File: sandbox.https.html

package info (click to toggle)
firefox-esr 140.5.0esr-1~deb13u1
  • links: PTS, VCS
  • area: main
  • in suites: trixie-proposed-updates
  • size: 4,539,036 kB
  • sloc: cpp: 7,381,527; javascript: 6,388,905; ansic: 3,710,087; python: 1,393,776; xml: 628,165; asm: 426,918; java: 184,004; sh: 65,744; makefile: 19,302; objc: 13,059; perl: 12,912; yacc: 4,583; cs: 3,846; pascal: 3,352; lex: 1,720; ruby: 1,226; exp: 762; php: 436; lisp: 258; awk: 247; sql: 66; sed: 54; csh: 10
file content (40 lines) | stat: -rw-r--r-- 2,197 bytes parent folder | download | duplicates (18)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
<!doctype html>
<meta charset=utf-8>
<script src="/resources/testharness.js"></script>
<script src="/resources/testharnessreport.js"></script>
<script src="/common/get-host-info.sub.js"></script>
<div id=log></div>
<script>
async_test(t => {
  window.addEventListener("message", t.step_func_done(({ data }) => {
    assert_equals(data.origin, "null");
    assert_true(data.sameOriginWithoutCORP, "Request to same-origin resource without CORP did not fail");
    assert_true(data.sameOriginWithSameOriginCORP, "Request to same-origin resource with same-origin CORP did not fail");
    assert_true(data.sameOriginWithCrossOriginCORP, "Request to same-origin resource with cross-origin CORP did not succeed");
    assert_true(data.crossOriginWithCrossOriginCORP, "Request to cross-origin resource with cross-origin CORP did not succeed");
  }));

  const origins = get_host_info();
  const frame = document.createElement("iframe");
  const nothingCrossOriginCORP = new URL("resources/nothing-cross-origin-corp.js", window.location).pathname;
  const nothingSameOriginCORP = new URL("resources/nothing-same-origin-corp.txt", window.location).pathname;
  frame.sandbox = "allow-scripts";
  frame.srcdoc = `<script>
const data = { sameOriginWithoutCORP: false,
               sameOriginWithSameOriginCORP: false,
               sameOriginWithCrossOriginCORP: false,
               crossOriginWithCrossOriginCORP: false,
               origin: self.origin };
function record(promise, token, expectation) {
  return promise.then(() => data[token] = expectation, () => data[token] = !expectation);
}
Promise.all([
  record(fetch("/common/blank.html", { mode: "no-cors" }), "sameOriginWithoutCORP", false),
  record(fetch("${nothingSameOriginCORP}", { mode: "no-cors" }), "sameOriginWithSameOriginCORP", false),
  record(fetch("${nothingCrossOriginCORP}", { mode: "no-cors" }), "sameOriginWithCrossOriginCORP", true),
  record(fetch("${origins.HTTPS_NOTSAMESITE_ORIGIN}${nothingCrossOriginCORP}", { mode: "no-cors" }), "crossOriginWithCrossOriginCORP", true)
]).then(() => parent.postMessage(data, "*"));
<\/script>`;
  document.body.append(frame);
}, "Cross-Origin-Embedder-Policy and sandbox");
</script>