Opened 6 weeks ago

Last modified 11 days ago

#37149 assigned Cleanup/optimization

Make CSP violation checks in selenium tests work for multiple browsers

Reported by: Varun Kasyap Pentamaraju Owned by: VIZZARD-X
Component: Testing framework Version: dev
Severity: Normal Keywords:
Cc: Varun Kasyap Pentamaraju Triage Stage: Someday/Maybe
Has patch: no Needs documentation: no
Needs tests: no Patch needs improvement: no
Easy pickings: no UI/UX: no

Description

Several integration tests currently verify that no Content Security Policy (CSP) violations occurred by inspecting browser logs in tearDown():

in django\contrib\admin\tests.py:

    def tearDown(self):
        # Ensure that no CSP violations were logged in the browser.
        self.assertEqual(self.get_browser_logs(source="security"), [])

the current logic relying on get_browser_logs() to check no CSP violations:

    def get_browser_logs(self, source=None, level="ALL"):
        """
        Return Chrome console logs filtered by level and optionally source.
        """
        try:
            logs = self.selenium.get_log("browser")
        except AttributeError:
            logs = []
        return [
            log
            for log in logs
            if (level == "ALL" or log["level"] == level)
            and (source is None or log["source"] == source)
        ]

however, get_browser_logs() is only supported for chrome and being skipped for non-chrome browsers.

A browser-independent alternative would be to register a securitypolicyviolation event listener in the test page and collect violations in tearDown().

Change History (7)

comment:1 by Sarah Boyce, 6 weeks ago

Summary: Use securitypolicyviolation event listener in tearDown() to check CSP violations for integration testsMake CSP violation checks in selenium tests work for multiple browsers
Triage Stage: UnreviewedAccepted

Thank you

comment:2 by Varun Kasyap Pentamaraju, 6 weeks ago

Cc: Varun Kasyap Pentamaraju added

comment:3 by VIZZARD-X, 5 weeks ago

Owner: set to VIZZARD-X
Status: newassigned

comment:4 by VIZZARD-X, 4 weeks ago

Has patch: set
Last edited 4 weeks ago by VIZZARD-X (previous) (diff)

comment:5 by Sarah Boyce, 12 days ago

Patch needs improvement: set

comment:6 by VIZZARD-X, 11 days ago

Has patch: unset
Patch needs improvement: unset

PR closed for now. Blocked by the Playwright migration #37154. Will be reimplemented using page.add_init_script() once that lands.

comment:7 by Jacob Walls, 11 days ago

Triage Stage: AcceptedSomeday/Maybe
Note: See TracTickets for help on using tickets.
Back to Top