Raw File
block-string-assignment-to-Element-outerHTML.tentative.html
<!DOCTYPE html>
<html>
<head>
  <script src="/resources/testharness.js"></script>
  <script src="/resources/testharnessreport.js"></script>
  <script src="support/helper.sub.js"></script>

  <meta http-equiv="Content-Security-Policy" content="trusted-types *">
</head>
<body>
<div id="container"></div>
<script>
  var container = document.querySelector('#container')

  // TrustedHTML assignments do not throw.
  test(t => {
    let p = createHTML_policy(window, 1);
    let html = p.createHTML(INPUTS.HTML);

    var d = document.createElement('div');
    document.querySelector('#container').appendChild(d);
    d.outerHTML = html;
    assert_equals(container.innerText, RESULTS.HTML);

    while (container.firstChild)
      container.firstChild.remove();
  }, "outerHTML with html assigned via policy (successful HTML transformation).");

  // String assignments throw.
  test(t => {
    var d = document.createElement('div');
    container.appendChild(d);
    assert_throws(new TypeError(), _ => {
      d.outerHTML = "Fail.";
    });
    assert_equals(container.innerText, "");
    while (container.firstChild)
      container.firstChild.remove();
  }, "`outerHTML = string` throws.");

  // Null assignment throws.
  test(t => {
    var d = document.createElement('div');
    container.appendChild(d);
    assert_throws(new TypeError(), _ => {
      d.outerHTML = null;
    });
    assert_equals(container.innerText, "");
    while (container.firstChild)
      container.firstChild.remove();
  }, "`outerHTML = null` throws.");

  // After default policy creation string assignment implicitly calls createHTML.
  test(t => {
    let p = window.TrustedTypes.createPolicy("default", { createHTML: createHTMLJS }, true);

    var d = document.createElement('div');
    document.querySelector('#container').appendChild(d);
    d.outerHTML = INPUTS.HTML;
    assert_equals(container.innerText, RESULTS.HTML);

    while (container.firstChild)
      container.firstChild.remove();
  }, "`outerHTML = string` assigned via default policy (successful HTML transformation).");

  // After default policy creation null assignment implicitly calls createHTML.
  test(t => {
    var d = document.createElement('div');
    container.appendChild(d);
    d.outerHTML = null;
    assert_equals(container.innerText, "null");

    while (container.firstChild)
      container.firstChild.remove();
  }, "`outerHTML = null` assigned via default policy does not throw");
</script>
</body>
</html>
back to top