File: fetch-canvas-tainting-iframe.html

package info (click to toggle)
firefox-esr 68.10.0esr-1~deb9u1
  • links: PTS, VCS
  • area: main
  • in suites: stretch
  • size: 3,143,932 kB
  • sloc: cpp: 5,227,879; javascript: 4,315,531; ansic: 2,467,042; python: 794,975; java: 349,993; asm: 232,034; xml: 228,320; sh: 82,008; lisp: 41,202; makefile: 22,347; perl: 15,555; objc: 5,277; cs: 4,725; yacc: 1,778; ada: 1,681; pascal: 1,673; lex: 1,417; exp: 527; php: 436; ruby: 225; awk: 162; sed: 53; csh: 44
file content (69 lines) | stat: -rw-r--r-- 2,116 bytes parent folder | download | duplicates (12)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
<html>
<title>iframe for fetch canvas tainting test</title>
<script>
const NOT_TAINTED = 'NOT_TAINTED';
const TAINTED = 'TAINTED';
const LOAD_ERROR = 'LOAD_ERROR';

// Creates an image/video element with src=|url| and an optional |cross_origin|
// attibute. Tries to read from the image/video using a canvas element. Returns
// NOT_TAINTED if it could be read, TAINTED if it could not be read, and
// LOAD_ERROR if loading the image/video failed.
function create_test_case_promise(url, cross_origin) {
  return new Promise(resolve => {
      if (url.indexOf('PNGIMAGE') != -1) {
        const img = document.createElement('img');
        if (cross_origin != '') {
          img.crossOrigin = cross_origin;
        }
        img.onload = function() {
          try {
            const canvas = document.createElement('canvas');
            canvas.width = 100;
            canvas.height = 100;
            const context = canvas.getContext('2d');
            context.drawImage(img, 0, 0);
            context.getImageData(0, 0, 100, 100);
            resolve(NOT_TAINTED);
          } catch (e) {
            resolve(TAINTED);
          }
        };
        img.onerror = function() {
          resolve(LOAD_ERROR);
        }
        img.src = url;
        return;
      }

      if (url.indexOf('VIDEO') != -1) {
        const video = document.createElement('video');
        video.autoplay = true;
        if (cross_origin != '') {
          video.crossOrigin = cross_origin;
        }
        video.onplay = function() {
          try {
            const canvas = document.createElement('canvas');
            canvas.width = 100;
            canvas.height = 100;
            const context = canvas.getContext('2d');
            context.drawImage(video, 0, 0);
            context.getImageData(0, 0, 100, 100);
            resolve(NOT_TAINTED);
          } catch (e) {
            resolve(TAINTED);
          }
        };
        video.onerror = function() {
          resolve(LOAD_ERROR);
        }
        video.src = url;
        return;
      }

      resolve('unknown resource type');
  });
}
</script>
</html>