ladybird/Libraries/LibWeb/FileAPI/FileList.h
Luke Wilde d08d6b08d3 LibWeb: Use enum for serialization and reimplement interface exposure
Our currently implementation of structured serialization has a design
flaw, where if the serialized/transferred type was not used in the
destination realm, it would not be seen as exposed and thus we would
not re-create the type on the other side.

This is very common, for example, transferring a MessagePort to a just
inserted iframe, or the just inserted iframe transferring a MessagePort
to it's parent. This is what Google reCAPTCHA does.

This flaw occurred due to relying on lazily populated HashMaps of
constructors, namespaces and interfaces. This commit changes it so that
per-type "is exposed" implementations are generated.

Since it no longer relies on interface name strings, this commit
changes serializable types to indicate their type with an enum,
in line with how transferrable types indicate their type.

This makes Google reCAPTCHA work on https://www.google.com/recaptcha/api2/demo
It currently doesn't work on non-Google origins due to a separate
same-origin policy bug.
2025-07-15 09:20:02 -04:00

61 lines
1.8 KiB
C++

/*
* Copyright (c) 2022, Andrew Kaster <akaster@serenityos.org>
* Copyright (c) 2023, Luke Wilde <lukew@serenityos.org>
*
* SPDX-License-Identifier: BSD-2-Clause
*/
#pragma once
#include <AK/Vector.h>
#include <LibGC/Ptr.h>
#include <LibWeb/Bindings/PlatformObject.h>
#include <LibWeb/FileAPI/File.h>
#include <LibWeb/WebIDL/Types.h>
namespace Web::FileAPI {
class FileList
: public Bindings::PlatformObject
, public Bindings::Serializable {
WEB_PLATFORM_OBJECT(FileList, Bindings::PlatformObject);
GC_DECLARE_ALLOCATOR(FileList);
public:
[[nodiscard]] static GC::Ref<FileList> create(JS::Realm&);
void add_file(GC::Ref<File> file) { m_files.append(file); }
virtual ~FileList() override;
// https://w3c.github.io/FileAPI/#dfn-length
WebIDL::UnsignedLong length() const { return m_files.size(); }
// https://w3c.github.io/FileAPI/#dfn-item
File* item(size_t index)
{
return index < m_files.size() ? m_files[index].ptr() : nullptr;
}
// https://w3c.github.io/FileAPI/#dfn-item
File const* item(size_t index) const
{
return index < m_files.size() ? m_files[index].ptr() : nullptr;
}
virtual Optional<JS::Value> item_value(size_t index) const override;
virtual HTML::SerializeType serialize_type() const override { return HTML::SerializeType::FileList; }
virtual WebIDL::ExceptionOr<void> serialization_steps(HTML::SerializationRecord& serialized, bool for_storage, HTML::SerializationMemory&) override;
virtual WebIDL::ExceptionOr<void> deserialization_steps(ReadonlySpan<u32> const& serialized, size_t& position, HTML::DeserializationMemory&) override;
private:
explicit FileList(JS::Realm&);
virtual void initialize(JS::Realm&) override;
virtual void visit_edges(Cell::Visitor&) override;
Vector<GC::Ref<File>> m_files;
};
}