Oregami
Repositories/oxedyne/daimond

oxedyne/daimond/dev/verify_autofill.mjs

7.3 KiB, 1 run

created by r2519314175:245, which is this file's identity for as long as the history lasts, whatever it is later renamed to

download · who wrote it · its history

1// verify_autofill.mjs — the passphrase box and a password manager's fill.
2//
3// The gate is a real login form (see verify_genpass.mjs), so a browser or OS
4// keychain may fill the passphrase on page load. A fill is not typing: it
5// replaces the whole value at once and fires one `input` event, and it lands
6// whenever the manager gets round to it — which on a cold load is BEFORE the
7// gate is drawn, because the gate waits on the wasm engine. This asserts the
8// box survives that, and that a redraw still clears it.
9//
10// node dev/verify_autofill.mjs
11//
12// Needs dev/serve.mjs (DAIMOND_PORT, default 8777). No gateway and no model: this is
13// the gate only.
14
15import { open, PASS, APP } from './harness.mjs';
16
17let failures = 0;
18const check = (cond, msg, detail) => {
19 console.log((cond ? ' ok ' : ' FAIL ') + msg + (detail != null ? ' — ' + detail : ''));
20 if (!cond) failures++;
21};
22const sleep = (ms) => new Promise(r => setTimeout(r, ms));
23
24const s = await open({ name: 'autofill-' + Date.now(), connect: false });
25const { page } = s;
26
27/// Back to the lock screen, and wait for it.
28async function relock() {
29 await page.reload({ waitUntil: 'domcontentloaded' });
30 await page.waitForSelector('#id-primary', { timeout: 20000 });
31 await page.waitForFunction(() =>
32 document.getElementById('identity-modal').dataset.mode === 'unlock', null, { timeout: 20000 });
33 await page.waitForTimeout(200);
34}
35
36/// Press Unlock and say whether the gate went away.
37async function submit() {
38 await page.evaluate(() => document.getElementById('id-primary').click());
39 return page.waitForSelector('#identity-modal', { state: 'hidden', timeout: 25000 })
40 .then(() => true).catch(() => false);
41}
42
43// ── The field a manager is handed ──────────────────────────
44await relock();
45const shape = await page.evaluate(() => {
46 const p = document.getElementById('id-pass');
47 return {
48 type: p.type,
49 auto: p.getAttribute('autocomplete'),
50 masked: !!p._secretMasked,
51 hasReal: p._real != null,
52 optedOut: p.hasAttribute('data-1p-ignore') || p.hasAttribute('data-lpignore'),
53 };
54});
55check(shape.type === 'password', 'the passphrase box is a real password input', shape.type);
56check(!shape.masked && !shape.hasReal,
57 'it is NOT the JS bullet mask: its value is its value', 'masked=' + shape.masked + ' _real=' + shape.hasReal);
58check(!shape.optedOut, 'no manager opt-out is set on it');
59check(shape.auto === 'current-password', 'unlocking tags it current-password', shape.auto);
60
61// The token a manager reads is in the served markup, so it is right from the
62// moment the form is parsed — the JS in showIdentity only re-states it.
63const markup = await (await fetch(`${APP}/index.html`)).text();
64const tag = (markup.match(/<input[^>]*id="id-pass"[^>]*>/) || [''])[0];
65check(/type="password"/.test(tag) && /autocomplete="current-password"/.test(tag),
66 'and the served HTML carries both before any script runs', tag.slice(0, 90) + '…');
67
68// ── A whole-value fill, drawn gate ─────────────────────────
69const filled = await page.evaluate((pass) => {
70 const p = document.getElementById('id-pass');
71 p.value = pass;
72 p.dispatchEvent(new Event('input', { bubbles: true }));
73 return { value: p.value, real: p._real };
74}, PASS);
75check(filled.value === PASS, 'a whole-value fill is held verbatim', JSON.stringify(filled.value));
76check(filled.real === undefined, 'and no shadow copy is invented for it', String(filled.real));
77check(await submit(), 'the filled passphrase unlocks');
78
79// ── The event sequence Chrome actually emits ───────────────
80await relock();
81await page.evaluate((pass) => {
82 const p = document.getElementById('id-pass');
83 p.focus();
84 p.dispatchEvent(new InputEvent('beforeinput', { bubbles: true, inputType: 'insertReplacementText', data: pass }));
85 p.value = pass;
86 p.dispatchEvent(new InputEvent('input', { bubbles: true, inputType: 'insertReplacementText', data: pass }));
87 p.dispatchEvent(new Event('change', { bubbles: true }));
88}, PASS);
89const afterEvents = await page.evaluate(() => document.getElementById('id-pass').value);
90check(afterEvents === PASS, 'a beforeinput/input/change fill is held verbatim too', JSON.stringify(afterEvents));
91check(await submit(), 'and unlocks');
92
93// ── A fill that lands BEFORE the gate is drawn ─────────────
94//
95// The real case. The form is in the served HTML, so a manager can fill it as
96// soon as the document parses; the gate is drawn later, after the wasm engine
97// has loaded. On a hard refresh that engine is refetched, so the gap is wide.
98await page.addInitScript((pass) => {
99 window.__gateAt = null;
100 window.__fillAt = null;
101 const m = new MutationObserver(() => {
102 const el = document.getElementById('identity-modal');
103 if (el && el.dataset.mode && window.__gateAt == null) window.__gateAt = performance.now();
104 });
105 document.addEventListener('DOMContentLoaded', () => {
106 // Iframes (the Web panel, the terminal) run this script too, and have no gate.
107 const el = document.getElementById('identity-modal');
108 if (el) m.observe(el, { attributes: true });
109 });
110 const t = setInterval(() => {
111 const p = document.getElementById('id-pass');
112 if (!p) return;
113 clearInterval(t);
114 p.value = pass;
115 p.dispatchEvent(new Event('input', { bubbles: true }));
116 window.__fillAt = performance.now();
117 }, 4);
118}, PASS);
119await relock();
120const race = await page.evaluate(() => ({
121 value: document.getElementById('id-pass').value,
122 fillAt: window.__fillAt,
123 gateAt: window.__gateAt,
124}));
125check(race.fillAt != null && race.gateAt != null && race.fillAt < race.gateAt,
126 'the fill lands before the gate is drawn, as on a cold load',
127 'fill ' + Math.round(race.fillAt) + 'ms, gate ' + Math.round(race.gateAt) + 'ms');
128check(race.value === PASS, 'and the gate does not wipe it', JSON.stringify(race.value));
129check(await submit(), 'so the app opens without the passphrase being retyped');
130
131// ── A REDRAW still clears the box ──────────────────────────
132//
133// What the clear is for: logging out, or switching account, must never leave
134// the last passphrase sitting in the field for the next person at the browser.
135await sleep(1200);
136await page.evaluate(() => { document.getElementById('id-pass').value = 'left over from before'; });
137const loggedOut = await page.evaluate(() => {
138 if (window.DaimondPanels && DaimondPanels.activate) DaimondPanels.activate('home');
139 const it = Array.from(document.querySelectorAll('.admin-item'))
140 .find(b => (b.textContent || '').trim() === 'Log out');
141 if (!it) return false;
142 it.click();
143 return true;
144});
145check(loggedOut, 'the Log out control is there and clicks');
146await page.waitForFunction(() =>
147 document.getElementById('identity-modal').style.display !== 'none', null, { timeout: 15000 });
148await page.waitForTimeout(300);
149const afterLogout = await page.evaluate(() => document.getElementById('id-pass').value);
150check(afterLogout === '', 'a redraw of the gate clears whatever was in the box', JSON.stringify(afterLogout));
151
152const hardErrs = s.errs.filter(e => !/502|Bad Gateway|Failed to load resource/.test(e));
153check(hardErrs.length === 0, 'no console errors', hardErrs.join(' | ') || 'none');
154
155console.log(`\n${failures ? failures + ' FAILED' : 'all passed'}`);
156await s.close();
157process.exit(failures ? 1 : 0);