function makeChannel(url, triggeringPrincipalURI = null) {
let uri2 = NetUtil.newURI(url); // by default system principal is used, which cannot be used for permission based tests // because the default system principal has all permissions var principal = Services.scriptSecurityManager.createContentPrincipal(
uri2,
{}
);
// For LNA tests, we need a cross-origin triggering principal to test blocking behavior // If not specified, use a different origin to ensure cross-origin requests var triggeringPrincipal; if (triggeringPrincipalURI) {
let triggeringURI = NetUtil.newURI(triggeringPrincipalURI);
triggeringPrincipal = Services.scriptSecurityManager.createContentPrincipal(
triggeringURI,
{}
);
} else { // Default to a cross-origin principal (public.example.com)
let triggeringURI = NetUtil.newURI("https://public.example.com");
triggeringPrincipal = Services.scriptSecurityManager.createContentPrincipal(
triggeringURI,
{}
);
}
ChromeUtils.defineLazyGetter(this, "H1_URL", function () { return"http://localhost:" + httpServer.identity.primaryPort;
});
ChromeUtils.defineLazyGetter(this, "H2_URL", function () { return"https://localhost:" + server.port();
});
ChromeUtils.defineLazyGetter(this, "H1_EXAMPLE_URL", function () { return"http://example.com:" + httpServer.identity.primaryPort;
});
ChromeUtils.defineLazyGetter(this, "H1_TEST_EXAMPLE_URL", function () { return"http://test.example.com:" + httpServer.identity.primaryPort;
});
ChromeUtils.defineLazyGetter(this, "H1_SERVER_LOCAL_URL", function () { return"http://server.local:" + httpServer.identity.primaryPort;
});
ChromeUtils.defineLazyGetter(this, "H1_API_DEV_LOCAL_URL", function () { return"http://api.dev.local:" + httpServer.identity.primaryPort;
});
let httpServer = null;
let server = new NodeHTTP2Server(); function pathHandler(metadata, response) {
response.setStatusLine(metadata.httpVersion, 200, "OK");
let body = "success";
response.bodyOutputStream.write(body, body.length);
}
add_setup(async () => {
Services.prefs.setBoolPref("network.lna.block_trackers", true);
Services.obs.addObserver(ChannelCreationObserver, "http-on-opening-request"); // fail transactions on Local Network Access
Services.prefs.setBoolPref("network.lna.blocking", true);
// enable prompt for prefs testing, with this we can simulate the prompt actions by // network.lna.blocking.prompt.allow = false/true
Services.prefs.setBoolPref("network.loopback-network.prompt.testing", true);
Services.prefs.setBoolPref("network.localnetwork.prompt.testing", true);
add_task(async function lna_blocking_tests_local_network() { // add override such that target servers is considered as local network (and not localhost) // Include both IPv4 and IPv6 loopback addresses since Happy Eyeballs may // connect via [::1] (IPv6) instead of 127.0.0.1 (IPv4). var override_value = "127.0.0.1" + ":" +
httpServer.identity.primaryPort + "," + "127.0.0.1" + ":" +
server.port() + ",::1:" +
httpServer.identity.primaryPort + ",::1:" +
server.port();
// Test the network.lna.skip-domains preference
add_task(async function lna_domain_skip_tests() { // Add DNS overrides to map test domains to 127.0.0.1
override.clearOverrides();
Services.dns.clearCache(true);
// Add override such that target servers are considered as local network (and not localhost) // This includes all the domains we're testing with. // Include both IPv4 and IPv6 loopback addresses since Happy Eyeballs may // connect via [::1] (IPv6) instead of 127.0.0.1 (IPv4). var override_value = "127.0.0.1" + ":" +
httpServer.identity.primaryPort + "," + "127.0.0.1" + ":" +
server.port() + ",::1:" +
httpServer.identity.primaryPort + ",::1:" +
server.port();
// Set the new skip preference
Services.prefs.setBoolPref( "network.lna.local-network-to-localhost.skip-checks",
skipPref
);
// Disable prompt simulation for clean testing (prompt should not affect skip logic)
Services.prefs.setBoolPref( "network.loopback-network.prompt.testing.allow", false
);
let chan = makeChannel(url + suffix);
chan.loadInfo.parentIpAddressSpace = parentSpace; // Target is always Local (localhost) since we're testing localhost servers
let expectFailure = expectedStatus !== Cr.NS_OK ? CL_EXPECT_FAILURE : 0;
await new Promise(resolve => {
chan.asyncOpen(new ChannelListener(resolve, null, expectFailure));
});
// Test that same-origin requests skip LNA checks
add_task(async function lna_same_origin_skip_checks() { // Ensure the local-network-to-localhost skip pref is disabled for this test
Services.prefs.setBoolPref( "network.lna.local-network-to-localhost.skip-checks", false
);
// Test cases: [triggeringOriginURI, targetURL, parentSpace, expectedStatus, description] const sameOriginTestCases = [ // Same origin cases - should skip LNA checks and allow the request
[
H1_URL,
H1_URL + "/test_lna",
Ci.nsILoadInfo.Public,
Cr.NS_OK, "same origin localhost to localhost from Public should be allowed",
],
[
H1_URL,
H1_URL + "/test_lna",
Ci.nsILoadInfo.Private,
Cr.NS_OK, "same origin localhost to localhost from Private should be allowed",
],
[
H2_URL,
H2_URL + "/test_lna",
Ci.nsILoadInfo.Public,
Cr.NS_OK, "same origin localhost to localhost (H2) from Public should be allowed",
],
[
H2_URL,
H2_URL + "/test_lna",
Ci.nsILoadInfo.Private,
Cr.NS_OK, "same origin localhost to localhost (H2) from Private should be allowed",
],
// Cross-origin cases - should apply normal LNA checks and block // Use null to get the default cross-origin principal (public.example.com)
[ null,
H1_URL + "/test_lna",
Ci.nsILoadInfo.Public,
Cr.NS_ERROR_LOCAL_NETWORK_ACCESS_DENIED, "cross origin to localhost from Public should be blocked",
], // Note: Private->Local transition test removed temporarily // as there may be other logic affecting this transition
// Same origin but from local address space should still be allowed
[
H1_URL,
H1_URL + "/test_lna",
Ci.nsILoadInfo.Local,
Cr.NS_OK, "same origin localhost to localhost from Local should be allowed",
],
];
for (let [
triggeringOriginURI,
targetURL,
parentSpace,
expectedStatus,
description,
] of sameOriginTestCases) {
info(`Testing same origin check: ${description}`);
// Use makeChannel with explicit triggering principal
let chan = makeChannel(targetURL, triggeringOriginURI);
chan.loadInfo.parentIpAddressSpace = parentSpace;
let expectFailure = expectedStatus !== Cr.NS_OK ? CL_EXPECT_FAILURE : 0;
await new Promise(resolve => {
chan.asyncOpen(new ChannelListener(resolve, null, expectFailure));
});
Assert.equal(
chan.status,
expectedStatus,
`Status should match for: ${description}`
); if (expectedStatus === Cr.NS_OK) { Assert.equal(
chan.protocolVersion,
targetURL.startsWith(H2_URL) ? "h2" : "http/1.1"
);
}
}
});
Messung V0.5 in Prozent
¤ Dauer der Verarbeitung: 0.21 Sekunden
(vorverarbeitet am 2026-10-01)
¤
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.