Revision e803257f327d543467241723edd21215fbcb2fc3 authored by Tom Anderson on 30 March 2018, 19:57:10 UTC, committed by Chromium WPT Sync on 30 March 2018, 19:57:10 UTC
BUG=787020
TBR=dpranke,asvitkine

Change-Id: I38740d1ee9fe621eabd5416f1a87b23a71fbb7e7
Reviewed-on: https://chromium-review.googlesource.com/986812
Reviewed-by: Thomas Anderson <thomasanderson@chromium.org>
Commit-Queue: Thomas Anderson <thomasanderson@chromium.org>
Cr-Commit-Position: refs/heads/master@{#547246}
1 parent 067f918
Raw File
access-control-sandboxed-iframe-denied.htm
<!DOCTYPE html>
<html>
  <head>
    <title>Tests that sandboxed iframe does not have CORS XHR access to its server</title>
    <script src="/resources/testharness.js"></script>
    <script src="/resources/testharnessreport.js"></script>
    <script src="/common/get-host-info.sub.js"></script>
  </head>
  <body>
    <script type="text/javascript">
const path = "/xhr/resources/pass.txt?pipe=" +
    "header(Cache-Control,no-store)|" +
    "header(Content-Type,text/plain)";

async_test((test) => {
  const xhr = new XMLHttpRequest;
  xhr.open("GET", get_host_info().HTTP_ORIGIN + path);
  xhr.send();
  xhr.onerror = test.unreached_func("Unexpected error");
  xhr.onload = test.step_func_done(() => {
    assert_equals(xhr.status, 200);
    assert_equals(xhr.responseText.trim(), "PASS");
  });
}, "Check that path exists and is accessible via local XHR request");

async_test((test) => {
  window.addEventListener("message", test.step_func((evt) => {
    if (evt.data === "ready") {
      document.getElementById("frame").contentWindow.postMessage(
          get_host_info().HTTP_ORIGIN + path, "*");
    } else {
      assert_equals(evt.data, "Exception thrown. Sandboxed iframe XHR access was denied in 'send'.");
      test.done();
    }
  }), false);
}, "Sandboxed iframe is denied access to path");
    </script>
    <iframe id="frame" sandbox="allow-scripts" src="/xhr/resources/access-control-sandboxed-iframe.html">
    </iframe>
  </body>
</html>
back to top