Title: [287970] trunk
Revision
287970
Author
[email protected]
Date
2022-01-12 19:23:40 -0800 (Wed, 12 Jan 2022)

Log Message

PCM: Same-site triggering events should support ephemeral measurement
https://bugs.webkit.org/show_bug.cgi?id=235160
<rdar://87423294>

Reviewed by Alex Christensen.

Source/WebCore:

We added ephemeral measurement for direct response advertising in https://bugs.webkit.org/show_bug.cgi?id=228984.
We added support for same-site triggering events in https://bugs.webkit.org/show_bug.cgi?id=233173.
These two features should work together.

The bug was that WebKit::NetworkSession::handlePrivateClickMeasurementConversion()
only checked for cross-site triggering events when handling ephemeral measurements.

Test: http/tests/privateClickMeasurement/triggering-event-with-attribution-source-through-fetch-keepalive-ephemeral.html

* loader/PrivateClickMeasurement.cpp:
(WebCore::PrivateClickMeasurement::isNeitherSameSiteNorCrossSiteTriggeringEvent):
    New convenience function to enhance readability in
    WebKit::NetworkSession::handlePrivateClickMeasurementConversion().
* loader/PrivateClickMeasurement.h:

Source/WebKit:

We added ephemeral measurement for direct response advertising in https://bugs.webkit.org/show_bug.cgi?id=228984.
We added support for same-site triggering events in https://bugs.webkit.org/show_bug.cgi?id=233173.
These two features should work together.

* NetworkProcess/NetworkSession.cpp:
(WebKit::NetworkSession::handlePrivateClickMeasurementConversion):
    This function previously only checked for cross-site triggering events when
    handling ephemeral measurements. Now it also checks for same-site triggering
    events.

LayoutTests:

* http/tests/privateClickMeasurement/triggering-event-with-attribution-source-through-fetch-keepalive-ephemeral-expected.txt: Added.
* http/tests/privateClickMeasurement/triggering-event-with-attribution-source-through-fetch-keepalive-ephemeral.html: Added.

Modified Paths

Added Paths

Diff

Modified: trunk/LayoutTests/ChangeLog (287969 => 287970)


--- trunk/LayoutTests/ChangeLog	2022-01-13 03:21:22 UTC (rev 287969)
+++ trunk/LayoutTests/ChangeLog	2022-01-13 03:23:40 UTC (rev 287970)
@@ -1,3 +1,14 @@
+2022-01-12  John Wilander  <[email protected]>
+
+        PCM: Same-site triggering events should support ephemeral measurement
+        https://bugs.webkit.org/show_bug.cgi?id=235160
+        <rdar://87423294>
+
+        Reviewed by Alex Christensen.
+
+        * http/tests/privateClickMeasurement/triggering-event-with-attribution-source-through-fetch-keepalive-ephemeral-expected.txt: Added.
+        * http/tests/privateClickMeasurement/triggering-event-with-attribution-source-through-fetch-keepalive-ephemeral.html: Added.
+
 2022-01-12  Diego Pino Garcia  <[email protected]>
 
         [GTK][WPE] Unreviewed test gardening, merge common WebRTC test failures

Added: trunk/LayoutTests/http/tests/privateClickMeasurement/triggering-event-with-attribution-source-through-fetch-keepalive-ephemeral-expected.txt (0 => 287970)


--- trunk/LayoutTests/http/tests/privateClickMeasurement/triggering-event-with-attribution-source-through-fetch-keepalive-ephemeral-expected.txt	                        (rev 0)
+++ trunk/LayoutTests/http/tests/privateClickMeasurement/triggering-event-with-attribution-source-through-fetch-keepalive-ephemeral-expected.txt	2022-01-13 03:23:40 UTC (rev 287970)
@@ -0,0 +1,16 @@
+CONSOLE MESSAGE: [Private Click Measurement] Triggering event was not accepted because the conversion data could not be parsed or was higher than the allowed maximum of 15.
+CONSOLE MESSAGE: Origin http://localhost:8000 is not allowed by Access-Control-Allow-Origin. Status code: 404
+CONSOLE MESSAGE: Fetch API cannot load https://localhost:8443/.well-known/private-click-measurement/trigger-attribution/Dummy?attributionSource=https://127.0.0.1 due to access control checks.
+Tests triggering of ephemeral private click measurement attribution with same-site triggering event request.
+
+
+Attributed Private Click Measurements:
+WebCore::PrivateClickMeasurement 1
+Source site: 127.0.0.1
+Attribute on site: localhost
+Source ID: 3
+Attribution trigger data: 12
+Attribution priority: 0
+Attribution earliest time to send: Within 24-48 hours
+Destination token: Not set
+Application bundle identifier: testBundleID

Added: trunk/LayoutTests/http/tests/privateClickMeasurement/triggering-event-with-attribution-source-through-fetch-keepalive-ephemeral.html (0 => 287970)


--- trunk/LayoutTests/http/tests/privateClickMeasurement/triggering-event-with-attribution-source-through-fetch-keepalive-ephemeral.html	                        (rev 0)
+++ trunk/LayoutTests/http/tests/privateClickMeasurement/triggering-event-with-attribution-source-through-fetch-keepalive-ephemeral.html	2022-01-13 03:23:40 UTC (rev 287970)
@@ -0,0 +1,56 @@
+<!DOCTYPE html>
+<html>
+<head>
+    <meta charset="UTF-8">
+    <script src=""
+    <script src=""
+</head>
+<body _onload_="runTest()">
+<div id="description">Tests triggering of ephemeral private click measurement attribution with same-site triggering event request.</div>
+<a id="targetLink" href="" attributionsourceid=3 attributiondestination="http://localhost:8000">Link</a><br>
+<div id="output"></div>
+<script>
+    prepareTest();
+
+    function activateElement(elementID) {
+        var element = document.getElementById(elementID);
+        var centerX = element.offsetLeft + element.offsetWidth / 2;
+        var centerY = element.offsetTop + element.offsetHeight / 2;
+        UIHelper.activateAt(centerX, centerY).then(
+            function () {
+            },
+            function () {
+                document.getElementById("output").innerText = "FAIL Promise rejected.";
+                tearDownAndFinish();
+            }
+        );
+    }
+
+    function triggerFetch(conversionData) {
+        return fetch("https://localhost:8443/privateClickMeasurement/resources/redirectToConversionWithAttributionSource.py?conversionData="+ conversionData + "&delay_ms=100", { keepalive: true });
+    }
+
+    function runTest() {
+        if (window.location.search === "?stepTwo") {
+            // Start private click attribution fetch but navigate away before the fetch redirection happens.
+            triggerFetch(12);
+            document.location.href = ""
+            return;
+        }
+        if (window.location.search === "?stepThree") {
+            document.body.removeChild(document.getElementById("targetLink"));
+            // Do an invalid private click attribution fetch to ensure the previous correct click attribution fetch will be finished.
+            triggerFetch("Dummy").catch(() => {
+                if (window.testRunner)
+                    testRunner.dumpPrivateClickMeasurement();
+                tearDownAndFinish();
+            });
+            return;
+        }
+        testRunner.setPrivateClickMeasurementEphemeralMeasurementForTesting(true);
+        testRunner.setPrivateClickMeasurementAppBundleIDForTesting("testBundleID");
+        activateElement("targetLink");
+    }
+</script>
+</body>
+</html>

Modified: trunk/Source/WebCore/ChangeLog (287969 => 287970)


--- trunk/Source/WebCore/ChangeLog	2022-01-13 03:21:22 UTC (rev 287969)
+++ trunk/Source/WebCore/ChangeLog	2022-01-13 03:23:40 UTC (rev 287970)
@@ -1,3 +1,26 @@
+2022-01-12  John Wilander  <[email protected]>
+
+        PCM: Same-site triggering events should support ephemeral measurement
+        https://bugs.webkit.org/show_bug.cgi?id=235160
+        <rdar://87423294>
+
+        Reviewed by Alex Christensen.
+
+        We added ephemeral measurement for direct response advertising in https://bugs.webkit.org/show_bug.cgi?id=228984.
+        We added support for same-site triggering events in https://bugs.webkit.org/show_bug.cgi?id=233173.
+        These two features should work together.
+
+        The bug was that WebKit::NetworkSession::handlePrivateClickMeasurementConversion()
+        only checked for cross-site triggering events when handling ephemeral measurements.
+
+        Test: http/tests/privateClickMeasurement/triggering-event-with-attribution-source-through-fetch-keepalive-ephemeral.html
+
+        * loader/PrivateClickMeasurement.cpp:
+        (WebCore::PrivateClickMeasurement::isNeitherSameSiteNorCrossSiteTriggeringEvent):
+            New convenience function to enhance readability in
+            WebKit::NetworkSession::handlePrivateClickMeasurementConversion().
+        * loader/PrivateClickMeasurement.h:
+
 2022-01-12  Andres Gonzalez  <[email protected]>
 
         Process deferred ChildrenChanged notifications before creating an isolated subtree.

Modified: trunk/Source/WebCore/loader/PrivateClickMeasurement.cpp (287969 => 287970)


--- trunk/Source/WebCore/loader/PrivateClickMeasurement.cpp	2022-01-13 03:21:22 UTC (rev 287969)
+++ trunk/Source/WebCore/loader/PrivateClickMeasurement.cpp	2022-01-13 03:23:40 UTC (rev 287970)
@@ -124,6 +124,15 @@
     return copy;
 }
 
+bool PrivateClickMeasurement::isNeitherSameSiteNorCrossSiteTriggeringEvent(const RegistrableDomain& redirectDomain, const URL& firstPartyURL, const AttributionTriggerData& attributionTriggerData)
+{
+    auto isSameSiteTriggeringEvent = redirectDomain.matches(firstPartyURL) && attributionTriggerData.sourceRegistrableDomain;
+    if (isSameSiteTriggeringEvent)
+        return false;
+    auto isCrossSiteTriggeringEvent = sourceSite().registrableDomain == redirectDomain && !attributionTriggerData.sourceRegistrableDomain;
+    return !isCrossSiteTriggeringEvent;
+}
+
 Expected<PrivateClickMeasurement::AttributionTriggerData, String> PrivateClickMeasurement::parseAttributionRequestQuery(const URL& redirectURL)
 {
     if (!redirectURL.hasQuery())

Modified: trunk/Source/WebCore/loader/PrivateClickMeasurement.h (287969 => 287970)


--- trunk/Source/WebCore/loader/PrivateClickMeasurement.h	2022-01-13 03:21:22 UTC (rev 287969)
+++ trunk/Source/WebCore/loader/PrivateClickMeasurement.h	2022-01-13 03:23:40 UTC (rev 287970)
@@ -378,6 +378,7 @@
     }
 
     WEBCORE_EXPORT static const Seconds maxAge();
+    WEBCORE_EXPORT bool isNeitherSameSiteNorCrossSiteTriggeringEvent(const RegistrableDomain& redirectDomain, const URL& firstPartyURL, const AttributionTriggerData&);
     WEBCORE_EXPORT static Expected<AttributionTriggerData, String> parseAttributionRequest(const URL& redirectURL);
     WEBCORE_EXPORT AttributionSecondsUntilSendData attributeAndGetEarliestTimeToSend(AttributionTriggerData&&, IsRunningLayoutTest);
     WEBCORE_EXPORT bool hasHigherPriorityThan(const PrivateClickMeasurement&) const;

Modified: trunk/Source/WebKit/ChangeLog (287969 => 287970)


--- trunk/Source/WebKit/ChangeLog	2022-01-13 03:21:22 UTC (rev 287969)
+++ trunk/Source/WebKit/ChangeLog	2022-01-13 03:23:40 UTC (rev 287970)
@@ -1,3 +1,21 @@
+2022-01-12  John Wilander  <[email protected]>
+
+        PCM: Same-site triggering events should support ephemeral measurement
+        https://bugs.webkit.org/show_bug.cgi?id=235160
+        <rdar://87423294>
+
+        Reviewed by Alex Christensen.
+
+        We added ephemeral measurement for direct response advertising in https://bugs.webkit.org/show_bug.cgi?id=228984.
+        We added support for same-site triggering events in https://bugs.webkit.org/show_bug.cgi?id=233173.
+        These two features should work together.
+
+        * NetworkProcess/NetworkSession.cpp:
+        (WebKit::NetworkSession::handlePrivateClickMeasurementConversion):
+            This function previously only checked for cross-site triggering events when
+            handling ephemeral measurements. Now it also checks for same-site triggering
+            events.
+
 2022-01-12  Fujii Hironori  <[email protected]>
 
         [WinCairo] Tiling scroll support

Modified: trunk/Source/WebKit/NetworkProcess/NetworkSession.cpp (287969 => 287970)


--- trunk/Source/WebKit/NetworkProcess/NetworkSession.cpp	2022-01-13 03:21:22 UTC (rev 287969)
+++ trunk/Source/WebKit/NetworkProcess/NetworkSession.cpp	2022-01-13 03:23:40 UTC (rev 287970)
@@ -372,7 +372,7 @@
         auto firstPartyForCookies = redirectRequest.firstPartyForCookies();
 
         // Ephemeral measurement can only have one pending click.
-        if (ephemeralMeasurement.sourceSite().registrableDomain != redirectDomain)
+        if (ephemeralMeasurement.isNeitherSameSiteNorCrossSiteTriggeringEvent(redirectDomain, firstPartyForCookies, attributionTriggerData))
             return;
         if (ephemeralMeasurement.destinationSite().registrableDomain != RegistrableDomain(firstPartyForCookies))
             return;
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes

Reply via email to