Skip to content

Commit b0bf004

Browse files
committed
add testcase for GR-20862
1 parent 95a49d4 commit b0bf004

File tree

1 file changed

+89
-0
lines changed
  • graal-js/src/com.oracle.truffle.js.scriptengine.test/src/com/oracle/truffle/js/scriptengine/test

1 file changed

+89
-0
lines changed
Lines changed: 89 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,89 @@
1+
/*
2+
* Copyright (c) 2020, 2020, Oracle and/or its affiliates. All rights reserved.
3+
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
4+
*
5+
* The Universal Permissive License (UPL), Version 1.0
6+
*
7+
* Subject to the condition set forth below, permission is hereby granted to any
8+
* person obtaining a copy of this software, associated documentation and/or
9+
* data (collectively the "Software"), free of charge and under any and all
10+
* copyright rights in the Software, and any and all patent rights owned or
11+
* freely licensable by each licensor hereunder covering either (i) the
12+
* unmodified Software as contributed to or provided by such licensor, or (ii)
13+
* the Larger Works (as defined below), to deal in both
14+
*
15+
* (a) the Software, and
16+
*
17+
* (b) any piece of software and/or hardware listed in the lrgrwrks.txt file if
18+
* one is included with the Software each a "Larger Work" to which the Software
19+
* is contributed by such licensors),
20+
*
21+
* without restriction, including without limitation the rights to copy, create
22+
* derivative works of, display, perform, and distribute the Software and make,
23+
* use, sell, offer for sale, import, export, have made, and have sold the
24+
* Software and the Larger Work(s), and to sublicense the foregoing rights on
25+
* either these or other terms.
26+
*
27+
* This license is subject to the following condition:
28+
*
29+
* The above copyright notice and either this complete permission notice or at a
30+
* minimum a reference to the UPL must be included in all copies or substantial
31+
* portions of the Software.
32+
*
33+
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
34+
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
35+
* FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
36+
* AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
37+
* LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
38+
* OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
39+
* SOFTWARE.
40+
*/
41+
package com.oracle.truffle.js.scriptengine.test;
42+
43+
import static org.junit.Assert.assertEquals;
44+
import static org.junit.Assert.assertFalse;
45+
import static org.junit.Assert.assertTrue;
46+
47+
import javax.script.ScriptException;
48+
49+
import org.graalvm.polyglot.PolyglotException;
50+
import org.junit.Test;
51+
52+
import com.oracle.truffle.js.scriptengine.GraalJSScriptEngine;
53+
54+
public class GR20862 {
55+
56+
private static final String INSECURE_SCRIPTENGINE_ACCESS_SYSTEM_PROPERTY = "graaljs.insecure-scriptengine-access";
57+
58+
private static void tryAccessingHost(boolean allowHostAccess) {
59+
System.setProperty(INSECURE_SCRIPTENGINE_ACCESS_SYSTEM_PROPERTY, allowHostAccess ? "true" : "false");
60+
try (GraalJSScriptEngine engine = GraalJSScriptEngine.create()) {
61+
engine.put("tester", new Tester());
62+
String src = "tester.ret42();";
63+
Object result = engine.eval(src);
64+
65+
// when access is allowed, expect correct result
66+
assertTrue(allowHostAccess);
67+
assertEquals(42, result);
68+
} catch (ScriptException ex) {
69+
// when access is not allowed, expect PolyglotException
70+
assertFalse(allowHostAccess);
71+
assertTrue(ex.getCause() instanceof PolyglotException);
72+
}
73+
}
74+
75+
public static class Tester {
76+
public int ret42() {
77+
return 42;
78+
}
79+
}
80+
81+
@Test
82+
public void testHostAccessBypass() {
83+
// try twice to avoid caching of engine with wrong setup
84+
tryAccessingHost(false);
85+
tryAccessingHost(true);
86+
tryAccessingHost(false);
87+
tryAccessingHost(true);
88+
}
89+
}

0 commit comments

Comments
 (0)