kHistogramName, 4 ,
1 );
}
{
base::HistogramTester histogram_tester;
EXPECT_TRUE(CreateAndSetCookie(cm.get(), GURL("https://domain4.test"),
"A=1; Max-Age=0",
CookieOptions::MakeAllInclusive()));
EXPECT_TRUE(cm->DoRecordPeriodicStatsForTesting());
histogram_tester.ExpectUniqueSample(kHistogramName, 3 ,
1 );
}
}
TEST_F(CookieMonsterTest, CookieCount2Histogram) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
{
base::HistogramTester histogram_tester;
ASSERT_TRUE(cm->DoRecordPeriodicStatsForTesting());
histogram_tester.ExpectUniqueSample("Cookie.Count2",
0,
1);
}
{
base::HistogramTester histogram_tester;
auto cookie = CanonicalCookie::CreateUnsafeCookieForTesting(
"a", "b", "a.url", "/", base::Time(),
base::Time::Now() + base::Minutes(59), base::Time(), base::Time(),
true,
false, CookieSameSite::NO_RESTRICTION,
COOKIE_PRIORITY_DEFAULT);
GURL source_url = cookie_util::SimulatedCookieSource(*cookie, "https");
ASSERT_TRUE(SetCanonicalCookie(cm.get(), std::move(cookie), source_url,
true));
ASSERT_TRUE(cm->DoRecordPeriodicStatsForTesting());
histogram_tester.ExpectUniqueSample("Cookie.Count2", 1,
1);
}
}
TEST_F(CookieMonsterTest, CookieJarSizeHistograms) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
{
base::HistogramTester histogram_tester;
ASSERT_TRUE(cm->DoRecordPeriodicStatsForTesting());
histogram_tester.ExpectUniqueSample("Cookie.CookieJarSize",
0,
1);
histogram_tester.ExpectUniqueSample("Cookie.AvgCookieJarSizePerKey2",
0,
1);
histogram_tester.ExpectUniqueSample("Cookie.MaxCookieJarSizePerKey",
0,
1);
}
auto set_cookie =
[&](const std::string& name, int cookie_value_size_kb,
const std::string& domain, CookieSameSite same_site,
const std::optional<CookiePartitionKey>& partition_key) {
auto cc = CanonicalCookie::CreateUnsafeCookieForTesting(
name, std::string(cookie_value_size_kb * 1024, '0'), domain, "/",
base::Time(), base::Time::Now() + base::Minutes(59), base::Time(),
base::Time(),
true,
false, same_site, COOKIE_PRIORITY_DEFAULT,
partition_key);
GURL source_url = cookie_util::SimulatedCookieSource(*cc, "https");
ASSERT_TRUE(SetCanonicalCookie(cm.get(), std::move(cc), source_url,
true));
};
{
base::HistogramTester histogram_tester;
set_cookie("a", 2, "a.url", CookieSameSite::NO_RESTRICTION, std::nullopt);
ASSERT_TRUE(cm->DoRecordPeriodicStatsForTesting());
histogram_tester.ExpectUniqueSample("Cookie.CookieJarSize",
2,
1);
histogram_tester.ExpectUniqueSample("Cookie.AvgCookieJarSizePerKey2",
2049,
1);
histogram_tester.ExpectUniqueSample("Cookie.MaxCookieJarSizePerKey",
2,
1);
}
{
base::HistogramTester histogram_tester;
set_cookie("b", 3, "a.url", CookieSameSite::NO_RESTRICTION,
CookiePartitionKey::FromURLForTesting(
GURL("https://toplevelsite.com")));
ASSERT_TRUE(cm->DoRecordPeriodicStatsForTesting());
histogram_tester.ExpectUniqueSample("Cookie.CookieJarSize",
2,
1);
histogram_tester.ExpectUniqueSample("Cookie.AvgCookieJarSizePerKey2",
2049,
1);
histogram_tester.ExpectUniqueSample("Cookie.MaxCookieJarSizePerKey",
2,
1);
}
{
base::HistogramTester histogram_tester;
set_cookie("c", 4, "c.url", CookieSameSite::LAX_MODE, std::nullopt);
ASSERT_TRUE(cm->DoRecordPeriodicStatsForTesting());
histogram_tester.ExpectUniqueSample("Cookie.CookieJarSize",
6,
1);
histogram_tester.ExpectUniqueSample("Cookie.AvgCookieJarSizePerKey2",
3073,
1);
histogram_tester.ExpectUniqueSample("Cookie.MaxCookieJarSizePerKey",
4,
1);
}
}
TEST_F(CookieMonsterTest, PartitionedCookieHistograms) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
{
base::HistogramTester histogram_tester;
ASSERT_TRUE(cm->DoRecordPeriodicStatsForTesting());
histogram_tester.ExpectUniqueSample("Cookie.PartitionedCookieCount",
0,
1);
histogram_tester.ExpectUniqueSample("Cookie.PartitionedCookieCount.Nonced",
0,
1);
histogram_tester.ExpectUniqueSample(
"Cookie.PartitionedCookieCount.Unnonced", 0,
1);
histogram_tester.ExpectUniqueSample(
"Cookie.PartitionedCookieJarSizeKibibytes",
0,
1);
histogram_tester.ExpectUniqueSample(
"Cookie.PartitionedCookieJarSizeKibibytes.Nonced", 0,
1);
histogram_tester.ExpectUniqueSample(
"Cookie.PartitionedCookieJarSizeKibibytes.Unnonced", 0,
1);
histogram_tester.ExpectUniqueSample("Cookie.CookiePartitionSizeKibibytes",
0,
0);
}
{
base::HistogramTester histogram_tester;
auto cookie = CanonicalCookie::CreateUnsafeCookieForTesting(
"a", "b", "a.url", "/", base::Time(),
base::Time::Now() + base::Minutes(59), base::Time(), base::Time(),
true,
false, CookieSameSite::NO_RESTRICTION,
COOKIE_PRIORITY_DEFAULT);
GURL source_url = cookie_util::SimulatedCookieSource(*cookie, "https");
ASSERT_TRUE(SetCanonicalCookie(cm.get(), std::move(cookie), source_url,
true));
ASSERT_TRUE(cm->DoRecordPeriodicStatsForTesting());
histogram_tester.ExpectUniqueSample("Cookie.PartitionedCookieCount",
0,
1);
histogram_tester.ExpectUniqueSample("Cookie.PartitionedCookieCount.Nonced",
0,
1);
histogram_tester.ExpectUniqueSample(
"Cookie.PartitionedCookieCount.Unnonced", 0,
1);
histogram_tester.ExpectUniqueSample("Cookie.Count2", 1,
1);
histogram_tester.ExpectUniqueSample(
"Cookie.PartitionedCookieJarSizeKibibytes",
0,
1);
histogram_tester.ExpectUniqueSample(
"Cookie.PartitionedCookieJarSizeKibibytes.Nonced", 0,
1);
histogram_tester.ExpectUniqueSample(
"Cookie.PartitionedCookieJarSizeKibibytes.Unnonced", 0,
1);
histogram_tester.ExpectUniqueSample("Cookie.CookiePartitionSizeKibibytes",
0,
0);
}
{
base::HistogramTester histogram_tester;
auto cookie = CanonicalCookie::CreateUnsafeCookieForTesting(
"a", std::string(2 * 1024, '0'), "a.url", "/", base::Time(),
base::Time::Now() + base::Minutes(59), base::Time(), base::Time(),
true,
false, CookieSameSite::NO_RESTRICTION,
COOKIE_PRIORITY_DEFAULT,
CookiePartitionKey::FromURLForTesting(GURL("https://example.com")));
GURL source_url = cookie_util::SimulatedCookieSource(*cookie, "https");
ASSERT_TRUE(SetCanonicalCookie(cm.get(), std::move(cookie), source_url,
true));
ASSERT_TRUE(cm->DoRecordPeriodicStatsForTesting());
histogram_tester.ExpectUniqueSample("Cookie.PartitionedCookieCount",
1,
1);
histogram_tester.ExpectUniqueSample("Cookie.PartitionedCookieCount.Nonced",
0,
1);
histogram_tester.ExpectUniqueSample(
"Cookie.PartitionedCookieCount.Unnonced", 1,
1);
histogram_tester.ExpectUniqueSample("Cookie.Count2", 1,
1);
histogram_tester.ExpectUniqueSample(
"Cookie.PartitionedCookieJarSizeKibibytes",
2,
1);
histogram_tester.ExpectUniqueSample(
"Cookie.PartitionedCookieJarSizeKibibytes.Nonced", 0,
1);
histogram_tester.ExpectUniqueSample(
"Cookie.PartitionedCookieJarSizeKibibytes.Unnonced", 2,
1);
histogram_tester.ExpectUniqueSample("Cookie.CookiePartitionSizeKibibytes",
2,
1);
}
{
base::HistogramTester histogram_tester;
auto cookie = CanonicalCookie::CreateUnsafeCookieForTesting(
"a", std::string(3 * 1024, '0'), "a.url", "/", base::Time(),
base::Time::Now() + base::Minutes(59), base::Time(), base::Time(),
true,
false, CookieSameSite::NO_RESTRICTION,
COOKIE_PRIORITY_DEFAULT,
CookiePartitionKey::FromURLForTesting(
GURL("https://example.com"),
CookiePartitionKey::AncestorChainBit::kCrossSite,
base::UnguessableToken::Create()));
GURL source_url = cookie_util::SimulatedCookieSource(*cookie, "https");
ASSERT_TRUE(SetCanonicalCookie(cm.get(), std::move(cookie), source_url,
true));
ASSERT_TRUE(cm->DoRecordPeriodicStatsForTesting());
histogram_tester.ExpectUniqueSample("Cookie.PartitionedCookieCount",
2,
1);
histogram_tester.ExpectUniqueSample("Cookie.PartitionedCookieCount.Nonced",
1,
1);
histogram_tester.ExpectUniqueSample(
"Cookie.PartitionedCookieCount.Unnonced", 1,
1);
histogram_tester.ExpectUniqueSample("Cookie.Count2", 1,
1);
histogram_tester.ExpectUniqueSample(
"Cookie.PartitionedCookieJarSizeKibibytes",
5,
1);
histogram_tester.ExpectUniqueSample(
"Cookie.PartitionedCookieJarSizeKibibytes.Nonced", 3,
1);
histogram_tester.ExpectUniqueSample(
"Cookie.PartitionedCookieJarSizeKibibytes.Unnonced", 2,
1);
histogram_tester.ExpectBucketCount("Cookie.CookiePartitionSizeKibibytes",
2,
1);
histogram_tester.ExpectBucketCount("Cookie.CookiePartitionSizeKibibytes",
3,
1);
}
}
TEST_F(CookieMonsterTest, MaxSameSiteNoneCookiesPerKey) {
const char kHistogramName[] = "Cookie.MaxSameSiteNoneCookiesPerKey";
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
ASSERT_EQ(0u, GetAllCookies(cm.get()).size());
{
base::HistogramTester histogram_tester;
ASSERT_TRUE(CreateAndSetCookie(cm.get(), GURL("https://domain1.test"),
"A=1;SameSite=Lax",
CookieOptions::MakeAllInclusive()));
ASSERT_EQ(1u, GetAllCookies(cm.get()).size());
ASSERT_TRUE(cm->DoRecordPeriodicStatsForTesting());
histogram_tester.ExpectUniqueSample(kHistogramName, 0 ,
1 );
}
{
base::HistogramTester histogram_tester;
ASSERT_TRUE(CreateAndSetCookie(cm.get(), GURL("https://domain1.test"),
"B=2;SameSite=None;Secure",
CookieOptions::MakeAllInclusive()));
ASSERT_EQ(2u, GetAllCookies(cm.get()).size());
ASSERT_TRUE(cm->DoRecordPeriodicStatsForTesting());
histogram_tester.ExpectUniqueSample(kHistogramName, 1 ,
1 );
}
{
base::HistogramTester histogram_tester;
ASSERT_TRUE(CreateAndSetCookie(cm.get(), GURL("https://domain2.test"),
"A=1;SameSite=None;Secure",
CookieOptions::MakeAllInclusive()));
ASSERT_TRUE(CreateAndSetCookie(cm.get(), GURL("https://domain2.test"),
"B=2;SameSite=None;Secure",
CookieOptions::MakeAllInclusive()));
ASSERT_TRUE(CreateAndSetCookie(cm.get(), GURL("https://domain3.test"),
"A=1;SameSite=None;Secure",
CookieOptions::MakeAllInclusive()));
ASSERT_EQ(5u, GetAllCookies(cm.get()).size());
ASSERT_TRUE(cm->DoRecordPeriodicStatsForTesting());
histogram_tester.ExpectUniqueSample(kHistogramName, 2 ,
1 );
}
}
TEST_F(CookieMonsterTest, SecureCookieLocalhost) {
auto cm = std::make_unique<CookieMonster>(nullptr, nullptr);
GURL insecure_localhost("http://localhost");
GURL secure_localhost("https://localhost");
{
auto cookie = CanonicalCookie::CreateForTesting(
insecure_localhost, "from_insecure_localhost=1; Secure",
base::Time::Now());
ASSERT_TRUE(cookie);
CookieInclusionStatus status =
SetCanonicalCookieReturnAccessResult(cm.get(), std::move(cookie),
insecure_localhost,
true )
.status;
EXPECT_TRUE(status.IsInclude());
EXPECT_TRUE(status.HasExactlyWarningReasonsForTesting(
{CookieInclusionStatus::WarningReason::
WARN_SECURE_ACCESS_GRANTED_NON_CRYPTOGRAPHIC}));
}
{
auto cookie = CanonicalCookie::CreateForTesting(
secure_localhost, "from_secure_localhost=1; Secure", base::Time::Now());
ASSERT_TRUE(cookie);
CookieInclusionStatus status =
SetCanonicalCookieReturnAccessResult(cm.get(), std::move(cookie),
secure_localhost,
true )
.status;
EXPECT_EQ(CookieInclusionStatus(), status);
}
{
GetCookieListCallback callback;
cm->GetCookieListWithOptionsAsync(
insecure_localhost, CookieOptions::MakeAllInclusive(),
CookiePartitionKeyCollection(), callback.MakeCallback());
callback.WaitUntilDone();
EXPECT_EQ(2u, callback.cookies_with_access_results().size());
for (const auto& cookie_item : callback.cookies_with_access_results()) {
EXPECT_TRUE(cookie_item.cookie.SecureAttribute());
EXPECT_TRUE(cookie_item.access_result.status.IsInclude());
EXPECT_TRUE(
cookie_item.access_result.status.HasExactlyWarningReasonsForTesting(
{CookieInclusionStatus::WarningReason::
WARN_SECURE_ACCESS_GRANTED_NON_CRYPTOGRAPHIC}));
}
}
{
GetCookieListCallback callback;
cm->GetCookieListWithOptionsAsync(
secure_localhost, CookieOptions::MakeAllInclusive(),
CookiePartitionKeyCollection(), callback.MakeCallback());
callback.WaitUntilDone();
EXPECT_EQ(2u, callback.cookies_with_access_results().size());
for (const auto& cookie_item : callback.cookies_with_access_results()) {
EXPECT_TRUE(cookie_item.cookie.SecureAttribute());
EXPECT_EQ(CookieInclusionStatus(), cookie_item.access_result.status);
}
}
}
TEST_F(CookieMonsterTest, MaybeDeleteEquivalentCookieAndUpdateStatus) {
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
auto preexisting_cookie = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "A=B;Secure;HttpOnly", base::Time::Now());
CookieAccessResult access_result = SetCanonicalCookieReturnAccessResult(
cm.get(), std::move(preexisting_cookie), https_www_foo_.url(),
true );
ASSERT_TRUE(access_result.status.IsInclude());
EXPECT_TRUE(SetCookie(cm.get(), https_www_foo_.url(), "B=A;"));
EXPECT_TRUE(SetCookie(cm.get(), http_www_foo_.url(), "C=A;"));
auto bad_cookie = CanonicalCookie::CreateForTesting(http_www_foo_.url(),
"A=D", base::Time::Now());
access_result = SetCanonicalCookieReturnAccessResult(
cm.get(), std::move(bad_cookie), http_www_foo_.url(),
true );
EXPECT_TRUE(access_result.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_OVERWRITE_SECURE}));
EXPECT_THAT(GetCookiesWithOptions(cm.get(), https_www_foo_.url(),
CookieOptions::MakeAllInclusive()),
::testing::HasSubstr("A=B"));
auto entries = net_log_.GetEntries();
size_t skipped_secure_netlog_index = ExpectLogContainsSomewhere(
entries, 0, NetLogEventType::COOKIE_STORE_COOKIE_REJECTED_SECURE,
NetLogEventPhase::NONE);
EXPECT_FALSE(LogContainsEntryWithTypeAfter(
entries, 0, NetLogEventType::COOKIE_STORE_COOKIE_REJECTED_HTTPONLY));
ExpectLogContainsSomewhereAfter(
entries, skipped_secure_netlog_index,
NetLogEventType::COOKIE_STORE_COOKIE_PRESERVED_SKIPPED_SECURE,
NetLogEventPhase::NONE);
net_log_.Clear();
bad_cookie = CanonicalCookie::CreateForTesting(
http_www_foo_.url(), "A=E; path=/some/path", base::Time::Now());
access_result = SetCanonicalCookieReturnAccessResult(
cm.get(), std::move(bad_cookie), http_www_foo_.url(),
true );
EXPECT_TRUE(access_result.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_OVERWRITE_SECURE}));
EXPECT_THAT(GetCookiesWithOptions(cm.get(), https_www_foo_.url(),
CookieOptions::MakeAllInclusive()),
::testing::HasSubstr("A=B"));
entries = net_log_.GetEntries();
skipped_secure_netlog_index = ExpectLogContainsSomewhere(
entries, 0, NetLogEventType::COOKIE_STORE_COOKIE_REJECTED_SECURE,
NetLogEventPhase::NONE);
EXPECT_FALSE(LogContainsEntryWithTypeAfter(
entries, 0, NetLogEventType::COOKIE_STORE_COOKIE_REJECTED_HTTPONLY));
EXPECT_FALSE(LogContainsEntryWithTypeAfter(
entries, skipped_secure_netlog_index,
NetLogEventType::COOKIE_STORE_COOKIE_PRESERVED_SKIPPED_SECURE));
net_log_.Clear();
bad_cookie = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "A=E; Secure", base::Time::Now());
access_result = SetCanonicalCookieReturnAccessResult(
cm.get(), std::move(bad_cookie), https_www_foo_.url(),
false );
EXPECT_TRUE(access_result.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_OVERWRITE_HTTP_ONLY}));
entries = net_log_.GetEntries();
ExpectLogContainsSomewhere(
entries, 0, NetLogEventType::COOKIE_STORE_COOKIE_REJECTED_HTTPONLY,
NetLogEventPhase::NONE);
EXPECT_FALSE(LogContainsEntryWithTypeAfter(
entries, 0, NetLogEventType::COOKIE_STORE_COOKIE_REJECTED_SECURE));
}
TEST_F(CookieMonsterTest,
MaybeDeleteEquivalentCookieAndUpdateStatus_PartitionedCookies) {
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
auto cookie_partition_key1 =
CookiePartitionKey::FromURLForTesting(GURL("https://toplevelsite1.com"));
auto preexisting_cookie = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "__Host-A=B; Secure; Path=/; Partitioned; HttpOnly",
base::Time::Now(), std::nullopt ,
cookie_partition_key1 );
CookieAccessResult access_result = SetCanonicalCookieReturnAccessResult(
cm.get(), std::move(preexisting_cookie), https_www_foo_.url(),
true );
ASSERT_TRUE(access_result.status.IsInclude());
EXPECT_TRUE(SetCookie(cm.get(), https_www_foo_.url(),
"__Host-A=C; Secure; Path=/; Partitioned",
CookiePartitionKey::FromURLForTesting(
GURL("https://toplevelsite2.com"))));
auto bad_cookie = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "__Host-A=D; Secure; Path=/; Partitioned",
base::Time::Now(), std::nullopt , cookie_partition_key1);
access_result = SetCanonicalCookieReturnAccessResult(
cm.get(), std::move(bad_cookie), https_www_foo_.url(),
false );
EXPECT_TRUE(access_result.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_OVERWRITE_HTTP_ONLY}));
EXPECT_THAT(
GetCookiesWithOptions(
cm.get(), https_www_foo_.url(), CookieOptions::MakeAllInclusive(),
CookiePartitionKeyCollection(cookie_partition_key1)),
::testing::HasSubstr("A=B"));
}
class CookieMonsterTest_MaybeDeleteEquivalentCookieAndUpdateStatus
: public CookieMonsterTest {
public:
void InitializeTest() {
store_ = base::MakeRefCounted<MockPersistentCookieStore>();
cm_ = std::make_unique<CookieMonster>(store_.get(), net::NetLog::Get());
auto preexisting_cookie_https = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "A=PreexistingHttps443", base::Time::Now());
CookieAccessResult access_result = SetCanonicalCookieReturnAccessResult(
cm_.get(), std::move(preexisting_cookie_https), https_www_foo_.url(),
true);
ASSERT_TRUE(access_result.status.IsInclude());
auto preexisting_domain_cookie_https = CanonicalCookie::CreateForTesting(
https_www_foo_.url(),
"A=PreexistingDomainHttps443; Domain=" + https_www_foo_.domain(),
base::Time::Now());
access_result = SetCanonicalCookieReturnAccessResult(
cm_.get(), std::move(preexisting_domain_cookie_https),
https_www_foo_.url(),
true);
ASSERT_TRUE(access_result.status.IsInclude());
ASSERT_EQ(GetAllCookies(cm_.get()).size(), 2UL);
}
void AddHttpPort443Cookie() {
GURL::Replacements replace_scheme;
replace_scheme.SetSchemeStr("http");
replace_scheme.SetPortStr("443");
GURL foo_made_http = https_www_foo_.url().ReplaceComponents(replace_scheme);
auto differ_by_scheme_only = CanonicalCookie::CreateForTesting(
foo_made_http, "A=InsertedHttp443", base::Time::Now());
CookieAccessResult access_result = SetCanonicalCookieReturnAccessResult(
cm_.get(), std::move(differ_by_scheme_only), foo_made_http,
true);
ASSERT_TRUE(access_result.status.IsInclude());
}
void AddHttpsPort80Cookie() {
GURL::Replacements replace_port;
replace_port.SetPortStr("80");
GURL foo_made_80 = https_www_foo_.url().ReplaceComponents(replace_port);
auto differ_by_port_only = CanonicalCookie::CreateForTesting(
foo_made_80, "A=InsertedHttps80", base::Time::Now());
CookieAccessResult access_result = SetCanonicalCookieReturnAccessResult(
cm_.get(), std::move(differ_by_port_only), foo_made_80,
true);
ASSERT_TRUE(access_result.status.IsInclude());
}
void AddDomainHttpsPort80Cookie() {
GURL::Replacements replace_port;
replace_port.SetPortStr("80");
GURL foo_made_80 = https_www_foo_.url().ReplaceComponents(replace_port);
auto differ_by_port_only = CanonicalCookie::CreateForTesting(
foo_made_80,
"A=InsertedDomainHttps80; Domain=" + https_www_foo_.domain(),
base::Time::Now());
CookieAccessResult access_result = SetCanonicalCookieReturnAccessResult(
cm_.get(), std::move(differ_by_port_only), foo_made_80,
true);
ASSERT_TRUE(access_result.status.IsInclude());
}
scoped_refptr<net::MockPersistentCookieStore> store_;
std::unique_ptr<CookieMonster> cm_;
base::test::ScopedFeatureList scoped_feature_list_;
};
TEST_F(CookieMonsterTest_MaybeDeleteEquivalentCookieAndUpdateStatus,
NoSchemeNoPort) {
scoped_feature_list_.InitWithFeatures(
{}, {net::features::kEnableSchemeBoundCookies,
net::features::kEnablePortBoundCookies});
InitializeTest();
AddHttpPort443Cookie();
auto cookies = GetAllCookies(cm_.get());
EXPECT_THAT(cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "InsertedHttp443"),
MatchesCookieNameValue("A", "PreexistingDomainHttps443")));
AddHttpsPort80Cookie();
cookies = GetAllCookies(cm_.get());
EXPECT_THAT(cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "InsertedHttps80"),
MatchesCookieNameValue("A", "PreexistingDomainHttps443")));
AddDomainHttpsPort80Cookie();
cookies = GetAllCookies(cm_.get());
EXPECT_THAT(cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "InsertedHttps80"),
MatchesCookieNameValue("A", "InsertedDomainHttps80")));
}
TEST_F(CookieMonsterTest_MaybeDeleteEquivalentCookieAndUpdateStatus,
YesSchemeNoPort) {
scoped_feature_list_.InitWithFeatures(
{net::features::kEnableSchemeBoundCookies},
{net::features::kEnablePortBoundCookies});
InitializeTest();
AddHttpPort443Cookie();
auto cookies = GetAllCookies(cm_.get());
EXPECT_THAT(cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "PreexistingHttps443"),
MatchesCookieNameValue("A", "InsertedHttp443"),
MatchesCookieNameValue("A", "PreexistingDomainHttps443")));
AddHttpsPort80Cookie();
cookies = GetAllCookies(cm_.get());
EXPECT_THAT(cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "InsertedHttp443"),
MatchesCookieNameValue("A", "InsertedHttps80"),
MatchesCookieNameValue("A", "PreexistingDomainHttps443")));
AddDomainHttpsPort80Cookie();
cookies = GetAllCookies(cm_.get());
EXPECT_THAT(cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "InsertedHttp443"),
MatchesCookieNameValue("A", "InsertedHttps80"),
MatchesCookieNameValue("A", "InsertedDomainHttps80")));
}
TEST_F(CookieMonsterTest_MaybeDeleteEquivalentCookieAndUpdateStatus,
NoSchemeYesPort) {
scoped_feature_list_.InitWithFeatures(
{net::features::kEnablePortBoundCookies},
{net::features::kEnableSchemeBoundCookies});
InitializeTest();
AddHttpPort443Cookie();
auto cookies = GetAllCookies(cm_.get());
EXPECT_THAT(cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "InsertedHttp443"),
MatchesCookieNameValue("A", "PreexistingDomainHttps443")));
AddHttpsPort80Cookie();
cookies = GetAllCookies(cm_.get());
EXPECT_THAT(cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "InsertedHttp443"),
MatchesCookieNameValue("A", "InsertedHttps80"),
MatchesCookieNameValue("A", "PreexistingDomainHttps443")));
AddDomainHttpsPort80Cookie();
cookies = GetAllCookies(cm_.get());
EXPECT_THAT(cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "InsertedHttp443"),
MatchesCookieNameValue("A", "InsertedHttps80"),
MatchesCookieNameValue("A", "InsertedDomainHttps80")));
}
TEST_F(CookieMonsterTest_MaybeDeleteEquivalentCookieAndUpdateStatus,
YesSchemeYesPort) {
scoped_feature_list_.InitWithFeatures(
{net::features::kEnableSchemeBoundCookies,
net::features::kEnablePortBoundCookies},
{});
InitializeTest();
AddHttpPort443Cookie();
auto cookies = GetAllCookies(cm_.get());
EXPECT_THAT(cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "PreexistingHttps443"),
MatchesCookieNameValue("A", "InsertedHttp443"),
MatchesCookieNameValue("A", "PreexistingDomainHttps443")));
AddHttpsPort80Cookie();
cookies = GetAllCookies(cm_.get());
EXPECT_THAT(cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "PreexistingHttps443"),
MatchesCookieNameValue("A", "InsertedHttp443"),
MatchesCookieNameValue("A", "InsertedHttps80"),
MatchesCookieNameValue("A", "PreexistingDomainHttps443")));
AddDomainHttpsPort80Cookie();
cookies = GetAllCookies(cm_.get());
EXPECT_THAT(cookies,
testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "PreexistingHttps443"),
MatchesCookieNameValue("A", "InsertedHttp443"),
MatchesCookieNameValue("A", "InsertedHttps80"),
MatchesCookieNameValue("A", "InsertedDomainHttps80")));
}
class CookieMonsterTest_StoreLoadedCookies : public CookieMonsterTest {
public:
void InitializeTest() {
store_ = base::MakeRefCounted<MockPersistentCookieStore>();
cm_ = std::make_unique<CookieMonster>(store_.get(), net::NetLog::Get());
base::Time most_recent_time = base::Time::Now();
base::Time middle_time = most_recent_time - base::Minutes(1);
base::Time least_recent_time = middle_time - base::Minutes(1);
auto basic_cookie = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "A=basic", base::Time::Now());
basic_cookie->SetCreationDate(most_recent_time);
starting_list_.push_back(std::move(basic_cookie));
GURL::Replacements replace_scheme;
replace_scheme.SetSchemeStr("http");
replace_scheme.SetPortStr("443");
GURL foo_with_http = https_www_foo_.url().ReplaceComponents(replace_scheme);
auto http_cookie = CanonicalCookie::CreateForTesting(
foo_with_http, "A=http", base::Time::Now());
http_cookie->SetCreationDate(middle_time);
starting_list_.push_back(std::move(http_cookie));
GURL::Replacements replace_port;
replace_port.SetPortStr("450");
GURL foo_with_450 = https_www_foo_.url().ReplaceComponents(replace_port);
auto port_450_cookie = CanonicalCookie::CreateForTesting(
foo_with_450, "A=port450", base::Time::Now());
port_450_cookie->SetCreationDate(least_recent_time);
starting_list_.push_back(std::move(port_450_cookie));
auto basic_domain_cookie = CanonicalCookie::CreateForTesting(
https_www_foo_.url(),
"A=basic_domain; Domain=" + https_www_foo_.domain(), base::Time::Now());
basic_domain_cookie->SetCreationDate(most_recent_time);
starting_list_.push_back(std::move(basic_domain_cookie));
auto http_domain_cookie = CanonicalCookie::CreateForTesting(
foo_with_http, "A=http_domain; Domain=" + https_www_foo_.domain(),
base::Time::Now());
http_domain_cookie->SetCreationDate(middle_time);
starting_list_.push_back(std::move(http_domain_cookie));
auto port_450_domain_cookie = CanonicalCookie::CreateForTesting(
foo_with_450, "A=port450_domain; Domain=" + https_www_foo_.domain(),
base::Time::Now());
port_450_domain_cookie->SetCreationDate(least_recent_time);
starting_list_.push_back(std::move(port_450_domain_cookie));
ASSERT_EQ(starting_list_.size(), 6UL);
}
scoped_refptr<net::MockPersistentCookieStore> store_;
std::unique_ptr<CookieMonster> cm_;
std::vector<std::unique_ptr<CanonicalCookie>> starting_list_;
base::test::ScopedFeatureList scoped_feature_list_;
};
TEST_F(CookieMonsterTest_StoreLoadedCookies, NoSchemeNoPort) {
scoped_feature_list_.InitWithFeatures(
{}, {net::features::kEnableSchemeBoundCookies,
net::features::kEnablePortBoundCookies});
InitializeTest();
cm_->StoreLoadedCookies(std::move(starting_list_));
auto cookies = GetAllCookies(cm_.get());
EXPECT_THAT(cookies, testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "basic"),
MatchesCookieNameValue("A", "basic_domain")));
}
TEST_F(CookieMonsterTest_StoreLoadedCookies, YesSchemeNoPort) {
scoped_feature_list_.InitWithFeatures(
{net::features::kEnableSchemeBoundCookies},
{net::features::kEnablePortBoundCookies});
InitializeTest();
cm_->StoreLoadedCookies(std::move(starting_list_));
auto cookies = GetAllCookies(cm_.get());
EXPECT_THAT(cookies, testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "basic"),
MatchesCookieNameValue("A", "http"),
MatchesCookieNameValue("A", "basic_domain"),
MatchesCookieNameValue("A", "http_domain")));
}
TEST_F(CookieMonsterTest_StoreLoadedCookies, NoSchemeYesPort) {
scoped_feature_list_.InitWithFeatures(
{net::features::kEnablePortBoundCookies},
{net::features::kEnableSchemeBoundCookies});
InitializeTest();
cm_->StoreLoadedCookies(std::move(starting_list_));
auto cookies = GetAllCookies(cm_.get());
EXPECT_THAT(cookies, testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "basic"),
MatchesCookieNameValue("A", "port450"),
MatchesCookieNameValue("A", "basic_domain")));
}
TEST_F(CookieMonsterTest_StoreLoadedCookies, YesSchemeYesPort) {
scoped_feature_list_.InitWithFeatures(
{net::features::kEnablePortBoundCookies,
net::features::kEnableSchemeBoundCookies},
{});
InitializeTest();
cm_->StoreLoadedCookies(std::move(starting_list_));
auto cookies = GetAllCookies(cm_.get());
EXPECT_THAT(cookies, testing::UnorderedElementsAre(
MatchesCookieNameValue("A", "basic"),
MatchesCookieNameValue("A", "http"),
MatchesCookieNameValue("A", "port450"),
MatchesCookieNameValue("A", "basic_domain"),
MatchesCookieNameValue("A", "http_domain")));
}
TEST_F(CookieMonsterTest, SkipDontOverwriteForMultipleReasons) {
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
auto preexisting_cookie = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "A=B;Secure;HttpOnly", base::Time::Now());
CookieAccessResult access_result = SetCanonicalCookieReturnAccessResult(
cm.get(), std::move(preexisting_cookie), https_www_foo_.url(),
true );
ASSERT_TRUE(access_result.status.IsInclude());
auto cookie = CanonicalCookie::CreateForTesting(http_www_foo_.url(), "A=B",
base::Time::Now());
access_result = SetCanonicalCookieReturnAccessResult(
cm.get(), std::move(cookie), http_www_foo_.url(),
false );
EXPECT_TRUE(access_result.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_OVERWRITE_SECURE,
CookieInclusionStatus::ExclusionReason::EXCLUDE_OVERWRITE_HTTP_ONLY}));
auto entries = net_log_.GetEntries();
ExpectLogContainsSomewhere(
entries, 0, NetLogEventType::COOKIE_STORE_COOKIE_REJECTED_SECURE,
NetLogEventPhase::NONE);
ExpectLogContainsSomewhere(
entries, 0, NetLogEventType::COOKIE_STORE_COOKIE_REJECTED_HTTPONLY,
NetLogEventPhase::NONE);
}
TEST_F(CookieMonsterTest, DontDeleteEquivalentCookieIfSetIsRejected) {
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
auto preexisting_cookie = CanonicalCookie::CreateForTesting(
http_www_foo_.url(), "cookie=foo", base::Time::Now());
CookieAccessResult access_result = SetCanonicalCookieReturnAccessResult(
cm.get(), std::move(preexisting_cookie), http_www_foo_.url(),
false );
ASSERT_TRUE(access_result.status.IsInclude());
auto bad_cookie = CanonicalCookie::CreateForTesting(
http_www_foo_.url(), "cookie=bar;secure", base::Time::Now());
CookieAccessResult access_result2 = SetCanonicalCookieReturnAccessResult(
cm.get(), std::move(bad_cookie), http_www_foo_.url(),
false );
EXPECT_TRUE(access_result2.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_SECURE_ONLY}));
EXPECT_EQ("cookie=foo", GetCookies(cm.get(), https_www_foo_.url()));
}
TEST_F(CookieMonsterTest, SetSecureCookies) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
GURL http_url("http://www.foo.com");
GURL http_superdomain_url("http://foo.com");
GURL https_url("https://www.foo.com");
GURL https_foo_url("https://www.foo.com/foo");
GURL http_foo_url("http://www.foo.com/foo");
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(cm.get(), http_url, "A=C;").IsInclude());
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(cm.get(), https_url, "A=B;").IsInclude());
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(cm.get(), http_url, "A=B; Secure")
.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_SECURE_ONLY}));
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), https_url, "A=B; Secure")
.IsInclude());
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), https_url, "A=B; Secure")
.IsInclude());
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), http_url, "A=C;")
.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_OVERWRITE_SECURE}));
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), https_url, "A=B; Secure")
.IsInclude());
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(cm.get(), https_url, "A=C;").IsInclude());
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), https_url, "A=B; Secure")
.IsInclude());
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), http_url, "A=C; path=/")
.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_OVERWRITE_SECURE}));
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(cm.get(), http_url, "A=C; path=/my/path")
.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_OVERWRITE_SECURE}));
EXPECT_TRUE(
SetCookie(cm.get(), https_url, "WITH_PATH=B; Secure; path=/my/path"));
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), http_url, "WITH_PATH=C")
.IsInclude());
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(cm.get(), http_url, "WITH_PATH=C; path=/")
.IsInclude());
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), http_url,
"WITH_PATH=C; path=/your/path")
.IsInclude());
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), http_url,
"WITH_PATH=C; path=/my/path")
.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_OVERWRITE_SECURE}));
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), http_url,
"WITH_PATH=C; path=/my/path/sub")
.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_OVERWRITE_SECURE}));
DeleteAll(cm.get());
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(cm.get(), http_url, "A=B; path=/foo")
.IsInclude());
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(cm.get(), https_url, "A=C; Secure; path=/")
.IsInclude());
EXPECT_EQ("A=B", GetCookies(cm.get(), http_foo_url));
EXPECT_THAT(GetCookies(cm.get(), https_foo_url), testing::HasSubstr("A=B"));
EXPECT_THAT(GetCookies(cm.get(), https_foo_url), testing::HasSubstr("A=C"));
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(cm.get(), http_url, "A=D; path=/foo")
.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_OVERWRITE_SECURE}));
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), http_url, "A=D; path=/")
.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_OVERWRITE_SECURE}));
EXPECT_THAT(GetCookies(cm.get(), https_foo_url), testing::HasSubstr("A=C"));
EXPECT_THAT(GetCookies(cm.get(), https_foo_url), testing::HasSubstr("A=B"));
EXPECT_THAT(GetCookies(cm.get(), https_foo_url),
testing::Not(testing::HasSubstr("A=D")));
EXPECT_TRUE(CreateAndSetCookieReturnStatus(
cm.get(), https_url,
"A=C; path=/; Expires=Thu, 01-Jan-1970 00:00:01 GMT")
.IsInclude());
EXPECT_EQ("A=B", GetCookies(cm.get(), https_foo_url));
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), https_url, "A=B; Secure")
.IsInclude());
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(cm.get(), http_url, "A=C; domain=foo.com")
.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_OVERWRITE_SECURE}));
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), http_url,
"A=C; domain=www.foo.com")
.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_OVERWRITE_SECURE}));
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), https_url,
"B=C; Secure; domain=foo.com")
.IsInclude());
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(cm.get(), http_url, "B=D; domain=foo.com")
.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_OVERWRITE_SECURE}));
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), http_url, "B=D")
.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_OVERWRITE_SECURE}));
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(cm.get(), http_superdomain_url, "B=D")
.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_OVERWRITE_SECURE}));
CookieOptions include_httponly = CookieOptions::MakeAllInclusive();
EXPECT_TRUE(CreateAndSetCookie(cm.get(), https_url, "C=D; httponly",
include_httponly));
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), https_url, "C=E; Secure")
.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_OVERWRITE_HTTP_ONLY}));
auto entries = net_log_.GetEntries();
ExpectLogContainsSomewhere(
entries, 0, NetLogEventType::COOKIE_STORE_COOKIE_REJECTED_HTTPONLY,
NetLogEventPhase::NONE);
}
TEST_F(CookieMonsterTest, LeaveSecureCookiesAlone_DomainMatch) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
const char* kRegistrableDomain = "foo.com";
const char* kSuperdomain = "a.foo.com";
const char* kDomain = "b.a.foo.com";
const char* kSubdomain = "c.b.a.foo.com";
const char* kAnotherDomain = "z.foo.com";
for (const char* preexisting_cookie_host :
{kRegistrableDomain, kSuperdomain, kDomain, kSubdomain}) {
GURL preexisting_cookie_url(
base::StrCat({url::kHttpsScheme, url::kStandardSchemeSeparator,
preexisting_cookie_host}));
for (const char* new_cookie_host :
{kRegistrableDomain, kSuperdomain, kDomain, kSubdomain}) {
GURL https_url(base::StrCat(
{url::kHttpsScheme, url::kStandardSchemeSeparator, new_cookie_host}));
GURL http_url(base::StrCat(
{url::kHttpScheme, url::kStandardSchemeSeparator, new_cookie_host}));
EXPECT_TRUE(CreateAndSetCookieReturnStatus(
cm.get(), preexisting_cookie_url, "A=0; Secure")
.IsInclude());
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(
cm.get(), preexisting_cookie_url,
base::StrCat({"B=0; Secure; Domain=", preexisting_cookie_host}))
.IsInclude());
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), http_url, "A=1")
.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_OVERWRITE_SECURE}))
<< "Insecure host cookie from " << http_url
<< " should not be set if equivalent secure host cookie from "
<< preexisting_cookie_url << " exists.";
EXPECT_TRUE(CreateAndSetCookieReturnStatus(
cm.get(), http_url,
base::StrCat({"A=2; Domain=", new_cookie_host}))
.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_OVERWRITE_SECURE}))
<< "Insecure domain cookie from " << http_url
<< " should not be set if equivalent secure host cookie from "
<< preexisting_cookie_url << " exists.";
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), http_url, "B=1")
.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_OVERWRITE_SECURE}))
<< "Insecure host cookie from " << http_url
<< " should not be set if equivalent secure domain cookie from "
<< preexisting_cookie_url << " exists.";
EXPECT_TRUE(CreateAndSetCookieReturnStatus(
cm.get(), http_url,
base::StrCat({"B=2; Domain=", new_cookie_host}))
.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_OVERWRITE_SECURE}))
<< "Insecure domain cookie from " << http_url
<< " should not be set if equivalent secure domain cookie from "
<< preexisting_cookie_url << " exists.";
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), https_url, "A=3;")
.IsInclude())
<< "Insecure host cookie from " << https_url
<< " can be set even if equivalent secure host cookie from "
<< preexisting_cookie_url << " exists.";
EXPECT_TRUE(CreateAndSetCookieReturnStatus(
cm.get(), https_url,
base::StrCat({"A=4; Domain=", new_cookie_host}))
.IsInclude())
<< "Insecure domain cookie from " << https_url
<< " can be set even if equivalent secure host cookie from "
<< preexisting_cookie_url << " exists.";
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), https_url, "B=3;")
.IsInclude())
<< "Insecure host cookie from " << https_url
<< " can be set even if equivalent secure domain cookie from "
<< preexisting_cookie_url << " exists.";
EXPECT_TRUE(CreateAndSetCookieReturnStatus(
cm.get(), https_url,
base::StrCat({"B=4; Domain=", new_cookie_host}))
.IsInclude())
<< "Insecure domain cookie from " << https_url
<< " can be set even if equivalent secure domain cookie from "
<< preexisting_cookie_url << " exists.";
DeleteAll(cm.get());
}
}
GURL nonmatching_https_url(base::StrCat(
{url::kHttpsScheme, url::kStandardSchemeSeparator, kAnotherDomain}));
for (const char* host : {kSuperdomain, kDomain, kSubdomain}) {
GURL https_url(
base::StrCat({url::kHttpsScheme, url::kStandardSchemeSeparator, host}));
GURL http_url(
base::StrCat({url::kHttpScheme, url::kStandardSchemeSeparator, host}));
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), nonmatching_https_url,
"A=0; Secure")
.IsInclude());
EXPECT_TRUE(CreateAndSetCookieReturnStatus(
cm.get(), nonmatching_https_url,
base::StrCat({"B=0; Secure; Domain=", kAnotherDomain}))
.IsInclude());
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(cm.get(), http_url, "A=1;").IsInclude())
<< "Insecure host cookie from " << http_url
<< " can be set even if equivalent secure host cookie from "
<< nonmatching_https_url << " exists.";
EXPECT_TRUE(CreateAndSetCookieReturnStatus(
cm.get(), http_url, base::StrCat({"A=2; Domain=", host}))
.IsInclude())
<< "Insecure domain cookie from " << http_url
<< " can be set even if equivalent secure host cookie from "
<< nonmatching_https_url << " exists.";
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(cm.get(), http_url, "B=1;").IsInclude())
<< "Insecure host cookie from " << http_url
<< " can be set even if equivalent secure domain cookie from "
<< nonmatching_https_url << " exists.";
EXPECT_TRUE(CreateAndSetCookieReturnStatus(
cm.get(), http_url, base::StrCat({"B=2; Domain=", host}))
.IsInclude())
<< "Insecure domain cookie from " << http_url
<< " can be set even if equivalent secure domain cookie from "
<< nonmatching_https_url << " exists.";
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(cm.get(), https_url, "A=3;").IsInclude())
<< "Insecure host cookie from " << https_url
<< " can be set even if equivalent secure host cookie from "
<< nonmatching_https_url << " exists.";
EXPECT_TRUE(CreateAndSetCookieReturnStatus(
cm.get(), https_url, base::StrCat({"A=4; Domain=", host}))
.IsInclude())
<< "Insecure domain cookie from " << https_url
<< " can be set even if equivalent secure host cookie from "
<< nonmatching_https_url << " exists.";
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(cm.get(), https_url, "B=3;").IsInclude())
<< "Insecure host cookie from " << https_url
<< " can be set even if equivalent secure host cookie from "
<< nonmatching_https_url << " exists.";
EXPECT_TRUE(CreateAndSetCookieReturnStatus(
cm.get(), https_url, base::StrCat({"B=4; Domain=", host}))
.IsInclude())
<< "Insecure domain cookie from " << https_url
<< " can be set even if equivalent secure host cookie from "
<< nonmatching_https_url << " exists.";
DeleteAll(cm.get());
}
}
TEST_F(CookieMonsterTest, LeaveSecureCookiesAlone_PathMatch) {
auto cm = std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
auto kPaths = std::to_array<const char*>({"/", "/1", "/1/2", "/1/2/3"});
const char* kOtherDirectory = "/9";
for (int preexisting_cookie_path_index = 0; preexisting_cookie_path_index < 4;
++preexisting_cookie_path_index) {
const char* preexisting_cookie_path = kPaths[preexisting_cookie_path_index];
GURL preexisting_cookie_url(
base::StrCat({url::kHttpsScheme, url::kStandardSchemeSeparator,
"a.foo.com", preexisting_cookie_path}));
for (int new_cookie_path_index = 0; new_cookie_path_index < 4;
++new_cookie_path_index) {
const char* new_cookie_path = kPaths[new_cookie_path_index];
bool should_path_match =
new_cookie_path_index >= preexisting_cookie_path_index;
GURL https_url(
base::StrCat({url::kHttpsScheme, url::kStandardSchemeSeparator,
"a.foo.com", new_cookie_path}));
GURL http_url(
base::StrCat({url::kHttpScheme, url::kStandardSchemeSeparator,
"a.foo.com", new_cookie_path}));
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(
cm.get(), preexisting_cookie_url,
base::StrCat({"A=0; Secure; Path=", preexisting_cookie_path}))
.IsInclude());
CookieInclusionStatus set = CreateAndSetCookieReturnStatus(
cm.get(), http_url, base::StrCat({"A=1; Path=", new_cookie_path}));
EXPECT_TRUE(should_path_match
? set.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_OVERWRITE_SECURE})
: set.IsInclude())
<< "Insecure cookie from " << http_url << " should "
<< (should_path_match ? "not " : "")
<< "be set if equivalent secure cookie from "
<< preexisting_cookie_url << " exists.";
EXPECT_TRUE(CreateAndSetCookieReturnStatus(
cm.get(), https_url,
base::StrCat({"A=2; Path=", new_cookie_path}))
.IsInclude())
<< "Insecure cookie from " << http_url
<< " can be set even if equivalent secure cookie from "
<< preexisting_cookie_url << " exists.";
DeleteAll(cm.get());
}
}
GURL nonmatching_https_url(
base::StrCat({url::kHttpsScheme, url::kStandardSchemeSeparator,
"a.foo.com", kOtherDirectory}));
for (int new_cookie_path_index = 1; new_cookie_path_index < 4;
++new_cookie_path_index) {
const char* new_cookie_path = kPaths[new_cookie_path_index];
GURL https_url(base::StrCat(
{url::kHttpsScheme, url::kStandardSchemeSeparator, new_cookie_path}));
GURL http_url(base::StrCat(
{url::kHttpScheme, url::kStandardSchemeSeparator, new_cookie_path}));
EXPECT_TRUE(CreateAndSetCookieReturnStatus(
cm.get(), nonmatching_https_url,
base::StrCat({"A=0; Secure; Path=", kOtherDirectory}))
.IsInclude());
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(
cm.get(), http_url, base::StrCat({"A=1; Path=", new_cookie_path}))
.IsInclude())
<< "Insecure cookie from " << http_url
<< " can be set even if equivalent secure cookie from "
<< nonmatching_https_url << " exists.";
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(
cm.get(), https_url, base::StrCat({"A=1; Path=", new_cookie_path}))
.IsInclude())
<< "Insecure cookie from " << https_url
<< " can be set even if equivalent secure cookie from "
<< nonmatching_https_url << " exists.";
}
}
TEST_F(CookieMonsterTest, EvictSecureCookies) {
DCHECK_EQ(180U, CookieMonster::kDomainMaxCookies);
DCHECK_EQ(150U, CookieMonster::kDomainMaxCookies -
CookieMonster::kDomainPurgeCookies);
DCHECK_EQ(3300U, CookieMonster::kMaxCookies);
DCHECK_EQ(30, CookieMonster::kSafeFromGlobalPurgeDays);
const CookiesEntry test1[] = {{180U, true}, {1U, false}};
TestSecureCookieEviction(test1, 150U, 0U, nullptr);
const CookiesEntry test2[] = {{180U, false}, {20U, true}};
TestSecureCookieEviction(test2, 20U, 149U, nullptr);
const CookiesEntry test3[] = {{200U, true}};
TestSecureCookieEviction(test3, 169U, 0U, nullptr);
const CookiesEntry test4[] = {{1U, false}, {199U, true}};
TestSecureCookieEviction(test4, 169U, 0U, nullptr);
const CookiesEntry test5[] = {{75U, false}, {75U, true}};
TestSecureCookieEviction(test5, 75U, 75U, nullptr);
const CookiesEntry test6[] = {{50U, true}, {50U, false}, {81U, true}};
TestSecureCookieEviction(test6, 131U, 19U, nullptr);
const CookiesEntry test7[] = {{50U, false}, {50U, true}, {81U, false}};
TestSecureCookieEviction(test7, 50U, 100U, nullptr);
const CookiesEntry test8[] = {{50U, false}, {50U, true}, {90U, false}};
TestSecureCookieEviction(test8, 50U, 109U, nullptr);
const CookiesEntry test9[] = {{180U, false}, {20U, true}};
const AltHosts test9_alt_hosts(0, 20);
TestSecureCookieEviction(test9, 20U, 169U, &test9_alt_hosts);
const CookiesEntry test10[] = {{1U, false}};
const AltHosts test10_alt_hosts(3300, 0);
TestSecureCookieEviction(test10, 2999U, 1U, &test10_alt_hosts);
const CookiesEntry test11[] = {{1U, false}};
const AltHosts test11_alt_hosts(0, 3300);
TestSecureCookieEviction(test11, 0U, 3000U, &test11_alt_hosts);
const CookiesEntry test12[] = {{1U, true}};
const AltHosts test12_alt_hosts(0, 3300);
TestSecureCookieEviction(test12, 1U, 2999U, &test12_alt_hosts);
const CookiesEntry test13[] = {{1U, false}};
const AltHosts test13_alt_hosts(1500, 1800);
TestSecureCookieEviction(test13, 1500U, 1500, &test13_alt_hosts);
const CookiesEntry test14[] = {{1U, true}};
const AltHosts test14_alt_hosts(1500, 1800);
TestSecureCookieEviction(test14, 1501U, 1499, &test14_alt_hosts);
}
TEST_F(CookieMonsterTest, EquivalentCookies) {
auto cm = std::make_unique<CookieMonster>(nullptr, nullptr);
GURL http_url("http://www.foo.com");
GURL http_superdomain_url("http://foo.com");
GURL https_url("https://www.foo.com");
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), https_url, "A=B; Secure")
.IsInclude());
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), https_url,
"A=C; path=/some/other/path")
.IsInclude());
EXPECT_FALSE(SetCookie(cm.get(), http_url, "A=D; path=/some/other/path"));
EXPECT_TRUE(CreateAndSetCookieReturnStatus(cm.get(), https_url, "A=B; Secure")
.IsInclude());
EXPECT_TRUE(
CreateAndSetCookieReturnStatus(cm.get(), https_url, "A=C; domain=foo.com")
.IsInclude());
EXPECT_FALSE(SetCookie(cm.get(), http_url, "A=D; domain=foo.com"));
}
TEST_F(CookieMonsterTest, SetCanonicalCookieDoesNotBlockForLoadAll) {
scoped_refptr<MockPersistentCookieStore> persistent_store =
base::MakeRefCounted<MockPersistentCookieStore>();
persistent_store->set_store_load_commands(true);
CookieMonster cm(persistent_store.get(), nullptr);
ResultSavingCookieCallback<CookieAccessResult> callback_set;
GURL cookie_url("http://a.com/");
cm.SetCanonicalCookieAsync(
CanonicalCookie::CreateForTesting(cookie_url, "A=B", base::Time::Now()),
cookie_url, CookieOptions::MakeAllInclusive(),
callback_set.MakeCallback());
GetCookieListCallback callback_get;
cm.GetCookieListWithOptionsAsync(
GURL("http://b.com/"), CookieOptions::MakeAllInclusive(),
CookiePartitionKeyCollection(), callback_get.MakeCallback());
const auto& commands = persistent_store->commands();
for (size_t i = 0; i < commands.size(); ++i) {
if (commands[i].type == CookieStoreCommand::LOAD_COOKIES_FOR_KEY)
persistent_store->TakeCallbackAt(i).Run(
std::vector<std::unique_ptr<CanonicalCookie>>());
}
callback_set.WaitUntilDone();
callback_get.WaitUntilDone();
for (size_t i = 0; i < commands.size(); ++i) {
if (commands[i].type == CookieStoreCommand::LOAD)
persistent_store->TakeCallbackAt(i).Run(
std::vector<std::unique_ptr<CanonicalCookie>>());
}
}
TEST_F(CookieMonsterTest, DeleteDuplicateCTime) {
const auto kNames = std::to_array<const char*>({"A", "B", "C"});
for (const auto* name : kNames) {
CookieMonster cm(nullptr, nullptr);
Time now = Time::Now();
GURL url("http://www.example.com");
for (size_t i = 0; i < std::size(kNames); ++i) {
std::string cookie_string =
base::StrCat({kNames[i], "=", base::NumberToString(i)});
EXPECT_TRUE(SetCookieWithCreationTime(&cm, url, cookie_string, now));
}
CookieList all_cookies = GetAllCookiesForURLWithOptions(
&cm, url, CookieOptions::MakeAllInclusive());
ASSERT_EQ(all_cookies.size(), std::size(kNames));
for (size_t i = 0; i < std::size(kNames); ++i) {
const CanonicalCookie& cookie = all_cookies[i];
if (cookie.Name() == name) {
EXPECT_TRUE(DeleteCanonicalCookie(&cm, cookie));
}
}
all_cookies = GetAllCookiesForURLWithOptions(
&cm, url, CookieOptions::MakeAllInclusive());
ASSERT_EQ(all_cookies.size(), std::size(kNames) - 1);
for (size_t i = 0; i < std::size(kNames) - 1; ++i) {
const CanonicalCookie& cookie = all_cookies[i];
EXPECT_NE(cookie.Name(), name);
}
}
}
TEST_F(CookieMonsterTest, DeleteCookieWithInheritedTimestamps) {
Time t1 = Time::Now();
Time t2 = t1 + base::Seconds(1);
GURL url("http://www.example.com");
std::string cookie_line = "foo=bar";
CookieOptions options = CookieOptions::MakeAllInclusive();
std::optional<base::Time> server_time = std::nullopt;
std::optional<CookiePartitionKey> partition_key = std::nullopt;
CookieMonster cm(nullptr, nullptr);
auto cookie = CanonicalCookie::CreateForTesting(url, cookie_line, t1,
server_time, partition_key);
ResultSavingCookieCallback<CookieAccessResult> set_callback_1;
cm.SetCanonicalCookieAsync(std::move(cookie), url, options,
set_callback_1.MakeCallback());
set_callback_1.WaitUntilDone();
cookie = CanonicalCookie::CreateForTesting(url, cookie_line, t2, server_time,
partition_key);
ResultSavingCookieCallback<CookieAccessResult> set_callback_2;
cm.SetCanonicalCookieAsync(std::move(cookie), url, options,
set_callback_2.MakeCallback());
set_callback_2.WaitUntilDone();
cookie = CanonicalCookie::CreateForTesting(url, cookie_line, t2, server_time,
partition_key);
ResultSavingCookieCallback<unsigned int> delete_callback;
cm.DeleteCanonicalCookieAsync(*cookie, delete_callback.MakeCallback());
delete_callback.WaitUntilDone();
EXPECT_EQ(1U, delete_callback.result());
}
TEST_F(CookieMonsterTest, RejectCreatedSameSiteCookieOnSet) {
GURL url("http://www.example.com");
std::string cookie_line = "foo=bar; SameSite=Lax";
CookieMonster cm(nullptr, nullptr);
CookieOptions env_cross_site;
env_cross_site.set_same_site_cookie_context(
CookieOptions::SameSiteCookieContext(
CookieOptions::SameSiteCookieContext::ContextType::CROSS_SITE));
CookieInclusionStatus status;
auto cookie =
CanonicalCookie::CreateForTesting(url, cookie_line, base::Time::Now(),
std::nullopt,
std::nullopt,
CookieSourceType::kUnknown, &status);
ASSERT_TRUE(cookie != nullptr);
ASSERT_TRUE(status.IsInclude());
ResultSavingCookieCallback<CookieAccessResult> callback;
cm.SetCanonicalCookieAsync(std::move(cookie), url, env_cross_site,
callback.MakeCallback());
callback.WaitUntilDone();
EXPECT_TRUE(callback.result().status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_SAMESITE_LAX}));
}
TEST_F(CookieMonsterTest, RejectCreatedSecureCookieOnSet) {
GURL http_url("http://www.example.com");
std::string cookie_line = "foo=bar; Secure";
CookieMonster cm(nullptr, nullptr);
CookieInclusionStatus status;
auto cookie = CanonicalCookie::CreateForTesting(
http_url, cookie_line, base::Time::Now(), std::nullopt,
std::nullopt, CookieSourceType::kUnknown,
&status);
ASSERT_TRUE(cookie != nullptr);
ASSERT_TRUE(status.IsInclude());
ResultSavingCookieCallback<CookieAccessResult> callback;
cm.SetCanonicalCookieAsync(std::move(cookie), http_url,
CookieOptions::MakeAllInclusive(),
callback.MakeCallback());
callback.WaitUntilDone();
EXPECT_TRUE(callback.result().status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_SECURE_ONLY}));
}
TEST_F(CookieMonsterTest, RejectCreatedHttpOnlyCookieOnSet) {
GURL url("http://www.example.com");
std::string cookie_line = "foo=bar; HttpOnly";
CookieMonster cm(nullptr, nullptr);
CookieInclusionStatus status;
auto cookie =
CanonicalCookie::CreateForTesting(url, cookie_line, base::Time::Now(),
std::nullopt,
std::nullopt,
CookieSourceType::kUnknown, &status);
ASSERT_TRUE(cookie != nullptr);
ASSERT_TRUE(status.IsInclude());
CookieOptions options_no_httponly;
options_no_httponly.set_same_site_cookie_context(
CookieOptions::SameSiteCookieContext(
CookieOptions::SameSiteCookieContext::ContextType::SAME_SITE_STRICT));
options_no_httponly.set_exclude_httponly();
ResultSavingCookieCallback<CookieAccessResult> callback;
cm.SetCanonicalCookieAsync(std::move(cookie), url, options_no_httponly,
callback.MakeCallback());
callback.WaitUntilDone();
EXPECT_TRUE(callback.result().status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_HTTP_ONLY}));
}
TEST_F(CookieMonsterTest, CookiesWithoutSameSiteMustBeSecure) {
const base::TimeDelta kLongAge = kLaxAllowUnsafeMaxAge * 4;
const base::TimeDelta kShortAge = kLaxAllowUnsafeMaxAge / 4;
struct TestCase {
bool is_url_secure;
std::string cookie_line;
CookieInclusionStatus expected_set_cookie_result;
CookieEffectiveSameSite expected_effective_samesite =
CookieEffectiveSameSite::NO_RESTRICTION;
base::TimeDelta creation_time_delta = base::TimeDelta();
};
auto test_cases = std::to_array<TestCase>({
{true, "A=B; SameSite=Lax", CookieInclusionStatus(),
CookieEffectiveSameSite::LAX_MODE},
{true, "A=B",
CookieInclusionStatus(), CookieEffectiveSameSite::LAX_MODE_ALLOW_UNSAFE,
kShortAge},
{true, "A=B",
CookieInclusionStatus(), CookieEffectiveSameSite::LAX_MODE, kLongAge},
{true, "A=B; SameSite=None; Secure", CookieInclusionStatus(),
CookieEffectiveSameSite::NO_RESTRICTION},
{true, "A=B; SameSite=None",
CookieInclusionStatus::MakeFromReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_SAMESITE_NONE_INSECURE},
{CookieInclusionStatus::WarningReason::
WARN_SAMESITE_NONE_INSECURE})},
{false, "A=B",
CookieInclusionStatus(), CookieEffectiveSameSite::LAX_MODE_ALLOW_UNSAFE,
kShortAge},
{false, "A=B",
CookieInclusionStatus(), CookieEffectiveSameSite::LAX_MODE, kLongAge},
{false, "A=B; Max-Age=1000000",
CookieInclusionStatus(), CookieEffectiveSameSite::LAX_MODE_ALLOW_UNSAFE,
kShortAge},
{false,
"A=B; Max-Age=1000000",
CookieInclusionStatus(), CookieEffectiveSameSite::LAX_MODE, kLongAge},
});
auto cm = std::make_unique<CookieMonster>(nullptr, nullptr);
GURL secure_url("https://www.example1.test");
GURL insecure_url("http://www.example2.test");
for (size_t i = 0; i < test_cases.size(); ++i) {
TestCase test = test_cases[i];
GURL url = test.is_url_secure ? secure_url : insecure_url;
base::Time creation_time = base::Time::Now() - test.creation_time_delta;
auto cookie =
CanonicalCookie::CreateForTesting(url, test.cookie_line, creation_time);
CanonicalCookie cookie_copy = *cookie;
CookieAccessResult result = SetCanonicalCookieReturnAccessResult(
cm.get(), std::move(cookie), url,
true );
EXPECT_EQ(test.expected_set_cookie_result, result.status)
<< "Test case " << i << " failed.";
if (result.status.IsInclude()) {
auto cookies = GetAllCookiesForURL(cm.get(), url);
ASSERT_EQ(1u, cookies.size());
EXPECT_EQ(test.expected_effective_samesite, result.effective_same_site)
<< "Test case " << i << " failed.";
DeleteCanonicalCookie(cm.get(), cookie_copy);
}
}
}
TEST_F(CookieMonsterTest, CookieChangeCause) {
auto cookie_monster =
std::make_unique<CookieMonster>(nullptr, net::NetLog::Get());
std::vector<CookieChangeInfo> changes;
auto subscription =
cookie_monster->GetChangeDispatcher().AddCallbackForAllChanges(
base::BindLambdaForTesting([&](const CookieChangeInfo& change) {
changes.push_back(change);
}));
auto format_cookie_line = [](std::string& cookie_name,
std::string& cookie_value,
base::Time expiry) -> std::string {
return base::StrCat({cookie_name, "=", cookie_value,
"; expires=", base::TimeFormatHTTP(expiry)});
};
GURL url("https://www.foo.com");
std::string cookie_name = "A";
std::string cookie_value = "B";
base::Time expiry = base::Time::Now() + base::Days(1);
auto cookie = CanonicalCookie::CreateForTesting(
url, format_cookie_line(cookie_name, cookie_value, expiry),
base::Time::Now());
ASSERT_TRUE(cookie);
this->SetCanonicalCookie(cookie_monster.get(), std::move(cookie), url,
true);
CookieMonsterTestTraits::DeliverChangeNotifications();
ASSERT_EQ(1u, changes.size());
EXPECT_EQ(CookieChangeCause::INSERTED, changes[0].cause);
EXPECT_EQ(cookie_name, changes[0].cookie.Name());
EXPECT_EQ(cookie_value, changes[0].cookie.Value());
changes.clear();
cookie = CanonicalCookie::CreateForTesting(
url, format_cookie_line(cookie_name, cookie_value, expiry),
base::Time::Now());
ASSERT_TRUE(cookie);
this->SetCanonicalCookie(cookie_monster.get(), std::move(cookie), url,
true);
CookieMonsterTestTraits::DeliverChangeNotifications();
ASSERT_EQ(2u, changes.size());
EXPECT_EQ(CookieChangeCause::OVERWRITE, changes[0].cause);
EXPECT_EQ(CookieChangeCause::INSERTED_NO_CHANGE_OVERWRITE, changes[1].cause);
EXPECT_EQ(cookie_name, changes[0].cookie.Name());
EXPECT_EQ(cookie_name, changes[1].cookie.Name());
EXPECT_EQ(cookie_value, changes[1].cookie.Value());
changes.clear();
base::Time new_expiry = base::Time::Now() + base::Days(2);
cookie = CanonicalCookie::CreateForTesting(
url, format_cookie_line(cookie_name, cookie_value, new_expiry),
base::Time::Now());
ASSERT_TRUE(cookie);
this->SetCanonicalCookie(cookie_monster.get(), std::move(cookie), url,
true);
CookieMonsterTestTraits::DeliverChangeNotifications();
ASSERT_EQ(2u, changes.size());
EXPECT_EQ(CookieChangeCause::OVERWRITE, changes[0].cause);
EXPECT_EQ(CookieChangeCause::INSERTED_NO_VALUE_CHANGE_OVERWRITE,
changes[1].cause);
EXPECT_EQ(cookie_name, changes[0].cookie.Name());
EXPECT_EQ(cookie_name, changes[1].cookie.Name());
EXPECT_EQ(cookie_value, changes[1].cookie.Value());
changes.clear();
std::string new_cookie_value = "C";
cookie = CanonicalCookie::CreateForTesting(
url, format_cookie_line(cookie_name, new_cookie_value, new_expiry),
base::Time::Now());
ASSERT_TRUE(cookie);
this->SetCanonicalCookie(cookie_monster.get(), std::move(cookie), url,
true);
CookieMonsterTestTraits::DeliverChangeNotifications();
ASSERT_EQ(2u, changes.size());
EXPECT_EQ(CookieChangeCause::OVERWRITE, changes[0].cause);
EXPECT_EQ(CookieChangeCause::INSERTED, changes[1].cause);
EXPECT_EQ(cookie_name, changes[0].cookie.Name());
EXPECT_EQ(cookie_name, changes[1].cookie.Name());
EXPECT_EQ(new_cookie_value, changes[1].cookie.Value());
changes.clear();
}
class CookieMonsterNotificationTest : public CookieMonsterTest {
public:
CookieMonsterNotificationTest()
: test_url_("http://www.foo.com/foo"),
store_(base::MakeRefCounted<MockPersistentCookieStore>()),
monster_(std::make_unique<CookieMonster>(store_.get(), nullptr)) {}
~CookieMonsterNotificationTest() override = default;
CookieMonster* monster() { return monster_.get(); }
protected:
const GURL test_url_;
private:
scoped_refptr<MockPersistentCookieStore> store_;
std::unique_ptr<CookieMonster> monster_;
};
void RecordCookieChanges(std::vector<CanonicalCookie>* out_cookies,
std::vector<CookieChangeCause>* out_causes,
const CookieChangeInfo& change) {
DCHECK(out_cookies);
out_cookies->push_back(change.cookie);
if (out_causes)
out_causes->push_back(change.cause);
}
TEST_F(CookieMonsterNotificationTest, NoNotificationOnLoad) {
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
store->set_store_load_commands(true);
auto monster = std::make_unique<CookieMonster>(store.get(), nullptr);
monster->GetAllCookiesAsync(CookieStore::GetAllCookiesCallback());
ASSERT_EQ(1u, store->commands().size());
EXPECT_EQ(CookieStoreCommand::LOAD, store->commands()[0].type);
std::vector<CanonicalCookie> cookies;
std::vector<CookieChangeCause> causes;
std::unique_ptr<CookieChangeSubscription> subscription =
monster->GetChangeDispatcher().AddCallbackForAllChanges(
base::BindRepeating(&RecordCookieChanges, &cookies, &causes));
std::vector<std::unique_ptr<CanonicalCookie>> initial_cookies;
GURL url("http://www.foo.com");
initial_cookies.push_back(
CanonicalCookie::CreateForTesting(url, "X=1; path=/", base::Time::Now()));
initial_cookies.push_back(
CanonicalCookie::CreateForTesting(url, "Y=1; path=/", base::Time::Now()));
initial_cookies.push_back(CanonicalCookie::CreateForTesting(
url, "Y=2; path=/", base::Time::Now() + base::Days(1)));
store->TakeCallbackAt(0).Run(std::move(initial_cookies));
base::RunLoop().RunUntilIdle();
EXPECT_EQ(0u, cookies.size());
EXPECT_EQ(0u, causes.size());
EXPECT_EQ(2u, this->GetAllCookies(monster.get()).size());
this->CreateAndSetCookie(monster.get(), url, "X=2; path=/",
CookieOptions::MakeAllInclusive());
this->CreateAndSetCookie(monster.get(), url, "Y=3; path=/; max-age=0",
CookieOptions::MakeAllInclusive());
base::RunLoop().RunUntilIdle();
ASSERT_EQ(3u, cookies.size());
ASSERT_EQ(3u, causes.size());
EXPECT_EQ("X", cookies[0].Name());
EXPECT_EQ("1", cookies[0].Value());
EXPECT_EQ(CookieChangeCause::OVERWRITE, causes[0]);
EXPECT_EQ("X", cookies[1].Name());
EXPECT_EQ("2", cookies[1].Value());
EXPECT_EQ(CookieChangeCause::INSERTED, causes[1]);
EXPECT_EQ("Y", cookies[2].Name());
EXPECT_EQ("2", cookies[2].Value());
EXPECT_EQ(CookieChangeCause::EXPIRED_OVERWRITE, causes[2]);
}
class CookieMonsterLegacyCookieAccessTest : public CookieMonsterTest {
public:
CookieMonsterLegacyCookieAccessTest()
: cm_(std::make_unique<CookieMonster>(nullptr ,
nullptr
)) {
task_environment_.reset();
task_environment_ =
std::make_unique<base::test::SingleThreadTaskEnvironment>(
base::test::TaskEnvironment::TimeSource::MOCK_TIME);
std::unique_ptr<TestCookieAccessDelegate> access_delegate =
std::make_unique<TestCookieAccessDelegate>();
access_delegate_ = access_delegate.get();
cm_->SetCookieAccessDelegate(std::move(access_delegate));
}
~CookieMonsterLegacyCookieAccessTest() override = default;
protected:
const std::string kDomain = "example.test";
const GURL kHttpsUrl = GURL("https://example.test");
const GURL kHttpUrl = GURL("http://example.test");
std::unique_ptr<CookieMonster> cm_;
raw_ptr<TestCookieAccessDelegate> access_delegate_;
};
TEST_F(CookieMonsterLegacyCookieAccessTest, SetLegacyNoSameSiteCookie) {
EXPECT_FALSE(CreateAndSetCookie(cm_.get(), kHttpUrl, "cookie=chocolate_chip",
CookieOptions()));
access_delegate_->SetExpectationForCookieDomain(
kDomain, CookieAccessSemantics::UNKNOWN);
EXPECT_FALSE(CreateAndSetCookie(cm_.get(), kHttpUrl, "cookie=chocolate_chip",
CookieOptions()));
access_delegate_->SetExpectationForCookieDomain(
kDomain, CookieAccessSemantics::NONLEGACY);
EXPECT_FALSE(CreateAndSetCookie(cm_.get(), kHttpUrl, "cookie=chocolate_chip",
CookieOptions()));
access_delegate_->SetExpectationForCookieDomain(
kDomain, CookieAccessSemantics::LEGACY);
EXPECT_TRUE(CreateAndSetCookie(cm_.get(), kHttpUrl, "cookie=chocolate_chip",
CookieOptions()));
}
TEST_F(CookieMonsterLegacyCookieAccessTest, GetLegacyNoSameSiteCookie) {
ASSERT_TRUE(CreateAndSetCookie(cm_.get(), kHttpUrl, "cookie=chocolate_chip",
CookieOptions::MakeAllInclusive()));
access_delegate_->SetExpectationForCookieDomain(
kDomain, CookieAccessSemantics::UNKNOWN);
EXPECT_EQ("", GetCookiesWithOptions(cm_.get(), kHttpUrl, CookieOptions()));
access_delegate_->SetExpectationForCookieDomain(
kDomain, CookieAccessSemantics::NONLEGACY);
EXPECT_EQ("", GetCookiesWithOptions(cm_.get(), kHttpUrl, CookieOptions()));
access_delegate_->SetExpectationForCookieDomain(
kDomain, CookieAccessSemantics::LEGACY);
EXPECT_EQ("cookie=chocolate_chip",
GetCookiesWithOptions(cm_.get(), kHttpUrl, CookieOptions()));
}
TEST_F(CookieMonsterLegacyCookieAccessTest,
SetLegacySameSiteNoneInsecureCookie) {
access_delegate_->SetExpectationForCookieDomain(
kDomain, CookieAccessSemantics::UNKNOWN);
EXPECT_FALSE(CreateAndSetCookie(cm_.get(), kHttpsUrl,
"cookie=oatmeal_raisin; SameSite=None",
CookieOptions()));
access_delegate_->SetExpectationForCookieDomain(
kDomain, CookieAccessSemantics::NONLEGACY);
EXPECT_FALSE(CreateAndSetCookie(cm_.get(), kHttpsUrl,
"cookie=oatmeal_raisin; SameSite=None",
CookieOptions()));
access_delegate_->SetExpectationForCookieDomain(
kDomain, CookieAccessSemantics::LEGACY);
EXPECT_TRUE(CreateAndSetCookie(cm_.get(), kHttpsUrl,
"cookie=oatmeal_raisin; SameSite=None",
CookieOptions()));
EXPECT_EQ("cookie=oatmeal_raisin",
GetCookiesWithOptions(cm_.get(), kHttpsUrl, CookieOptions()));
}
TEST_F(CookieMonsterLegacyCookieAccessTest,
GetLegacySameSiteNoneInsecureCookie) {
access_delegate_->SetExpectationForCookieDomain(
kDomain, CookieAccessSemantics::LEGACY);
ASSERT_TRUE(CreateAndSetCookie(cm_.get(), kHttpUrl,
"cookie=oatmeal_raisin; SameSite=None",
CookieOptions::MakeAllInclusive()));
access_delegate_->SetExpectationForCookieDomain(
kDomain, CookieAccessSemantics::UNKNOWN);
EXPECT_EQ("", GetCookiesWithOptions(cm_.get(), kHttpUrl, CookieOptions()));
access_delegate_->SetExpectationForCookieDomain(
kDomain, CookieAccessSemantics::NONLEGACY);
EXPECT_EQ("", GetCookiesWithOptions(cm_.get(), kHttpUrl, CookieOptions()));
access_delegate_->SetExpectationForCookieDomain(
kDomain, CookieAccessSemantics::LEGACY);
EXPECT_EQ("cookie=oatmeal_raisin",
GetCookiesWithOptions(cm_.get(), kHttpUrl, CookieOptions()));
}
TEST_F(CookieMonsterTest, IsCookieSentToSamePortThatSetIt) {
ASSERT_EQ(CookieMonster::IsCookieSentToSamePortThatSetIt(
GURL("https://foo.com"), url::PORT_UNSPECIFIED,
CookieSourceScheme::kSecure),
CookieMonster::CookieSentToSamePort::kSourcePortUnspecified);
ASSERT_EQ(CookieMonster::IsCookieSentToSamePortThatSetIt(
GURL("https://foo.com"), url::PORT_INVALID,
CookieSourceScheme::kSecure),
CookieMonster::CookieSentToSamePort::kInvalid);
ASSERT_EQ(CookieMonster::IsCookieSentToSamePortThatSetIt(
GURL("https://foo.com"), 443, CookieSourceScheme::kSecure),
CookieMonster::CookieSentToSamePort::kYes);
ASSERT_EQ(
CookieMonster::IsCookieSentToSamePortThatSetIt(
GURL("https://foo.com:1234"), 1234, CookieSourceScheme::kSecure),
CookieMonster::CookieSentToSamePort::kYes);
ASSERT_EQ(CookieMonster::IsCookieSentToSamePortThatSetIt(
GURL("https://foo.com"), 80, CookieSourceScheme::kNonSecure),
CookieMonster::CookieSentToSamePort::kNoButDefault);
ASSERT_EQ(
CookieMonster::IsCookieSentToSamePortThatSetIt(
GURL("https://foo.com:443"), 80, CookieSourceScheme::kNonSecure),
CookieMonster::CookieSentToSamePort::kNoButDefault);
ASSERT_EQ(CookieMonster::IsCookieSentToSamePortThatSetIt(
GURL("wss://foo.com"), 80, CookieSourceScheme::kNonSecure),
CookieMonster::CookieSentToSamePort::kNoButDefault);
ASSERT_EQ(CookieMonster::IsCookieSentToSamePortThatSetIt(
GURL("http://foo.com"), 443, CookieSourceScheme::kSecure),
CookieMonster::CookieSentToSamePort::kNoButDefault);
ASSERT_EQ(CookieMonster::IsCookieSentToSamePortThatSetIt(
GURL("ws://foo.com"), 443, CookieSourceScheme::kSecure),
CookieMonster::CookieSentToSamePort::kNoButDefault);
ASSERT_EQ(CookieMonster::IsCookieSentToSamePortThatSetIt(
GURL("http://foo.com:9000"), 85, CookieSourceScheme::kSecure),
CookieMonster::CookieSentToSamePort::kNo);
ASSERT_EQ(CookieMonster::IsCookieSentToSamePortThatSetIt(
GURL("https://foo.com"), 80, CookieSourceScheme::kSecure),
CookieMonster::CookieSentToSamePort::kNo);
ASSERT_EQ(CookieMonster::IsCookieSentToSamePortThatSetIt(
GURL("wss://foo.com"), 80, CookieSourceScheme::kSecure),
CookieMonster::CookieSentToSamePort::kNo);
ASSERT_EQ(CookieMonster::IsCookieSentToSamePortThatSetIt(
GURL("http://foo.com"), 443, CookieSourceScheme::kNonSecure),
CookieMonster::CookieSentToSamePort::kNo);
ASSERT_EQ(CookieMonster::IsCookieSentToSamePortThatSetIt(
GURL("ws://foo.com"), 443, CookieSourceScheme::kNonSecure),
CookieMonster::CookieSentToSamePort::kNo);
ASSERT_EQ(CookieMonster::IsCookieSentToSamePortThatSetIt(
GURL("http://foo.com:444"), 443, CookieSourceScheme::kSecure),
CookieMonster::CookieSentToSamePort::kNo);
}
TEST_F(CookieMonsterTest, CookieDomainSetHistogram) {
base::MetricsSubSampler::ScopedAlwaysSampleForTesting always_sample;
base::HistogramTester histograms;
const char kHistogramName[] = "Cookie.DomainSet.Subsampled";
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
histograms.ExpectTotalCount(kHistogramName, 0);
EXPECT_TRUE(SetCookie(cm.get(), https_www_foo_.url(), "A=B"));
histograms.ExpectTotalCount(kHistogramName, 1);
histograms.ExpectBucketCount(kHistogramName, false, 1);
EXPECT_TRUE(SetCookie(cm.get(), https_www_foo_.url(),
"A=B; Domain=" + https_www_foo_.host()));
histograms.ExpectTotalCount(kHistogramName, 2);
histograms.ExpectBucketCount(kHistogramName, true, 1);
EXPECT_FALSE(
SetCookie(cm.get(), https_www_foo_.url(), "A=B; Domain=other.com"));
histograms.ExpectTotalCount(kHistogramName, 2);
histograms.ExpectBucketCount(kHistogramName, false, 1);
}
TEST_F(CookieMonsterTest, CookiePortReadHistogram) {
base::MetricsSubSampler::ScopedAlwaysSampleForTesting always_sample;
base::HistogramTester histograms;
const char kHistogramName[] = "Cookie.Port.Read.RemoteHost.Subsampled";
const char kHistogramNameLocal[] = "Cookie.Port.Read.Localhost.Subsampled";
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
histograms.ExpectTotalCount(kHistogramName, 0);
EXPECT_TRUE(SetCookie(cm.get(), GURL("https://www.foo.com"), "A=B"));
histograms.ExpectTotalCount(kHistogramName, 0);
EXPECT_EQ(GetCookies(cm.get(), GURL("https://www.foo.com")), "A=B");
histograms.ExpectTotalCount(kHistogramName, 1);
histograms.ExpectBucketCount(kHistogramName,
ReducePortRangeForCookieHistogram(443), 1);
EXPECT_EQ(GetCookies(cm.get(), GURL("https://www.foo.com:82")), "A=B");
histograms.ExpectTotalCount(kHistogramName, 2);
histograms.ExpectBucketCount(kHistogramName,
ReducePortRangeForCookieHistogram(82), 1);
EXPECT_EQ(GetCookies(cm.get(), GURL("https://www.foo.com:8080")), "A=B");
histograms.ExpectTotalCount(kHistogramName, 3);
histograms.ExpectBucketCount(kHistogramName,
ReducePortRangeForCookieHistogram(8080), 1);
EXPECT_EQ(GetCookies(cm.get(), GURL("https://www.foo.com:1234")), "A=B");
histograms.ExpectTotalCount(kHistogramName, 4);
histograms.ExpectBucketCount(kHistogramName,
ReducePortRangeForCookieHistogram(1234), 1);
EXPECT_EQ(GetCookies(cm.get(), GURL("https://www.other.com")), "");
histograms.ExpectTotalCount(kHistogramName, 4);
EXPECT_TRUE(SetCookie(cm.get(), GURL("https://localhost"), "local=host"));
histograms.ExpectTotalCount(kHistogramNameLocal, 0);
EXPECT_EQ(GetCookies(cm.get(), GURL("https://localhost:82")), "local=host");
histograms.ExpectTotalCount(kHistogramNameLocal, 1);
histograms.ExpectBucketCount(kHistogramNameLocal,
ReducePortRangeForCookieHistogram(82), 1);
}
TEST_F(CookieMonsterTest, CookiePortSetHistogram) {
base::MetricsSubSampler::ScopedAlwaysSampleForTesting always_sample;
base::HistogramTester histograms;
const char kHistogramName[] = "Cookie.Port.Set.RemoteHost.Subsampled";
const char kHistogramNameLocal[] = "Cookie.Port.Set.Localhost.Subsampled";
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
histograms.ExpectTotalCount(kHistogramName, 0);
EXPECT_TRUE(SetCookie(cm.get(), GURL("https://www.foo.com"), "A=B"));
histograms.ExpectTotalCount(kHistogramName, 1);
histograms.ExpectBucketCount(kHistogramName,
ReducePortRangeForCookieHistogram(443), 1);
EXPECT_TRUE(SetCookie(cm.get(), GURL("https://www.foo.com:80"), "A=B"));
histograms.ExpectTotalCount(kHistogramName, 2);
histograms.ExpectBucketCount(kHistogramName,
ReducePortRangeForCookieHistogram(80), 1);
EXPECT_TRUE(SetCookie(cm.get(), GURL("https://www.foo.com:9000"), "A=B"));
histograms.ExpectTotalCount(kHistogramName, 3);
histograms.ExpectBucketCount(kHistogramName,
ReducePortRangeForCookieHistogram(9000), 1);
EXPECT_TRUE(SetCookie(cm.get(), GURL("https://www.foo.com:1234"), "A=B"));
histograms.ExpectTotalCount(kHistogramName, 4);
histograms.ExpectBucketCount(kHistogramName,
ReducePortRangeForCookieHistogram(1234), 1);
EXPECT_FALSE(SetCookie(cm.get(), GURL("https://www.foo.com"),
"A=B; Domain=malformedcookie.com"));
histograms.ExpectTotalCount(kHistogramName, 4);
EXPECT_NE(GetCookies(cm.get(), GURL("https://www.foo.com")), "");
histograms.ExpectTotalCount(kHistogramName, 4);
histograms.ExpectTotalCount(kHistogramNameLocal, 0);
EXPECT_TRUE(
SetCookie(cm.get(), GURL("https://localhost:1234"), "local=host"));
histograms.ExpectTotalCount(kHistogramNameLocal, 1);
histograms.ExpectBucketCount(kHistogramNameLocal,
ReducePortRangeForCookieHistogram(1234), 1);
}
TEST_F(CookieMonsterTest, CookiePortReadDiffersFromSetHistogram) {
base::MetricsSubSampler::ScopedAlwaysSampleForTesting always_sample;
base::HistogramTester histograms;
const char kHistogramName[] =
"Cookie.Port.ReadDiffersFromSet.RemoteHost.Subsampled";
const char kHistogramNameLocal[] =
"Cookie.Port.ReadDiffersFromSet.Localhost.Subsampled";
const char kHistogramNameDomainSet[] =
"Cookie.Port.ReadDiffersFromSet.DomainSet.Subsampled";
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
histograms.ExpectTotalCount(kHistogramName, 0);
EXPECT_TRUE(SetCookie(cm.get(), GURL("https://www.foo.com/withport"),
"A=B; Path=/withport"));
auto unspecified_cookie = CanonicalCookie::CreateForTesting(
GURL("https://www.foo.com/withoutport"), "C=D; Path=/withoutport",
base::Time::Now());
unspecified_cookie->SetSourcePort(url::PORT_UNSPECIFIED);
EXPECT_TRUE(SetCanonicalCookieReturnAccessResult(
cm.get(), std::move(unspecified_cookie),
GURL("https://www.foo.com/withoutport"),
false )
.status.IsInclude());
auto invalid_cookie = CanonicalCookie::CreateForTesting(
GURL("https://www.foo.com/invalidport"), "E=F; Path=/invalidport",
base::Time::Now());
invalid_cookie->SetSourcePort(99999);
EXPECT_TRUE(SetCanonicalCookieReturnAccessResult(
cm.get(), std::move(invalid_cookie),
GURL("https://www.foo.com/invalidport"),
false )
.status.IsInclude());
EXPECT_EQ(GetCookies(cm.get(), GURL("https://www.foo.com/withport")), "A=B");
histograms.ExpectTotalCount(kHistogramName, 1);
histograms.ExpectBucketCount(kHistogramName,
CookieMonster::CookieSentToSamePort::kYes, 1);
EXPECT_EQ(GetCookies(cm.get(), GURL("https://www.foo.com:8080/withport")),
"A=B");
histograms.ExpectTotalCount(kHistogramName, 2);
histograms.ExpectBucketCount(kHistogramName,
CookieMonster::CookieSentToSamePort::kNo, 1);
EXPECT_EQ(GetCookies(cm.get(), GURL("http://www.foo.com/withport")), "A=B");
histograms.ExpectTotalCount(kHistogramName, 3);
histograms.ExpectBucketCount(
kHistogramName, CookieMonster::CookieSentToSamePort::kNoButDefault, 1);
EXPECT_EQ(GetCookies(cm.get(), GURL("http://www.foo.com/withoutport")),
"C=D");
histograms.ExpectTotalCount(kHistogramName, 4);
histograms.ExpectBucketCount(
kHistogramName,
CookieMonster::CookieSentToSamePort::kSourcePortUnspecified, 1);
EXPECT_EQ(GetCookies(cm.get(), GURL("http://www.foo.com/invalidport")),
"E=F");
histograms.ExpectTotalCount(kHistogramName, 5);
histograms.ExpectBucketCount(
kHistogramName, CookieMonster::CookieSentToSamePort::kInvalid, 1);
histograms.ExpectTotalCount(kHistogramNameLocal, 0);
EXPECT_TRUE(SetCookie(cm.get(), GURL("https://localhost"), "local=host"));
EXPECT_EQ(GetCookies(cm.get(), GURL("https://localhost")), "local=host");
histograms.ExpectTotalCount(kHistogramNameLocal, 1);
histograms.ExpectBucketCount(kHistogramNameLocal,
CookieMonster::CookieSentToSamePort::kYes, 1);
EXPECT_TRUE(SetCookie(cm.get(), GURL("https://www.foo.com/withDomain"),
"W=D; Domain=foo.com; Path=/withDomain"));
histograms.ExpectTotalCount(kHistogramNameDomainSet, 0);
EXPECT_EQ(GetCookies(cm.get(), GURL("https://www.foo.com/withDomain")),
"W=D");
histograms.ExpectTotalCount(kHistogramNameDomainSet, 1);
histograms.ExpectBucketCount(kHistogramNameDomainSet,
CookieMonster::CookieSentToSamePort::kYes, 1);
histograms.ExpectTotalCount(kHistogramName, 6);
histograms.ExpectBucketCount(kHistogramName,
CookieMonster::CookieSentToSamePort::kYes, 2);
}
TEST_F(CookieMonsterTest, CookieSourceSchemeNameHistogram) {
base::MetricsSubSampler::ScopedAlwaysSampleForTesting always_sample;
base::HistogramTester histograms;
const char kHistogramName[] = "Cookie.CookieSourceSchemeName.Subsampled";
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
histograms.ExpectTotalCount(kHistogramName, 0);
struct TestCase {
CookieSourceSchemeName enum_value;
std::string scheme;
};
const TestCase kTestCases[] = {
{CookieSourceSchemeName::kHttpsScheme, url::kHttpsScheme},
{CookieSourceSchemeName::kHttpScheme, url::kHttpScheme},
{CookieSourceSchemeName::kWssScheme, url::kWssScheme},
{CookieSourceSchemeName::kWsScheme, url::kWsScheme},
{CookieSourceSchemeName::kChromeExtensionScheme, "chrome-extension"},
{CookieSourceSchemeName::kFileScheme, url::kFileScheme},
{CookieSourceSchemeName::kOther, "abcd1234"}};
std::vector<std::string> schemes;
for (auto test_case : kTestCases) {
schemes.push_back(test_case.scheme);
}
ResultSavingCookieCallback<bool> cookie_scheme_callback;
cm->SetCookieableSchemes(schemes, cookie_scheme_callback.MakeCallback());
cookie_scheme_callback.WaitUntilDone();
ASSERT_TRUE(cookie_scheme_callback.result());
const char kUrl[] = "://www.foo.com";
int count = 0;
for (auto test_case : kTestCases) {
histograms.ExpectBucketCount(kHistogramName, test_case.enum_value, 0);
EXPECT_TRUE(SetCookie(cm.get(), GURL(test_case.scheme + kUrl), "A=B"));
histograms.ExpectBucketCount(kHistogramName, test_case.enum_value, 1);
histograms.ExpectTotalCount(kHistogramName, ++count);
}
EXPECT_FALSE(SetCookie(cm.get(), GURL("invalidscheme://foo.com"), "A=B"));
histograms.ExpectTotalCount(kHistogramName, count);
}
class FirstPartySetEnabledCookieMonsterTest : public CookieMonsterTest {
public:
FirstPartySetEnabledCookieMonsterTest()
: cm_(nullptr , nullptr
) {
std::unique_ptr<TestCookieAccessDelegate> access_delegate =
std::make_unique<TestCookieAccessDelegate>();
access_delegate_ = access_delegate.get();
cm_.SetCookieAccessDelegate(std::move(access_delegate));
}
~FirstPartySetEnabledCookieMonsterTest() override = default;
CookieMonster* cm() { return &cm_; }
protected:
CookieMonster cm_;
raw_ptr<TestCookieAccessDelegate> access_delegate_;
};
TEST_F(FirstPartySetEnabledCookieMonsterTest, RecordsPeriodicFPSSizes) {
net::SchemefulSite owner1(GURL("https://owner1.test"));
net::SchemefulSite owner2(GURL("https://owner2.test"));
net::SchemefulSite member1(GURL("https://member1.test"));
net::SchemefulSite member2(GURL("https://member2.test"));
net::SchemefulSite member3(GURL("https://member3.test"));
net::SchemefulSite member4(GURL("https://member4.test"));
access_delegate_->SetFirstPartySets({
{owner1, net::FirstPartySetEntry(owner1, net::SiteType::kPrimary)},
{member1, net::FirstPartySetEntry(owner1, net::SiteType::kAssociated)},
{member2, net::FirstPartySetEntry(owner1, net::SiteType::kAssociated)},
{owner2, net::FirstPartySetEntry(owner2, net::SiteType::kPrimary)},
{member3, net::FirstPartySetEntry(owner2, net::SiteType::kAssociated)},
{member4, net::FirstPartySetEntry(owner2, net::SiteType::kAssociated)},
});
ASSERT_TRUE(SetCookie(cm(), GURL("https://owner1.test"), kValidCookieLine));
ASSERT_TRUE(SetCookie(cm(), GURL("https://subdomain.member1.test"),
kValidCookieLine));
ASSERT_TRUE(SetCookie(cm(), GURL("https://member2.test"), kValidCookieLine));
ASSERT_TRUE(
SetCookie(cm(), GURL("https://subdomain.owner2.test"), kValidCookieLine));
ASSERT_TRUE(SetCookie(cm(), GURL("https://member3.test"), kValidCookieLine));
ASSERT_TRUE(
SetCookie(cm(), GURL("https://unrelated1.test"), kValidCookieLine));
ASSERT_TRUE(
SetCookie(cm(), GURL("https://unrelated2.test"), kValidCookieLine));
ASSERT_TRUE(
SetCookie(cm(), GURL("https://unrelated3.test"), kValidCookieLine));
base::HistogramTester histogram_tester;
EXPECT_TRUE(cm()->DoRecordPeriodicStatsForTesting());
EXPECT_THAT(histogram_tester.GetAllSamples("Cookie.PerFirstPartySetCount"),
testing::ElementsAre(
base::Bucket(2 , 1 ),
base::Bucket(3 , 1 )));
}
TEST_F(CookieMonsterTest, GetAllCookiesForURLNonce) {
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
CookieOptions options = CookieOptions::MakeAllInclusive();
auto anonymous_iframe_key = CookiePartitionKey::FromURLForTesting(
GURL("https://anonymous-iframe.test"),
CookiePartitionKey::AncestorChainBit::kCrossSite,
base::UnguessableToken::Create());
EXPECT_TRUE(CreateAndSetCookie(cm.get(), https_www_foo_.url(),
"A=0; Secure; HttpOnly; Path=/;", options));
EXPECT_TRUE(CreateAndSetCookie(cm.get(), https_www_foo_.url(),
"__Host-B=0; Secure; HttpOnly; Path=/;",
options));
EXPECT_TRUE(CreateAndSetCookie(
cm.get(), https_www_foo_.url(),
"__Host-B=1; Secure; HttpOnly; Path=/; Partitioned", options,
std::nullopt, std::nullopt, anonymous_iframe_key));
EXPECT_TRUE(CreateAndSetCookie(
cm.get(), https_www_foo_.url(),
"__Host-C=0; Secure; HttpOnly; Path=/; Partitioned", options,
std::nullopt, std::nullopt, anonymous_iframe_key));
EXPECT_THAT(GetAllCookiesForURL(cm.get(), https_www_foo_.url()),
ElementsAre(MatchesCookieNameValue("A", "0"),
MatchesCookieNameValue("__Host-B", "0")));
EXPECT_THAT(
GetAllCookiesForURL(cm.get(), https_www_foo_.url(),
CookiePartitionKeyCollection(anonymous_iframe_key)),
ElementsAre(MatchesCookieNameValue("__Host-B", "1"),
MatchesCookieNameValue("__Host-C", "0")));
EXPECT_THAT(GetExcludedCookiesForURL(
cm.get(), https_www_foo_.url(),
CookiePartitionKeyCollection(anonymous_iframe_key)),
testing::UnorderedElementsAre(
MatchesCookieWithAccessResult(
MatchesCookieWithName("A"),
MatchesCookieAccessResult(
HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_ANONYMOUS_CONTEXT}),
_, _, _)),
MatchesCookieWithAccessResult(
MatchesCookieWithName("__Host-B"),
MatchesCookieAccessResult(
HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::
EXCLUDE_ANONYMOUS_CONTEXT}),
_, _, _))));
}
TEST_F(CookieMonsterTest, SiteHasCookieInOtherPartition) {
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
CookieOptions options = CookieOptions::MakeAllInclusive();
GURL url("https://subdomain.example.com/");
net::SchemefulSite site(url);
auto partition_key =
CookiePartitionKey::FromURLForTesting(GURL("https://toplevelsite.com"));
EXPECT_FALSE(cm->SiteHasCookieInOtherPartition(site, partition_key));
GetAllCookiesForURL(cm.get(), url,
CookiePartitionKeyCollection::ContainsAll());
EXPECT_THAT(cm->SiteHasCookieInOtherPartition(site, partition_key),
testing::Optional(false));
EXPECT_TRUE(CreateAndSetCookie(
cm.get(), url, "foo=bar; Secure; SameSite=None; Partitioned", options,
std::nullopt, std::nullopt, partition_key));
EXPECT_THAT(cm->SiteHasCookieInOtherPartition(site, partition_key),
testing::Optional(false));
auto other_partition_key = CookiePartitionKey::FromURLForTesting(
GURL("https://nottoplevelsite.com"));
EXPECT_THAT(cm->SiteHasCookieInOtherPartition(site, other_partition_key),
testing::Optional(true));
EXPECT_TRUE(CreateAndSetCookie(
cm.get(), url, "foo=bar; Secure; SameSite=None; Partitioned", options,
std::nullopt, std::nullopt,
CookiePartitionKey::FromURLForTesting(
GURL("https://nottoplevelsite.com"),
CookiePartitionKey::AncestorChainBit::kCrossSite,
base::UnguessableToken::Create())));
EXPECT_THAT(cm->SiteHasCookieInOtherPartition(site, partition_key),
testing::Optional(false));
EXPECT_TRUE(CreateAndSetCookie(cm.get(), url,
"bar=baz; Secure; SameSite=None;", options,
std::nullopt, std::nullopt));
EXPECT_THAT(cm->SiteHasCookieInOtherPartition(site, partition_key),
testing::Optional(false));
}
TEST_F(CookieMonsterTest, FilterCookiesWithOptionsExcludeShadowingDomains) {
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
base::Time creation_time = base::Time::Now();
std::optional<base::Time> server_time = std::nullopt;
CookieOptions options = CookieOptions::MakeAllInclusive();
options.set_return_excluded_cookies();
auto CookieListsMatch = [](const CookieAccessResultList& actual,
const CookieList& expected) {
if (actual.size() != expected.size()) {
return false;
}
for (size_t i = 0; i < actual.size(); i++) {
if (!actual[i].cookie.IsEquivalent(expected[i])) {
return false;
}
}
return true;
};
base::test::ScopedFeatureList scoped_feature_list;
scoped_feature_list.InitWithFeatures(
{net::features::kEnableSchemeBoundCookies},
{net::features::kEnablePortBoundCookies});
std::vector<CanonicalCookie*> cookie_ptrs;
CookieAccessResultList included;
CookieAccessResultList excluded;
auto reset = [&cookie_ptrs, &included, &excluded]() {
cookie_ptrs.clear();
included.clear();
excluded.clear();
};
auto origin_cookie1 = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "foo1=origin", creation_time, server_time);
auto origin_cookie2 = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "foo2=origin", creation_time, server_time);
auto domain_cookie1 = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "foo1=domain; Domain=" + https_www_foo_.domain(),
creation_time, server_time);
cookie_ptrs = {origin_cookie1.get(), origin_cookie2.get(),
domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, {*origin_cookie1, *origin_cookie2}));
EXPECT_TRUE(CookieListsMatch(excluded, {*domain_cookie1}));
reset();
cookie_ptrs = {domain_cookie1.get(), origin_cookie2.get(),
origin_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, {*origin_cookie2, *origin_cookie1}));
EXPECT_TRUE(CookieListsMatch(excluded, {*domain_cookie1}));
reset();
auto domain_cookie2 = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "foo2=domain; Domain=" + https_www_foo_.domain(),
creation_time, server_time);
cookie_ptrs = {domain_cookie1.get(), origin_cookie2.get(),
origin_cookie1.get(), domain_cookie2.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, {*origin_cookie2, *origin_cookie1}));
EXPECT_TRUE(CookieListsMatch(excluded, {*domain_cookie1, *domain_cookie2}));
reset();
auto domain_cookie3 = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "foo3=domain; Domain=" + https_www_foo_.domain(),
creation_time, server_time);
cookie_ptrs = {domain_cookie1.get(), origin_cookie2.get(),
origin_cookie1.get(), domain_cookie2.get(),
domain_cookie3.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(
included, {*origin_cookie2, *origin_cookie1, *domain_cookie3}));
EXPECT_TRUE(CookieListsMatch(excluded, {*domain_cookie1, *domain_cookie2}));
reset();
auto sub_domain_cookie1 = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "foo1=subdomain; Domain=" + https_www_foo_.host(),
creation_time, server_time);
cookie_ptrs = {domain_cookie1.get(), origin_cookie2.get(),
origin_cookie1.get(), sub_domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, {*origin_cookie2, *origin_cookie1}));
EXPECT_TRUE(
CookieListsMatch(excluded, {*domain_cookie1, *sub_domain_cookie1}));
reset();
cookie_ptrs = {domain_cookie1.get(), sub_domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(
CookieListsMatch(included, {*domain_cookie1, *sub_domain_cookie1}));
EXPECT_TRUE(CookieListsMatch(excluded, {}));
reset();
auto path_origin_cookie1 = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "foo1=pathorigin; Path=/bar", creation_time,
server_time);
cookie_ptrs = {path_origin_cookie1.get(), domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, {}));
EXPECT_TRUE(
CookieListsMatch(excluded, {*path_origin_cookie1, *domain_cookie1}));
reset();
auto insecure_origin_cookie1 = CanonicalCookie::CreateForTesting(
http_www_foo_.url(), "foo1=insecureorigin", creation_time, server_time);
EXPECT_EQ(insecure_origin_cookie1->SourceScheme(),
CookieSourceScheme::kNonSecure);
cookie_ptrs = {insecure_origin_cookie1.get(), domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, {*domain_cookie1}));
EXPECT_TRUE(CookieListsMatch(excluded, {*insecure_origin_cookie1}));
EXPECT_TRUE(
excluded[0].access_result.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_SCHEME_MISMATCH}));
reset();
auto insecure_domain_cookie1 = CanonicalCookie::CreateForTesting(
http_www_foo_.url(),
"foo1=insecuredomain; Domain=" + http_www_foo_.domain(), creation_time,
server_time);
cookie_ptrs = {origin_cookie1.get(), insecure_domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, {*origin_cookie1}));
EXPECT_TRUE(CookieListsMatch(excluded, {*insecure_domain_cookie1}));
EXPECT_TRUE(
excluded[0].access_result.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_SCHEME_MISMATCH}));
reset();
cookie_ptrs = {insecure_origin_cookie1.get(), insecure_domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, {}));
EXPECT_TRUE(CookieListsMatch(
excluded, {*insecure_origin_cookie1, *insecure_domain_cookie1}));
EXPECT_TRUE(
excluded[1].access_result.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_SCHEME_MISMATCH}));
reset();
cm->SetCookieAccessDelegate(std::make_unique<TestCookieAccessDelegate>());
CookieURLHelper http_www_trustworthy =
CookieURLHelper("http://www.trustworthysitefortestdelegate.example");
CookieURLHelper https_www_trustworthy =
CookieURLHelper("https://www.trustworthysitefortestdelegate.example");
auto trust_origin_cookie1 = CanonicalCookie::CreateForTesting(
http_www_trustworthy.url(), "foo1=trustorigin", creation_time,
server_time);
auto secure_trust_domain_cookie1 = CanonicalCookie::CreateForTesting(
https_www_trustworthy.url(),
"foo1=securetrustdomain; Domain=" + https_www_trustworthy.domain(),
creation_time, server_time);
auto secure_trust_domain_cookie2 = CanonicalCookie::CreateForTesting(
https_www_trustworthy.url(),
"foo2=securetrustdomain; Domain=" + https_www_trustworthy.domain(),
creation_time, server_time);
cookie_ptrs = {trust_origin_cookie1.get(), secure_trust_domain_cookie1.get(),
secure_trust_domain_cookie2.get()};
cm->FilterCookiesWithOptions(http_www_trustworthy.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(
included, {*trust_origin_cookie1, *secure_trust_domain_cookie2}));
EXPECT_TRUE(CookieListsMatch(excluded, {*secure_trust_domain_cookie1}));
reset();
auto trust_domain_cookie1 = CanonicalCookie::CreateForTesting(
http_www_trustworthy.url(),
"foo1=trustdomain; Domain=" + http_www_trustworthy.domain(),
creation_time, server_time);
auto trust_domain_cookie2 = CanonicalCookie::CreateForTesting(
http_www_trustworthy.url(),
"foo2=trustdomain; Domain=" + http_www_trustworthy.domain(),
creation_time, server_time);
auto secure_trust_origin_cookie1 = CanonicalCookie::CreateForTesting(
https_www_trustworthy.url(), "foo1=securetrustorigin", creation_time,
server_time);
cookie_ptrs = {secure_trust_origin_cookie1.get(), trust_domain_cookie1.get(),
trust_domain_cookie2.get()};
cm->FilterCookiesWithOptions(http_www_trustworthy.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(
included, {*secure_trust_origin_cookie1, *trust_domain_cookie2}));
EXPECT_TRUE(CookieListsMatch(excluded, {*trust_domain_cookie1}));
reset();
auto port_origin_cookie1 = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "foo1=differentportorigin", creation_time,
server_time);
port_origin_cookie1->SetSourcePort(123);
cookie_ptrs = {port_origin_cookie1.get(), domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(
CookieListsMatch(included, {*port_origin_cookie1, *domain_cookie1}));
EXPECT_TRUE(included[0].access_result.status.HasWarningReason(
CookieInclusionStatus::WarningReason::WARN_PORT_MISMATCH));
reset();
auto port_insecure_origin_cookie1 =
std::make_unique<CanonicalCookie>(*insecure_origin_cookie1);
port_insecure_origin_cookie1->SetSourcePort(123);
cookie_ptrs = {port_insecure_origin_cookie1.get(), domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, {*domain_cookie1}));
EXPECT_TRUE(
excluded[0].access_result.status.HasExactlyWarningReasonsForTesting(
{CookieInclusionStatus::WarningReason::WARN_PORT_MISMATCH}));
EXPECT_TRUE(
excluded[0].access_result.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_SCHEME_MISMATCH}));
reset();
scoped_feature_list.Reset();
scoped_feature_list.InitWithFeatures(
{net::features::kEnableSchemeBoundCookies,
net::features::kEnablePortBoundCookies},
{});
cookie_ptrs = {port_origin_cookie1.get(), domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, {*domain_cookie1}));
EXPECT_TRUE(CookieListsMatch(excluded, {*port_origin_cookie1}));
EXPECT_TRUE(
excluded[0].access_result.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_PORT_MISMATCH}));
reset();
cookie_ptrs = {port_insecure_origin_cookie1.get(), domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, {*domain_cookie1}));
EXPECT_TRUE(CookieListsMatch(excluded, {*port_insecure_origin_cookie1}));
EXPECT_TRUE(
excluded[0].access_result.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_SCHEME_MISMATCH,
CookieInclusionStatus::ExclusionReason::EXCLUDE_PORT_MISMATCH}));
reset();
}
TEST_F(CookieMonsterTest, FilterCookiesWithOptionsWarnShadowingDomains) {
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cm = std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
base::Time creation_time = base::Time::Now();
std::optional<base::Time> server_time = std::nullopt;
CookieOptions options = CookieOptions::MakeAllInclusive();
options.set_return_excluded_cookies();
auto CookieListsMatch = [](const CookieAccessResultList& actual,
const std::vector<CanonicalCookie*>& expected) {
if (actual.size() != expected.size()) {
return false;
}
for (size_t i = 0; i < actual.size(); i++) {
if (!actual[i].cookie.IsEquivalent(*expected[i])) {
return false;
}
}
return true;
};
auto DomainCookiesHaveWarnings =
[](const CookieAccessResultList& actual,
const std::vector<CanonicalCookie>& expected) {
std::map<CanonicalCookie, CookieInclusionStatus> cookie_result_map;
for (const auto& cookie_result : actual) {
cookie_result_map.insert(
{cookie_result.cookie, cookie_result.access_result.status});
}
for (const auto& cookie : expected) {
if (!cookie_result_map[cookie].HasWarningReason(
CookieInclusionStatus::WarningReason::
WARN_SHADOWING_DOMAIN)) {
return false;
}
cookie_result_map.erase(cookie);
}
for (const auto& item : cookie_result_map) {
if (item.second.HasWarningReason(
CookieInclusionStatus::WarningReason::
WARN_SHADOWING_DOMAIN)) {
return false;
}
}
return true;
};
base::test::ScopedFeatureList scoped_feature_list;
scoped_feature_list.InitWithFeatures(
{}, {net::features::kEnableSchemeBoundCookies,
net::features::kEnablePortBoundCookies});
std::vector<CanonicalCookie*> cookie_ptrs;
CookieAccessResultList included;
CookieAccessResultList excluded;
auto reset = [&cookie_ptrs, &included, &excluded]() {
cookie_ptrs.clear();
included.clear();
excluded.clear();
};
auto origin_cookie1 = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "foo1=origin", creation_time, server_time);
auto origin_cookie2 = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "foo2=origin", creation_time, server_time);
auto domain_cookie1 = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "foo1=domain; Domain=" + https_www_foo_.domain(),
creation_time, server_time);
cookie_ptrs = {origin_cookie1.get(), origin_cookie2.get(),
domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, cookie_ptrs));
EXPECT_TRUE(DomainCookiesHaveWarnings(included, {*domain_cookie1}));
reset();
cookie_ptrs = {domain_cookie1.get(), origin_cookie2.get(),
origin_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, cookie_ptrs));
EXPECT_TRUE(DomainCookiesHaveWarnings(included, {*domain_cookie1}));
reset();
auto domain_cookie2 = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "foo2=domain; Domain=" + https_www_foo_.domain(),
creation_time, server_time);
cookie_ptrs = {domain_cookie1.get(), origin_cookie2.get(),
origin_cookie1.get(), domain_cookie2.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, cookie_ptrs));
EXPECT_TRUE(
DomainCookiesHaveWarnings(included, {*domain_cookie1, *domain_cookie2}));
reset();
auto domain_cookie3 = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "foo3=domain; Domain=" + https_www_foo_.domain(),
creation_time, server_time);
cookie_ptrs = {domain_cookie1.get(), origin_cookie2.get(),
origin_cookie1.get(), domain_cookie2.get(),
domain_cookie3.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, cookie_ptrs));
EXPECT_TRUE(
DomainCookiesHaveWarnings(included, {*domain_cookie1, *domain_cookie2}));
reset();
auto sub_domain_cookie1 = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "foo1=subdomain; Domain=" + https_www_foo_.host(),
creation_time, server_time);
cookie_ptrs = {domain_cookie1.get(), origin_cookie2.get(),
origin_cookie1.get(), sub_domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, cookie_ptrs));
EXPECT_TRUE(DomainCookiesHaveWarnings(
included, {*domain_cookie1, *sub_domain_cookie1}));
reset();
cookie_ptrs = {domain_cookie1.get(), sub_domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, cookie_ptrs));
EXPECT_TRUE(DomainCookiesHaveWarnings(included, {}));
reset();
auto path_origin_cookie1 = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "foo1=pathorigin; Path=/bar", creation_time,
server_time);
cookie_ptrs = {path_origin_cookie1.get(), domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, {domain_cookie1.get()}));
EXPECT_TRUE(DomainCookiesHaveWarnings(included, {*domain_cookie1}));
reset();
auto insecure_origin_cookie1 = CanonicalCookie::CreateForTesting(
http_www_foo_.url(), "foo1=insecureorigin", creation_time, server_time);
EXPECT_EQ(insecure_origin_cookie1->SourceScheme(),
CookieSourceScheme::kNonSecure);
cookie_ptrs = {insecure_origin_cookie1.get(), domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, cookie_ptrs));
EXPECT_TRUE(DomainCookiesHaveWarnings(included, {}));
EXPECT_TRUE(included[0].access_result.status.HasWarningReason(
CookieInclusionStatus::WarningReason::WARN_SCHEME_MISMATCH));
reset();
auto insecure_domain_cookie1 = CanonicalCookie::CreateForTesting(
http_www_foo_.url(),
"foo1=insecuredomain; Domain=" + http_www_foo_.domain(), creation_time,
server_time);
cookie_ptrs = {origin_cookie1.get(), insecure_domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, cookie_ptrs));
EXPECT_TRUE(DomainCookiesHaveWarnings(included, {}));
EXPECT_TRUE(
included[1].access_result.status.HasExactlyWarningReasonsForTesting(
{CookieInclusionStatus::WarningReason::WARN_SCHEME_MISMATCH}));
reset();
cookie_ptrs = {insecure_origin_cookie1.get(), insecure_domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, cookie_ptrs));
EXPECT_TRUE(DomainCookiesHaveWarnings(included, {}));
EXPECT_TRUE(included[0].access_result.status.HasWarningReason(
CookieInclusionStatus::WarningReason::WARN_SCHEME_MISMATCH));
EXPECT_TRUE(
included[1].access_result.status.HasExactlyWarningReasonsForTesting(
{CookieInclusionStatus::WarningReason::WARN_SCHEME_MISMATCH}));
reset();
cm->SetCookieAccessDelegate(std::make_unique<TestCookieAccessDelegate>());
CookieURLHelper http_www_trustworthy =
CookieURLHelper("http://www.trustworthysitefortestdelegate.example");
CookieURLHelper https_www_trustworthy =
CookieURLHelper("https://www.trustworthysitefortestdelegate.example");
auto trust_origin_cookie1 = CanonicalCookie::CreateForTesting(
http_www_trustworthy.url(), "foo1=trustorigin", creation_time,
server_time);
auto secure_trust_domain_cookie1 = CanonicalCookie::CreateForTesting(
https_www_trustworthy.url(),
"foo1=securetrustdomain; Domain=" + https_www_trustworthy.domain(),
creation_time, server_time);
auto secure_trust_domain_cookie2 = CanonicalCookie::CreateForTesting(
https_www_trustworthy.url(),
"foo2=securetrustdomain; Domain=" + https_www_trustworthy.domain(),
creation_time, server_time);
cookie_ptrs = {trust_origin_cookie1.get(), secure_trust_domain_cookie1.get(),
secure_trust_domain_cookie2.get()};
cm->FilterCookiesWithOptions(http_www_trustworthy.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, cookie_ptrs));
EXPECT_TRUE(
DomainCookiesHaveWarnings(included, {*secure_trust_domain_cookie1}));
reset();
auto trust_domain_cookie1 = CanonicalCookie::CreateForTesting(
http_www_trustworthy.url(),
"foo1=trustdomain; Domain=" + http_www_trustworthy.domain(),
creation_time, server_time);
auto trust_domain_cookie2 = CanonicalCookie::CreateForTesting(
http_www_trustworthy.url(),
"foo2=trustdomain; Domain=" + http_www_trustworthy.domain(),
creation_time, server_time);
auto secure_trust_origin_cookie1 = CanonicalCookie::CreateForTesting(
https_www_trustworthy.url(), "foo1=securetrustorigin", creation_time,
server_time);
cookie_ptrs = {secure_trust_origin_cookie1.get(), trust_domain_cookie1.get(),
trust_domain_cookie2.get()};
cm->FilterCookiesWithOptions(http_www_trustworthy.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, cookie_ptrs));
EXPECT_TRUE(DomainCookiesHaveWarnings(included, {*trust_domain_cookie1}));
reset();
auto port_origin_cookie1 = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), "foo1=differentportorigin", creation_time,
server_time);
port_origin_cookie1->SetSourcePort(123);
cookie_ptrs = {port_origin_cookie1.get(), domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, cookie_ptrs));
EXPECT_TRUE(DomainCookiesHaveWarnings(included, {}));
EXPECT_TRUE(included[0].access_result.status.HasWarningReason(
CookieInclusionStatus::WarningReason::WARN_PORT_MISMATCH));
reset();
auto port_insecure_origin_cookie1 =
std::make_unique<CanonicalCookie>(*insecure_origin_cookie1);
port_insecure_origin_cookie1->SetSourcePort(123);
cookie_ptrs = {port_insecure_origin_cookie1.get(), domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, cookie_ptrs));
EXPECT_TRUE(DomainCookiesHaveWarnings(included, {}));
EXPECT_TRUE(
included[0].access_result.status.HasExactlyWarningReasonsForTesting(
{CookieInclusionStatus::WarningReason::WARN_SCHEME_MISMATCH,
CookieInclusionStatus::WarningReason::WARN_PORT_MISMATCH}));
reset();
scoped_feature_list.Reset();
scoped_feature_list.InitWithFeatures(
{net::features::kEnablePortBoundCookies},
{net::features::kEnableSchemeBoundCookies});
cookie_ptrs = {port_origin_cookie1.get(), domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, {domain_cookie1.get()}));
EXPECT_TRUE(DomainCookiesHaveWarnings(included, {}));
EXPECT_TRUE(CookieListsMatch(excluded, {port_origin_cookie1.get()}));
EXPECT_TRUE(
excluded[0].access_result.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_PORT_MISMATCH}));
reset();
cookie_ptrs = {port_insecure_origin_cookie1.get(), domain_cookie1.get()};
cm->FilterCookiesWithOptions(https_www_foo_.url(), options,
CookiePartitionKeyCollection(), cookie_ptrs,
included, excluded);
EXPECT_TRUE(CookieListsMatch(included, {domain_cookie1.get()}));
EXPECT_TRUE(DomainCookiesHaveWarnings(included, {}));
EXPECT_TRUE(CookieListsMatch(excluded, {port_insecure_origin_cookie1.get()}));
EXPECT_TRUE(
excluded[0].access_result.status.HasExactlyExclusionReasonsForTesting(
{CookieInclusionStatus::ExclusionReason::EXCLUDE_PORT_MISMATCH}));
EXPECT_TRUE(excluded[0].access_result.status.HasWarningReason(
CookieInclusionStatus::WarningReason::WARN_SCHEME_MISMATCH));
reset();
}
TEST_F(CookieMonsterTest, FromStorageCookieCreated300DaysAgoThenUpdatedNow) {
auto store = base::MakeRefCounted<FlushablePersistentStore>();
auto cookie_monster =
std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
cookie_monster->SetPersistSessionCookies(true);
EXPECT_TRUE(GetAllCookies(cookie_monster.get()).empty());
base::Time original_creation = base::Time::Now() - base::Days(300);
base::Time original_expiry = original_creation + base::Days(800);
CookieList list;
list.push_back(*CanonicalCookie::CreateUnsafeCookieForTesting(
"A", "B", "." + https_www_foo_.url().GetHost(), "/", original_creation,
original_expiry, base::Time(), base::Time(), true, false,
CookieSameSite::NO_RESTRICTION, COOKIE_PRIORITY_DEFAULT));
EXPECT_TRUE(SetAllCookies(cookie_monster.get(), list));
EXPECT_THAT(GetAllCookies(cookie_monster.get()),
ElementsAre(MatchesCookieNameValueCreationExpiry(
"A", "B", original_creation, original_expiry)));
base::Time new_creation = base::Time::Now();
base::Time new_expiry = new_creation + base::Days(800);
EXPECT_TRUE(SetCanonicalCookie(
cookie_monster.get(),
CanonicalCookie::CreateSanitizedCookie(
https_www_foo_.url(), "A", "B", https_www_foo_.url().GetHost(), "/",
new_creation, new_expiry, base::Time(), true, false,
CookieSameSite::NO_RESTRICTION, COOKIE_PRIORITY_DEFAULT, std::nullopt,
nullptr),
https_www_foo_.url(), false));
EXPECT_THAT(
GetAllCookies(cookie_monster.get()),
ElementsAre(MatchesCookieNameValueCreationExpiry(
"A", "B", original_creation, new_creation + base::Days(400))));
}
TEST_F(CookieMonsterTest, FromStorageCookieCreated500DaysAgoThenUpdatedNow) {
auto store = base::MakeRefCounted<FlushablePersistentStore>();
auto cookie_monster =
std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
cookie_monster->SetPersistSessionCookies(true);
EXPECT_TRUE(GetAllCookies(cookie_monster.get()).empty());
base::Time original_creation = base::Time::Now() - base::Days(500);
base::Time original_expiry = original_creation + base::Days(800);
CookieList list;
list.push_back(*CanonicalCookie::CreateUnsafeCookieForTesting(
"A", "B", "." + https_www_foo_.url().GetHost(), "/", original_creation,
original_expiry, base::Time(), base::Time(), true, false,
CookieSameSite::NO_RESTRICTION, COOKIE_PRIORITY_DEFAULT));
EXPECT_TRUE(SetAllCookies(cookie_monster.get(), list));
EXPECT_THAT(GetAllCookies(cookie_monster.get()),
ElementsAre(MatchesCookieNameValueCreationExpiry(
"A", "B", original_creation, original_expiry)));
base::Time new_creation = base::Time::Now();
base::Time new_expiry = new_creation + base::Days(800);
EXPECT_TRUE(SetCanonicalCookie(
cookie_monster.get(),
CanonicalCookie::CreateSanitizedCookie(
https_www_foo_.url(), "A", "B", https_www_foo_.url().GetHost(), "/",
new_creation, new_expiry, base::Time(), true, false,
CookieSameSite::NO_RESTRICTION, COOKIE_PRIORITY_DEFAULT, std::nullopt,
nullptr),
https_www_foo_.url(), false));
EXPECT_THAT(
GetAllCookies(cookie_monster.get()),
ElementsAre(MatchesCookieNameValueCreationExpiry(
"A", "B", original_creation, new_creation + base::Days(400))));
}
TEST_F(CookieMonsterTest, SanitizedCookieCreated300DaysAgoThenUpdatedNow) {
auto store = base::MakeRefCounted<FlushablePersistentStore>();
auto cookie_monster =
std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
cookie_monster->SetPersistSessionCookies(true);
EXPECT_TRUE(GetAllCookies(cookie_monster.get()).empty());
base::Time original_creation = base::Time::Now() - base::Days(300);
base::Time original_expiry = original_creation + base::Days(800);
EXPECT_TRUE(SetCanonicalCookie(
cookie_monster.get(),
CanonicalCookie::CreateSanitizedCookie(
https_www_foo_.url(), "A", "B", https_www_foo_.url().GetHost(), "/",
original_creation, original_expiry, base::Time(), true, false,
CookieSameSite::NO_RESTRICTION, COOKIE_PRIORITY_DEFAULT, std::nullopt,
nullptr),
https_www_foo_.url(), false));
EXPECT_THAT(
GetAllCookies(cookie_monster.get()),
ElementsAre(MatchesCookieNameValueCreationExpiry(
"A", "B", original_creation, original_creation + base::Days(400))));
base::Time new_creation = base::Time::Now();
base::Time new_expiry = new_creation + base::Days(800);
EXPECT_TRUE(SetCanonicalCookie(
cookie_monster.get(),
CanonicalCookie::CreateSanitizedCookie(
https_www_foo_.url(), "A", "B", https_www_foo_.url().GetHost(), "/",
new_creation, new_expiry, base::Time(), true, false,
CookieSameSite::NO_RESTRICTION, COOKIE_PRIORITY_DEFAULT, std::nullopt,
nullptr),
https_www_foo_.url(), false));
EXPECT_THAT(
GetAllCookies(cookie_monster.get()),
ElementsAre(MatchesCookieNameValueCreationExpiry(
"A", "B", original_creation, new_creation + base::Days(400))));
}
TEST_F(CookieMonsterTest, SanitizedCookieCreated500DaysAgoThenUpdatedNow) {
auto store = base::MakeRefCounted<FlushablePersistentStore>();
auto cookie_monster =
std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
cookie_monster->SetPersistSessionCookies(true);
EXPECT_TRUE(GetAllCookies(cookie_monster.get()).empty());
base::Time original_creation = base::Time::Now() - base::Days(500);
base::Time original_expiry = original_creation + base::Days(800);
EXPECT_TRUE(SetCanonicalCookie(
cookie_monster.get(),
CanonicalCookie::CreateSanitizedCookie(
https_www_foo_.url(), "A", "B", https_www_foo_.url().GetHost(), "/",
original_creation, original_expiry, base::Time(), true, false,
CookieSameSite::NO_RESTRICTION, COOKIE_PRIORITY_DEFAULT, std::nullopt,
nullptr),
https_www_foo_.url(), false));
EXPECT_TRUE(GetAllCookies(cookie_monster.get()).empty());
base::Time new_creation = base::Time::Now();
base::Time new_expiry = new_creation + base::Days(800);
EXPECT_TRUE(SetCanonicalCookie(
cookie_monster.get(),
CanonicalCookie::CreateSanitizedCookie(
https_www_foo_.url(), "A", "B", https_www_foo_.url().GetHost(), "/",
new_creation, new_expiry, base::Time(), true, false,
CookieSameSite::NO_RESTRICTION, COOKIE_PRIORITY_DEFAULT, std::nullopt,
nullptr),
https_www_foo_.url(), false));
EXPECT_THAT(GetAllCookies(cookie_monster.get()),
ElementsAre(MatchesCookieNameValueCreationExpiry(
"A", "B", new_creation, new_creation + base::Days(400))));
}
INSTANTIATE_TEST_SUITE_P(,
CookieMonsterTestPriorityGarbageCollectionObc,
testing::Combine(testing::Bool(), testing::Bool()));
INSTANTIATE_TEST_SUITE_P(,
CookieMonsterTestGarbageCollectionObc,
testing::ValuesIn(std::vector<std::tuple<bool, bool>>{
{true, false},
{false, true},
{true, true}}));
class CookieMonsterHttpPrefixTest : public CookieMonsterTest {
public:
CookieMonsterHttpPrefixTest() {
scoped_feature_list_.InitWithFeatures(
{features::kPrefixCookieHttp, features::kPrefixCookieHostHttp}, {});
}
private:
base::test::ScopedFeatureList scoped_feature_list_;
};
class CookieMonsterNoHttpPrefixTest : public CookieMonsterTest {
public:
CookieMonsterNoHttpPrefixTest() {
scoped_feature_list_.InitWithFeatures(
{}, {features::kPrefixCookieHttp, features::kPrefixCookieHostHttp});
}
private:
base::test::ScopedFeatureList scoped_feature_list_;
};
TEST_F(CookieMonsterHttpPrefixTest, RejectsHttpPrefixCookie) {
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cookie_monster =
std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
EXPECT_TRUE(GetAllCookies(cookie_monster.get()).empty());
std::string cookie_line = "__Http-Test1=1; path=/; secure";
std::unique_ptr<CanonicalCookie> cookie = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), cookie_line, base::Time::Now(),
std::nullopt,
std::nullopt);
EXPECT_FALSE(cookie);
}
TEST_F(CookieMonsterNoHttpPrefixTest, AcceptsHttpPrefixCookieWithoutFlag) {
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cookie_monster =
std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
EXPECT_TRUE(GetAllCookies(cookie_monster.get()).empty());
std::string cookie_line = "__Http-Test1=1; path=/; secure";
std::unique_ptr<CanonicalCookie> cookie = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), cookie_line, base::Time::Now(),
std::nullopt,
std::nullopt);
SetCanonicalCookie(cookie_monster.get(), std::move(cookie),
https_www_foo_.url(), true);
EXPECT_EQ(1u, GetAllCookies(cookie_monster.get()).size());
}
TEST_F(CookieMonsterHttpPrefixTest, AcceptsHttpPrefixCookie) {
auto store = base::MakeRefCounted<MockPersistentCookieStore>();
auto cookie_monster =
std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
EXPECT_TRUE(GetAllCookies(cookie_monster.get()).empty());
std::string cookie_line = "__Http-Test2=1; path=/; secure; httponly";
std::unique_ptr<CanonicalCookie> cookie = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), cookie_line, base::Time::Now(),
std::nullopt,
std::nullopt);
SetCanonicalCookie(cookie_monster.get(), std::move(cookie),
https_www_foo_.url(), true);
EXPECT_EQ(1u, GetAllCookies(cookie_monster.get()).size());
}
TEST_F(CookieMonsterHttpPrefixTest, RejectsHostHttpPrefixCookie) {
auto store = base::MakeRefCounted<FlushablePersistentStore>();
auto cookie_monster =
std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
cookie_monster->SetPersistSessionCookies(true);
EXPECT_TRUE(GetAllCookies(cookie_monster.get()).empty());
std::string cookie_line = "__Host-Http-Test=1; path=/; secure";
std::unique_ptr<CanonicalCookie> cookie = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), cookie_line, base::Time::Now(),
std::nullopt,
std::nullopt);
EXPECT_FALSE(cookie);
}
TEST_F(CookieMonsterNoHttpPrefixTest, AcceptsHostHttpPrefixCookieWithoutFlag) {
auto store = base::MakeRefCounted<FlushablePersistentStore>();
auto cookie_monster =
std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
cookie_monster->SetPersistSessionCookies(true);
EXPECT_TRUE(GetAllCookies(cookie_monster.get()).empty());
std::string cookie_line = "__Host-Http-Test=1; path=/; secure";
std::unique_ptr<CanonicalCookie> cookie = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), cookie_line, base::Time::Now(),
std::nullopt,
std::nullopt);
SetCanonicalCookie(cookie_monster.get(), std::move(cookie),
https_www_foo_.url(), true);
EXPECT_EQ(1u, GetAllCookies(cookie_monster.get()).size());
}
TEST_F(CookieMonsterHttpPrefixTest, RejectsHostHttpPrefixCookiePath) {
auto store = base::MakeRefCounted<FlushablePersistentStore>();
auto cookie_monster =
std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
cookie_monster->SetPersistSessionCookies(true);
EXPECT_TRUE(GetAllCookies(cookie_monster.get()).empty());
std::string cookie_line =
"__Host-Http-Test=1; path=/cookies/; secure; httponly";
std::string url = https_www_foo_.url().spec() + "cookies/";
std::unique_ptr<CanonicalCookie> cookie = CanonicalCookie::CreateForTesting(
GURL(url), cookie_line, base::Time::Now(),
std::nullopt,
std::nullopt);
EXPECT_FALSE(cookie);
}
TEST_F(CookieMonsterHttpPrefixTest, AcceptsHostHttpPrefixCookie) {
auto store = base::MakeRefCounted<FlushablePersistentStore>();
auto cookie_monster =
std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
cookie_monster->SetPersistSessionCookies(true);
EXPECT_TRUE(GetAllCookies(cookie_monster.get()).empty());
std::string cookie_line = "__Host-Http-Test=1; path=/; secure; httponly";
std::unique_ptr<CanonicalCookie> cookie = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), cookie_line, base::Time::Now(),
std::nullopt,
std::nullopt);
SetCanonicalCookie(cookie_monster.get(), std::move(cookie),
https_www_foo_.url(), true);
EXPECT_EQ(1u, GetAllCookies(cookie_monster.get()).size());
}
TEST_F(CookieMonsterHttpPrefixTest, RejectsHostHttpPrefixCookieWithDomain) {
auto store = base::MakeRefCounted<FlushablePersistentStore>();
auto cookie_monster =
std::make_unique<CookieMonster>(store.get(), net::NetLog::Get());
cookie_monster->SetPersistSessionCookies(true);
EXPECT_TRUE(GetAllCookies(cookie_monster.get()).empty());
std::string cookie_line =
"__Host-Http-Test=1; path=/; secure; httponly; domain=foo.com";
std::unique_ptr<CanonicalCookie> cookie = CanonicalCookie::CreateForTesting(
https_www_foo_.url(), cookie_line, base::Time::Now(),
std::nullopt,
std::nullopt);
EXPECT_FALSE(cookie);
}
}