All files / kernel-test/src/vats endowment-fetch.ts

0% Statements 0/40
0% Branches 0/8
0% Functions 0/9
0% Lines 0/40

Press n or j to go to the next uncovered block, b, p or k for the previous block.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107                                                                                                                                                                                                                     
import { makeDefaultExo } from '@metamask/kernel-utils/exo';
 
import { unwrapTestLogger } from '../test-powers.ts';
import type { TestPowers } from '../test-powers.ts';
 
/**
 * Build a root object for a vat that uses the network endowment (`fetch`
 * plus `Request`, `Headers`, `Response` constructors).
 *
 * @param vatPowers - The powers of the vat.
 * @param vatPowers.logger - The logger for the vat.
 * @returns The root object.
 */
// eslint-disable-next-line @typescript-eslint/explicit-function-return-type
export async function buildRootObject(vatPowers: TestPowers) {
  const tlog = unwrapTestLogger(vatPowers, 'endowment-user');
 
  tlog('buildRootObject');
 
  const root = makeDefaultExo('root', {
    bootstrap: () => {
      tlog('bootstrap');
    },
    hello: async (url: string) => {
      try {
        const response = await fetch(url);
        const text = await response.text();
        tlog(`response: ${text}`);
        // Verify hardened Request/Headers/Response constructors are
        // available on a successful path so the test can assert on them.
        tlog(
          `Request constructor: ${new Request(url) instanceof Request ? 'ok' : 'missing'}`,
        );
        tlog(
          `Headers constructor: ${new Headers({ 'x-test': '1' }) instanceof Headers ? 'ok' : 'missing'}`,
        );
        tlog(
          `Response constructor: ${new Response('body') instanceof Response ? 'ok' : 'missing'}`,
        );
        return text;
      } catch (error) {
        tlog(`error: ${String(error)}`);
        throw error;
      }
    },
    // The CWE-367 escape from #7557: an input that names the allowed host on
    // the caveat's read and a forbidden one on fetch's.
    fetchWithTwoFacedUrl: async (decoyUrl: string, targetUrl: string) => {
      let reads = 0;
      const twoFaced = {
        toString: () => {
          reads += 1;
          return reads === 1 ? decoyUrl : targetUrl;
        },
      };
      try {
        const response = await fetch(twoFaced as unknown as RequestInfo);
        tlog(`fetched: ${response.headers.get('x-fetched-url')}`);
      } catch (error) {
        tlog(`error: ${String(error)}`);
      }
      tlog(`reads: ${reads}`);
    },
    fetchFollowingRedirect: async (url: string) => {
      try {
        const response = await fetch(url);
        tlog(`fetched: ${response.headers.get('x-fetched-url')}`);
        tlog(`redirect mode: ${response.headers.get('x-redirect-mode')}`);
        tlog(`redirected: ${String(response.redirected)}`);
        // Read through the hardened response wrapper the endowment returns,
        // which is not the plain `Response` the unit tests exercise.
        tlog(`body: ${await response.text()}`);
      } catch (error) {
        tlog(`error: ${String(error)}`);
      }
    },
    fetchWithIntegrity: async (url: string, integrity: string) => {
      try {
        const response = await fetch(url, { integrity });
        tlog(`body: ${await response.text()}`);
      } catch (error) {
        tlog(`error: ${String(error)}`);
      }
    },
    fetchWithSpoofedRequest: async (decoyUrl: string, targetUrl: string) => {
      /**
       * A `Request` whose `url` getter lies while its internal slot — the one
       * `fetch` reads — holds the forbidden host.
       */
      class SpoofedRequest extends Request {
        /** @returns The decoy URL, not the URL this request was built with. */
        override get url(): string {
          return decoyUrl;
        }
      }
      try {
        const response = await fetch(new SpoofedRequest(targetUrl));
        tlog(`fetched: ${response.headers.get('x-fetched-url')}`);
      } catch (error) {
        tlog(`error: ${String(error)}`);
      }
    },
  });
 
  return root;
}