mirror of
https://github.com/priyanshujain/sanderling.git
synced 2026-10-02 19:17:10 +00:00
feat(hierarchy): an element reports whether it masks what is typed into it
ios reads it off SecureTextField, which the companion already sent and nothing read; web reads input[type=password]. Android cannot: the native tree mapper drops the password attribute before the sidecar sees it, so the fact is three-valued and null there rather than a false that would read as "not secure".
This commit is contained in:
1 parent
5f1f50c2fb
commit
b1e95739ad
11 files changed
+186
-5
No files matched your search
@@ -746,6 +746,10 @@ func (d *Driver) Hierarchy(ctx context.Context) (string, error) {
|
||||
// emitted is the flag the field declares and not the property's value.
|
||||
checked: el.checked === true || null,
|
||||
selected: el.selected === true || null,
|
||||
// Emitted as a plain boolean, never null, on every editable field: a
|
||||
// consumer deciding what a typed value may be recorded as has to tell
|
||||
// "not a secure entry" apart from "nobody said", and android says nothing.
|
||||
secure: isEditable ? el.type === 'password' : null,
|
||||
// Emitted as a plain boolean, never null: internal/hierarchy falls back to
|
||||
// the native heuristic when the field is absent, which reads any class
|
||||
// name containing "EditText" as an Android text widget. On web that is a
|
||||
|
||||
@@ -191,6 +191,43 @@ func TestElementState_ReportsTheOtherDocumentedBooleans(t *testing.T) {
|
||||
)
|
||||
}
|
||||
|
||||
// Every editable field states `secure`, false included. internal/verifier
|
||||
// redacts a typed value whenever the target does not positively report "not a
|
||||
// secure entry", so a dump that omitted the key on an ordinary text field would
|
||||
// redact the whole recent-action memory on web.
|
||||
func TestElementState_SecureStatesEveryEditableField(t *testing.T) {
|
||||
server := httptest.NewServer(http.FileServer(http.Dir("testdata")))
|
||||
defer server.Close()
|
||||
|
||||
d := New()
|
||||
defer d.Terminate(context.Background())
|
||||
ctx, cancel := context.WithTimeout(context.Background(), 60*time.Second)
|
||||
defer cancel()
|
||||
if err := d.Launch(ctx, server.URL+"/element-state.html", false, nil); err != nil {
|
||||
t.Fatalf("Launch: %v", err)
|
||||
}
|
||||
|
||||
for _, testCase := range []struct {
|
||||
selector string
|
||||
want bool
|
||||
}{
|
||||
{"id:secret", true},
|
||||
{"id:editing", false},
|
||||
} {
|
||||
element := elementInHierarchyDump(ctx, t, d, testCase.selector)
|
||||
if !element.SecureReported() {
|
||||
t.Errorf("the dump states no secure fact for %s", testCase.selector)
|
||||
}
|
||||
if element.Secure != testCase.want {
|
||||
t.Errorf("%s secure = %v, want %v", testCase.selector, element.Secure, testCase.want)
|
||||
}
|
||||
}
|
||||
|
||||
if button := elementInHierarchyDump(ctx, t, d, "id:save"); button.SecureReported() {
|
||||
t.Error("a button is not a text entry and states nothing")
|
||||
}
|
||||
}
|
||||
|
||||
// Focus belongs to the node the user is typing into, not to the element the
|
||||
// shadow tree is mounted on.
|
||||
//
|
||||
|
||||
@@ -11,6 +11,7 @@
|
||||
<input id="toggle-all" type="checkbox" />
|
||||
<input id="toggle-done" type="checkbox" checked />
|
||||
<input id="editing" type="text" value="buy milk" />
|
||||
<input id="secret" type="password" />
|
||||
<button id="save">save</button>
|
||||
<button id="cancel" disabled>cancel</button>
|
||||
<select id="filter">
|
||||
|
||||
@@ -54,6 +54,7 @@ type treeNode struct {
|
||||
Clickable *bool `json:"clickable,omitempty"`
|
||||
Enabled *bool `json:"enabled,omitempty"`
|
||||
Editable *bool `json:"editable,omitempty"`
|
||||
Secure *bool `json:"secure,omitempty"`
|
||||
}
|
||||
|
||||
// MapHierarchy converts a flat describe-all dump from the simulator companion
|
||||
@@ -228,6 +229,11 @@ func mapElement(element *rawElement, scrollable bool) (treeNode, bool) {
|
||||
if editable {
|
||||
yes := true
|
||||
node.Editable = &yes
|
||||
// Stated on every editable field, false included: a consumer deciding
|
||||
// what a typed value may be recorded as has to tell "not a secure
|
||||
// entry" apart from "nobody said".
|
||||
secure := element.Type == "SecureTextField"
|
||||
node.Secure = &secure
|
||||
}
|
||||
if element.Type == "Button" {
|
||||
yes := true
|
||||
@@ -238,7 +244,8 @@ func mapElement(element *rawElement, scrollable bool) (treeNode, bool) {
|
||||
}
|
||||
|
||||
func isEditable(elementType string) bool {
|
||||
return elementType == "TextArea" || elementType == "TextField"
|
||||
return elementType == "TextArea" || elementType == "TextField" ||
|
||||
elementType == "SecureTextField"
|
||||
}
|
||||
|
||||
// labelIsDisplayedText reports whether an element type's AXLabel is the string
|
||||
|
||||
@@ -388,3 +388,41 @@ func TestScrollableIgnoresAContainerOffTheScreen(t *testing.T) {
|
||||
t.Fatalf("scrollable containers = %+v, want none off the screen", got)
|
||||
}
|
||||
}
|
||||
|
||||
// A secure text entry is what XCUITest reports a password field as
|
||||
// (companion/Sources/ElementTypeName.swift). It has to reach the tree as a
|
||||
// fact, because that is what lets a typed value be redacted from the record
|
||||
// without redacting every other field's.
|
||||
func TestSecureFactPerEditableType(t *testing.T) {
|
||||
cases := []struct {
|
||||
elementType string
|
||||
wantReported bool
|
||||
wantSecure bool
|
||||
}{
|
||||
{"SecureTextField", true, true},
|
||||
{"TextField", true, false},
|
||||
{"TextArea", true, false},
|
||||
{"Button", false, false},
|
||||
{"StaticText", false, false},
|
||||
}
|
||||
for _, testCase := range cases {
|
||||
dump := `[{"type":"` + testCase.elementType + `","frame":{"x":0,"y":0,"width":10,"height":10},"enabled":true}]`
|
||||
element := parseSingle(t, dump)
|
||||
if element.SecureReported() != testCase.wantReported {
|
||||
t.Errorf("%s reported secure = %v, want %v",
|
||||
testCase.elementType, element.SecureReported(), testCase.wantReported)
|
||||
}
|
||||
if element.Secure != testCase.wantSecure {
|
||||
t.Errorf("%s secure = %v, want %v", testCase.elementType, element.Secure, testCase.wantSecure)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// A secure text entry is a field a run must be able to type into, or the login
|
||||
// screens every real app opens on are unreachable.
|
||||
func TestSecureTextFieldIsEditable(t *testing.T) {
|
||||
dump := `[{"type":"SecureTextField","frame":{"x":0,"y":0,"width":10,"height":10},"enabled":true}]`
|
||||
if element := parseSingle(t, dump); !element.Editable {
|
||||
t.Error("a secure text entry must be editable")
|
||||
}
|
||||
}
|
||||
@@ -72,10 +72,20 @@ type Element struct {
|
||||
Focused bool `json:"focused,omitempty"`
|
||||
Selected bool `json:"selected,omitempty"`
|
||||
Editable bool `json:"editable,omitempty"`
|
||||
Secure bool `json:"secure,omitempty"`
|
||||
Bounds Bounds `json:"bounds"`
|
||||
Attributes map[string]string `json:"attrs,omitempty"`
|
||||
}
|
||||
|
||||
// SecureReported reports whether the producer stated this element's secure
|
||||
// fact at all. Android never does, so an element without it is unknown rather
|
||||
// than known not to be a secure entry, and a caller deciding what may be
|
||||
// written down has to tell those two apart.
|
||||
func (e *Element) SecureReported() bool {
|
||||
_, reported := e.Attributes["secure"]
|
||||
return reported
|
||||
}
|
||||
|
||||
// Node is one node in the hierarchy tree.
|
||||
type Node struct {
|
||||
Element
|
||||
@@ -194,6 +204,7 @@ type treeNodeJSON struct {
|
||||
Checked flagJSON `json:"checked"`
|
||||
Selected flagJSON `json:"selected"`
|
||||
Editable flagJSON `json:"editable"`
|
||||
Secure flagJSON `json:"secure"`
|
||||
}
|
||||
|
||||
// flagJSON is one boolean field of a node. A value that is not a boolean
|
||||
@@ -223,7 +234,7 @@ func (f *flagJSON) UnmarshalJSON(data []byte) error {
|
||||
|
||||
func (n *treeNodeJSON) unreadableFlags() int {
|
||||
count := 0
|
||||
for _, flag := range []flagJSON{n.Clickable, n.Enabled, n.Focused, n.Checked, n.Selected, n.Editable} {
|
||||
for _, flag := range []flagJSON{n.Clickable, n.Enabled, n.Focused, n.Checked, n.Selected, n.Editable, n.Secure} {
|
||||
if flag.unreadable {
|
||||
count++
|
||||
}
|
||||
@@ -305,6 +316,7 @@ var selectorKeys = []string{
|
||||
"placeholderValue",
|
||||
"resource-id",
|
||||
"scrollable",
|
||||
"secure",
|
||||
"selected",
|
||||
"tag",
|
||||
"testID",
|
||||
@@ -583,6 +595,9 @@ func elementFromNode(node *treeNodeJSON) *Element {
|
||||
if node.Selected.set {
|
||||
element.Selected = node.Selected.value
|
||||
}
|
||||
if node.Secure.set {
|
||||
element.Secure = node.Secure.value
|
||||
}
|
||||
if node.Editable.set {
|
||||
element.Editable = node.Editable.value
|
||||
} else {
|
||||
@@ -613,6 +628,9 @@ func elementFromNode(node *treeNodeJSON) *Element {
|
||||
if node.Selected.set {
|
||||
element.Attributes["selected"] = strconv.FormatBool(node.Selected.value)
|
||||
}
|
||||
if node.Secure.set {
|
||||
element.Attributes["secure"] = strconv.FormatBool(node.Secure.value)
|
||||
}
|
||||
element.Attributes["editable"] = strconv.FormatBool(element.Editable)
|
||||
|
||||
return element
|
||||
|
||||
@@ -235,6 +235,53 @@ func TestBoolFieldsFromNode(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// secure is the one state flag with three answers: a producer that reports
|
||||
// nothing leaves the element unknown rather than known-not-secure, and a
|
||||
// consumer deciding what a typed value may be written into a record reads the
|
||||
// difference.
|
||||
func TestSecureIsUnknownUntilAProducerReportsIt(t *testing.T) {
|
||||
cases := []struct {
|
||||
name string
|
||||
node string
|
||||
wantReported bool
|
||||
wantSecure bool
|
||||
}{
|
||||
{"reported secure", `{"attributes": {"bounds": "[0,0,10,10]"}, "secure": true}`, true, true},
|
||||
{"reported not secure", `{"attributes": {"bounds": "[0,0,10,10]"}, "secure": false}`, true, false},
|
||||
{"never reported", `{"attributes": {"bounds": "[0,0,10,10]"}}`, false, false},
|
||||
}
|
||||
for _, testCase := range cases {
|
||||
t.Run(testCase.name, func(t *testing.T) {
|
||||
tree, err := Parse(testCase.node)
|
||||
if err != nil {
|
||||
t.Fatalf("Parse: %v", err)
|
||||
}
|
||||
element := tree.Elements[0]
|
||||
if element.SecureReported() != testCase.wantReported {
|
||||
t.Errorf("SecureReported = %v, want %v", element.SecureReported(), testCase.wantReported)
|
||||
}
|
||||
if element.Secure != testCase.wantSecure {
|
||||
t.Errorf("Secure = %v, want %v", element.Secure, testCase.wantSecure)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
// A selector reaches the fact by the same route every other boolean state does.
|
||||
func TestSecureIsSelectable(t *testing.T) {
|
||||
tree, err := Parse(`{"attributes": {"resource-id": "root", "bounds": "[0,0,10,10]"}, "children": [
|
||||
{"attributes": {"resource-id": "pwd", "bounds": "[0,0,10,5]"}, "secure": true, "children": []},
|
||||
{"attributes": {"resource-id": "email", "bounds": "[0,5,10,10]"}, "secure": false, "children": []}
|
||||
]}`)
|
||||
if err != nil {
|
||||
t.Fatalf("Parse: %v", err)
|
||||
}
|
||||
element := tree.Find("secure:true")
|
||||
if element == nil || element.ResourceID != "pwd" {
|
||||
t.Errorf("secure:true resolved to %+v, want the pwd element", element)
|
||||
}
|
||||
}
|
||||
|
||||
func TestEditableDerivation(t *testing.T) {
|
||||
cases := []struct {
|
||||
name string
|
||||
|
||||
Reference in new issue
Block a user