michael@0: /* This Source Code Form is subject to the terms of the Mozilla Public michael@0: * License, v. 2.0. If a copy of the MPL was not distributed with this michael@0: * file, You can obtain one at http://mozilla.org/MPL/2.0/. */ michael@0: michael@0: /* See https://bugzilla.mozilla.org/show_bug.cgi?id=813901 */ michael@0: michael@0: const Cu = Components.utils; michael@0: michael@0: // Make sure that we can't inject __exposedProps__ via the proto of a COW-ed object. michael@0: michael@0: function checkThrows(expression, sb, regexp) { michael@0: var result = Cu.evalInSandbox('(function() { try { ' + expression + '; return "allowed"; } catch (e) { return e.toString(); }})();', sb); michael@0: dump('result: ' + result + '\n\n\n'); michael@0: do_check_true(!!regexp.exec(result)); michael@0: } michael@0: michael@0: function run_test() { michael@0: michael@0: var sb = new Cu.Sandbox('http://www.example.org'); michael@0: sb.obj = {foo: 2}; michael@0: checkThrows('obj.foo = 3;', sb, /denied/); michael@0: Cu.evalInSandbox("var p = {__exposedProps__: {foo: 'rw'}};", sb); michael@0: sb.obj.__proto__ = sb.p; michael@0: checkThrows('obj.foo = 4;', sb, /__exposedProps__/); michael@0: }