Improve test coverage for HTTPS upgrade exception matching (#33765)

Covered with tests the HTTPS upgrade exceptions logic, updated comments
with logic information.

Resolves: https://github.com/brave/brave-browser/issues/49186
---------

Signed-off-by: Vadym Struts <vstruts@brave.com>
This commit is contained in:
vadims
2026-02-27 16:08:06 +01:00
committed by GitHub
parent 5bd09fd759
commit ac92cda1c1
4 changed files with 123 additions and 2 deletions
@@ -14,7 +14,19 @@ static_library("browser") {
deps = [
"//base",
"//brave/components/brave_component_updater/browser",
"//net:net_features",
"//net",
"//url",
]
}
source_set("unit_tests") {
testonly = true
sources = [ "https_upgrade_exceptions_service_unittest.cc" ]
deps = [
":browser",
"//base/test:test_support",
"//net:net_features",
"//testing/gtest",
]
}
@@ -74,7 +74,13 @@ bool HttpsUpgradeExceptionsService::CanUpgradeToHTTPS(const GURL& url) {
// don't upgrade any websites yet.
return false;
}
// Allow upgrade only if the domain is not on the exceptions list.
// The exceptions list is provided by the "Brave Local Data Files Updater"
// CRX. It contains a list of hosts that should be excluded from HTTPS
// upgrades. The matching logic checks only the host name, as a result, if a
// subdomain is not explicitly listed, it will still be upgraded to HTTPS.
// For example, if a.com is on the list, a.com will not be upgraded, but
// sub.a.com will be upgraded.
return !exceptional_domains_.contains(url.host());
}
@@ -0,0 +1,102 @@
/* Copyright (c) 2026 The Brave Authors. All rights reserved.
* This Source Code Form is subject to the terms of the Mozilla Public
* License, v. 2.0. If a copy of the MPL was not distributed with this file,
* You can obtain one at https://mozilla.org/MPL/2.0/. */
#include "brave/components/https_upgrade_exceptions/browser/https_upgrade_exceptions_service.h"
#include <memory>
#include <string_view>
#include "base/test/scoped_feature_list.h"
#include "net/base/features.h"
#include "testing/gtest/include/gtest/gtest.h"
namespace {
// The list of exceptions contains TLDs+1
constexpr char kExceptionList[] = "a.com";
} // namespace
class HttpsUpgradeExceptionsServiceBaseTest : public testing::Test {
public:
void SetUp() override {
local_data_files_service_ =
brave_component_updater::LocalDataFilesServiceFactory(nullptr);
https_upgrade_exceptions_service_ = std::make_unique<
https_upgrade_exceptions::HttpsUpgradeExceptionsService>(
local_data_files_service_.get());
ASSERT_TRUE(https_upgrade_exceptions_service_);
testing::Test::SetUp();
}
https_upgrade_exceptions::HttpsUpgradeExceptionsService*
https_upgrade_exceptions_service() {
return https_upgrade_exceptions_service_.get();
}
private:
std::unique_ptr<brave_component_updater::LocalDataFilesService>
local_data_files_service_;
std::unique_ptr<https_upgrade_exceptions::HttpsUpgradeExceptionsService>
https_upgrade_exceptions_service_;
};
class HttpsUpgradeExceptionsServiceFeatureDisabledTest
: public HttpsUpgradeExceptionsServiceBaseTest {
public:
HttpsUpgradeExceptionsServiceFeatureDisabledTest() {
feature_list_.InitAndDisableFeature(net::features::kBraveHttpsByDefault);
}
private:
base::test::ScopedFeatureList feature_list_;
};
TEST_F(HttpsUpgradeExceptionsServiceFeatureDisabledTest,
CanUpgradeToHTTPS_DisabledFeature) {
const auto a_url = GURL("http://a.com");
EXPECT_FALSE(https_upgrade_exceptions_service()->CanUpgradeToHTTPS(a_url));
https_upgrade_exceptions_service()->OnDATFileDataReady(kExceptionList);
EXPECT_FALSE(https_upgrade_exceptions_service()->CanUpgradeToHTTPS(a_url));
}
class HttpsUpgradeExceptionsServiceFeatureEnabledTest
: public HttpsUpgradeExceptionsServiceBaseTest {
public:
HttpsUpgradeExceptionsServiceFeatureEnabledTest() {
feature_list_.InitAndEnableFeature(net::features::kBraveHttpsByDefault);
}
private:
base::test::ScopedFeatureList feature_list_;
};
TEST_F(HttpsUpgradeExceptionsServiceFeatureEnabledTest,
CanUpgradeToHTTPS_NotReady) {
const auto a_url = GURL("http://a.com");
EXPECT_FALSE(https_upgrade_exceptions_service()->CanUpgradeToHTTPS(a_url));
}
TEST_F(HttpsUpgradeExceptionsServiceFeatureEnabledTest, CanUpgradeToHTTPS) {
struct TestCases {
std::string name;
GURL url;
bool can_upgrade;
} kTestCases[] = {
{"Do not upgrade as exception", GURL("http://a.com"), false},
{"Do not upgrade as wrong schema", GURL("chrome://a.com"), false},
{"Simple Upgrade to HTTPS", GURL("http://b.com"), true}};
https_upgrade_exceptions_service()->OnDATFileDataReady(kExceptionList);
for (const auto& test_case : kTestCases) {
SCOPED_TRACE(testing::Message() << test_case.name);
EXPECT_EQ(
https_upgrade_exceptions_service()->CanUpgradeToHTTPS(test_case.url),
test_case.can_upgrade);
}
}