using System; using System.IO; using Paca.Browser.Profiles; using Xunit; namespace Paca.Tests.Browser; public class ChromeIncognitoIsolationTests { [Fact] public void EphemeralProfileManager_Creates_Isolated_Directory() { var mgr = new EphemeralProfileManager(); var sessionId = Guid.NewGuid().ToString("N"); var path = mgr.GetOrCreateEphemeralProfileDirectory(sessionId); Assert.True(Directory.Exists(path)); Assert.Contains("Paca_Incognito_", Path.GetFileName(path)); Assert.True(mgr.IsEphemeralPath(path)); // Normal path should not be classified as ephemeral Assert.False(mgr.IsEphemeralPath(@"C:\Users\AppData\Local\Paca")); Assert.False(mgr.IsEphemeralPath(@"C:\Windows\System32")); // Cleanup var cleaned = mgr.CleanupEphemeralProfile(sessionId); Assert.True(cleaned); Assert.False(Directory.Exists(path)); } [Fact] public void EphemeralProfileManager_Prevents_Path_Traversal() { var mgr = new EphemeralProfileManager(); Assert.Throws((Action)(() => mgr.GetOrCreateEphemeralProfileDirectory("../../Windows"))); Assert.Throws((Action)(() => mgr.GetOrCreateEphemeralProfileDirectory(@"..\..\AppData"))); Assert.Throws((Action)(() => mgr.GetOrCreateEphemeralProfileDirectory(""))); Assert.Throws((Action)(() => mgr.GetOrCreateEphemeralProfileDirectory(" "))); } [Fact] public void EphemeralProfileScope_Automatically_Cleans_Up_On_Dispose() { var mgr = new EphemeralProfileManager(); string directoryPath; using (var scope = mgr.CreateEphemeralScope()) { directoryPath = scope.ProfilePath; Assert.True(Directory.Exists(directoryPath)); // Write dummy cookie / cache file var dummyFile = Path.Combine(directoryPath, "Cookies.db"); File.WriteAllText(dummyFile, "dummy_incognito_tokens"); Assert.True(File.Exists(dummyFile)); } // After scope disposal, directory must be completely wiped Assert.False(Directory.Exists(directoryPath)); } [Fact] public void EphemeralCookieJar_Isolates_Cookies_Between_Sessions() { var jarNormal = new EphemeralCookieJar(); var jarIncognito = new EphemeralCookieJar(); jarNormal.SetCookie("example.com", "session_token", "normal_user_token_12345"); jarIncognito.SetCookie("example.com", "session_token", "incognito_anonymous_token_99999"); Assert.Equal("normal_user_token_12345", jarNormal.GetCookie("example.com", "session_token")); Assert.Equal("incognito_anonymous_token_99999", jarIncognito.GetCookie("example.com", "session_token")); jarIncognito.Clear(); Assert.Null(jarIncognito.GetCookie("example.com", "session_token")); Assert.NotNull(jarNormal.GetCookie("example.com", "session_token")); } }