File: send-non-same-origin.sub.htm

package info (click to toggle)
firefox-esr 52.8.1esr-1~deb8u1
  • links: PTS, VCS
  • area: main
  • in suites: jessie
  • size: 1,983,244 kB
  • sloc: cpp: 4,810,275; ansic: 2,004,548; python: 451,282; java: 241,615; asm: 178,649; xml: 136,302; sh: 82,207; makefile: 22,575; perl: 15,783; objc: 4,389; yacc: 1,816; ada: 1,697; pascal: 1,519; lex: 1,257; cs: 879; exp: 499; php: 436; lisp: 258; awk: 152; sed: 51; ruby: 47; csh: 27
file content (33 lines) | stat: -rw-r--r-- 1,313 bytes parent folder | download | duplicates (4)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
<!DOCTYPE html>
<html>
  <head>
    <title>XMLHttpRequest: send() - non same-origin</title>
    <script src="/resources/testharness.js"></script>
    <script src="/resources/testharnessreport.js"></script>
    <base>
    <link rel="help" href="https://xhr.spec.whatwg.org/#cross-origin-request-steps" data-tested-assertations="/following::DL[2]/DT[1] /following::DL[2]/DD[1]" />
    <link rel="help" href="https://xhr.spec.whatwg.org/#cross-origin-request-event-rules" data-tested-assertations="/following::DL[1]/DT[2] /following::DL[1]/DD[2]" />
  </head>
  <body>
    <div id="log"></div>
    <script src="/common/get-host-info.sub.js"></script>
    <script>
      // Setting base URL before running the tests
      var host_info = get_host_info();
      document.getElementsByTagName("base")[0].setAttribute("href", host_info.HTTP_REMOTE_ORIGIN);

      function url(url) {
        test(function() {
          var client = new XMLHttpRequest()
          client.open("GET", url, false)
          assert_throws("NetworkError", function() { client.send() })
        }, document.title + " (" + url + ")")
      }
      url("mailto:test@example.org")
      url("tel:+31600000000")
      url(host_info.HTTP_REMOTE_ORIGIN)
      url("javascript:alert('FAIL')")
      url("folder.txt")
    </script>
  </body>
</html>